# Logstash not creating new index

**URL:** <https://discuss.elastic.co/t/logstash-not-creating-new-index/291265>\
**Category:** Logstash\
**Created:** [December 8, 2021, 9:17pm UTC](https://discuss.elastic.co/t/logstash-not-creating-new-index/291265 "2021-12-08T21:17:02Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![will.nickisch](https://avatars.discourse-cdn.com/v4/letter/w/a88e57/32.png) [@will.nickisch](https://discuss.elastic.co/u/will.nickisch)\
**Post date:** [December 8, 2021, 9:17pm UTC](https://discuss.elastic.co/t/logstash-not-creating-new-index/291265/1 "2021-12-08T21:17:02Z")

</div>

I am having an issue with multiple tcp inputs and logstash not pulling in messages from the second tcp input.

The data received on port 6050 is going into the default index logstash-%{+YYYY.MM.dd} but the data sent from rsyslog to port 6052 is not being recorded at all.

I gave the logstash user temp superuser permissions to rule out permissions and still no luck.

Here is what I have for config files (edited to remove sensitive data and not applicable data):  
rsyslog.conf

```auto
:fromhost-ip, isequal, "X.X.X.X" @@localhost:6052;json-template
& stop
*.* @@localhost:6050;json-template

```

logstash configs  
01input.config

```auto
input {
  tcp {
    host => "localhost"
    port => 6050
    codec => "json"
    tags => "rsyslog"
  }
  tcp {
    host => "localhost"
    port => 6052
    codec => "json"
    type => "debug"
    tags => "cubes"
  }
  }
}

#filter { }
#output { }

```

99output.conf

```auto
output {
  if [tags] == "cubes" {
    elasticsearch { hosts => ["10.30.97.248:9200"]
    user => ["logstash"]
    password => ["password"]
    index => ["cubes-%{+YYYY.MM.dd}"]
  }
    } else {
    elasticsearch { hosts => ["10.30.97.248:9200"] 
    user => ["logstash"]
    password => ["password"]
    }
  }
}

```

When I perform a GET \_cat/indices none of the cubes-%{+YYYY.MM.dd} indices are even being created.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 8, 2021, 10:04pm UTC](https://discuss.elastic.co/t/logstash-not-creating-new-index/291265/2 "2021-12-08T22:04:52Z")

</div>

If ILM is enabled, and it is on by default for recent versions, then the index option is silently ignored. Personally I think that is a bad idea, but I don't get a vote on it.

---

<div class="post-metadata">

**Author:** ![will.nickisch](https://avatars.discourse-cdn.com/v4/letter/w/a88e57/32.png) [@will.nickisch](https://discuss.elastic.co/u/will.nickisch)\
**Post date:** [December 8, 2021, 10:26pm UTC](https://discuss.elastic.co/t/logstash-not-creating-new-index/291265/3 "2021-12-08T22:26:50Z")

</div>

Im fairly new to ELK. How do I disable that?  
And if I disable that will it stop the index lifecycle policies?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 8, 2021, 10:46pm UTC](https://discuss.elastic.co/t/logstash-not-creating-new-index/291265/4 "2021-12-08T22:46:10Z")

</div>

You can use the [ilm\_enabled](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm_enabled) option to disable it.

---

<div class="post-metadata">

**Author:** ![will.nickisch](https://avatars.discourse-cdn.com/v4/letter/w/a88e57/32.png) [@will.nickisch](https://discuss.elastic.co/u/will.nickisch)\
**Post date:** [December 9, 2021, 4:33pm UTC](https://discuss.elastic.co/t/logstash-not-creating-new-index/291265/5 "2021-12-09T16:33:25Z")

</div>

I set that setting to FALSE but no change. It is still not creating the new index and putting data anywhere.

---

<div class="post-metadata">

**Author:** ![will.nickisch](https://avatars.discourse-cdn.com/v4/letter/w/a88e57/32.png) [@will.nickisch](https://discuss.elastic.co/u/will.nickisch)\
**Post date:** [December 9, 2021, 5:39pm UTC](https://discuss.elastic.co/t/logstash-not-creating-new-index/291265/6 "2021-12-09T17:39:10Z")

</div>

I added the following code and now it is creating the index, but no data is being loaded into the new index

```auto
 ilm_enabled => true
    ilm_pattern => "{now/d}"
    ilm_rollover_alias => "cubes"

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 9, 2021, 6:28pm UTC](https://discuss.elastic.co/t/logstash-not-creating-new-index/291265/7 "2021-12-09T18:28:32Z")

</div>

> [@will.nickisch](#):
>
> `if [tags] == "cubes"`

Try `if "cubes" in [tags]`

---

<div class="post-metadata">

**Author:** ![will.nickisch](https://avatars.discourse-cdn.com/v4/letter/w/a88e57/32.png) [@will.nickisch](https://discuss.elastic.co/u/will.nickisch)\
**Post date:** [December 9, 2021, 10:28pm UTC](https://discuss.elastic.co/t/logstash-not-creating-new-index/291265/8 "2021-12-09T22:28:02Z")

</div>

I did finally get this working. to document the fix:  
Insead of stating a second tcp input and using rsyslog to send those messages to the second input to get the tag, I just created a new filter with a mutate to add the tag. Once that tag was there I was able to use the `if "cubes" in [tags]` to add it to the new Index.

Thank you for the help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 6, 2022, 10:28pm UTC](https://discuss.elastic.co/t/logstash-not-creating-new-index/291265/9 "2022-01-06T22:28:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
