# Logstash not creating index on elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-not-creating-index-on-elasticsearch/82146>\
**Category:** Logstash\
**Created:** [April 12, 2017, 11:39am UTC](https://discuss.elastic.co/t/logstash-not-creating-index-on-elasticsearch/82146 "2017-04-12T11:39:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dbElastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dbelastic/32/46548_2.png) [@dbElastic](https://discuss.elastic.co/u/dbElastic)\
**Post date:** [April 12, 2017, 11:39am UTC](https://discuss.elastic.co/t/logstash-not-creating-index-on-elasticsearch/82146/1 "2017-04-12T11:39:14Z")

</div>

Hello,  
I have ElasticSearch and Logstash installed on same machine(Ubuntu).  
I have the below apache\_logs.conf file contents:

input {  
file {  
path =\> "/var/log/apache\_logs"  
type =\> "apache\_log" # a type to identify those logs (will need this later)  
start\_position =\> "beginning"  
}  
}

filter {  
grok {  
match=\> { message =\> "%{COMBINEDAPACHELOG}" }  
}  
date {  
locale =\> "en"  
match =\> ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}

output {  
stdout { }  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "myLogs"

```
}

```

}

The command --\> sudo service logstash configtest returns "Configuration OK"  
The log file is placed in "/var/log/apache\_logs"  
However, indices are not getting created in elasticsearch and hence not reflected in kibana.  
Could you please point out if I have missed out on any settings.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 12, 2017, 1:16pm UTC](https://discuss.elastic.co/t/logstash-not-creating-index-on-elasticsearch/82146/2 "2017-04-12T13:16:21Z")

</div>

So /var/log/apache\_logs is a directory rather than a file? Point directly to the file, or a wildcard that includes the file you want to read.

---

<div class="post-metadata">

**Author:** ![dbElastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dbelastic/32/46548_2.png) [@dbElastic](https://discuss.elastic.co/u/dbElastic)\
**Post date:** [April 13, 2017, 3:36am UTC](https://discuss.elastic.co/t/logstash-not-creating-index-on-elasticsearch/82146/3 "2017-04-13T03:36:54Z")

</div>

Hello,  
Thank you for the response. I mentioned path as /var/log/apache\_logs wherein apache\_logs is the name of the log file.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 13, 2017, 7:12am UTC](https://discuss.elastic.co/t/logstash-not-creating-index-on-elasticsearch/82146/4 "2017-04-13T07:12:34Z")

</div>

Okay. Logstash is probably tailing the file. In that case clearing the sincedb file will help. Please read the file input documentation and check the numerous posts about this in the past. Increasing Logstash's log level will give more clues about what it's doing.

---

<div class="post-metadata">

**Author:** ![dbElastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dbelastic/32/46548_2.png) [@dbElastic](https://discuss.elastic.co/u/dbElastic)\
**Post date:** [April 19, 2017, 12:30pm UTC](https://discuss.elastic.co/t/logstash-not-creating-index-on-elasticsearch/82146/5 "2017-04-19T12:30:42Z")

</div>

Okay, so I used the below in the file block:  
file {  
path =\> "/var/log/apache\_logs"  
type =\> "apache\_log" # a type to identify those logs (will need this later)  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null" #to clear since db  
}

and it worked!  
Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2017, 12:41pm UTC](https://discuss.elastic.co/t/logstash-not-creating-index-on-elasticsearch/82146/6 "2017-05-17T12:41:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
