# Logstash Shield index\_not\_found\_exception

**URL:** <https://discuss.elastic.co/t/logstash-shield-index-not-found-exception/53952>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [June 26, 2016, 3:25am UTC](https://discuss.elastic.co/t/logstash-shield-index-not-found-exception/53952 "2016-06-26T03:25:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nww\_Pot\_Fung\_Nng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nww_pot_fung_nng/32/128628_2.png) [@Nww\_Pot\_Fung\_Nng](https://discuss.elastic.co/u/Nww_Pot_Fung_Nng)\
**Post date:** [June 26, 2016, 3:25am UTC](https://discuss.elastic.co/t/logstash-shield-index-not-found-exception/53952/1 "2016-06-26T03:25:01Z")

</div>

Hi All,

I've setup shield on elasticsearch, kibana and logstash.

elasticseach and kibana are fine. But, I got the following error for logstash receiving events.

"error"=\>{"type"=\>"index\_not\_found\_exception", "reason"=\>"no such index", "index"=\>"logstash.apache-2016.06.26", "resource.type"=\>"index\_expression", "[resource.id](http://resource.id)"=\>"logstash.apache-2016.06.26"}

If I manually create the indice logstash.apache-2016.06.26 using account logstash, it just works fine.

So, did I miss something?

elasticsearch {  
hosts =\> ["[https://localhost:9200](https://localhost:9200)"]  
user =\> "logstash"  
password =\> "logstash"  
ssl =\> true  
ssl\_certificate\_verification =\> false  
cacert =\> '/appl/erp/elastic/elasticsearch-2.3.3/config/shield/rootCA.pem'  
index =\> "logstash.%{type}-%{+YYYY.MM.dd}"  
}

Regards,  
fung

---

<div class="post-metadata">

**Author:** ![Nww\_Pot\_Fung\_Nng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nww_pot_fung_nng/32/128628_2.png) [@Nww\_Pot\_Fung\_Nng](https://discuss.elastic.co/u/Nww_Pot_Fung_Nng)\
**Post date:** [June 28, 2016, 1:57am UTC](https://discuss.elastic.co/t/logstash-shield-index-not-found-exception/53952/2 "2016-06-28T01:57:15Z")

</div>

As a workaround, we need to create the indice manually in crontab.

0 0 \* \* \* /bin/curl -k -u logstash:logstash -XPUT "[https://localhost:9200/logstash.apache-](https://localhost:9200/logstash.apache-)`date +\%Y.\%m.\%d`" \> cr\_logstash\_indices.log 2\>&1

Anyone got any idea why logstash is not creating the indices? Before setting up Shield, everything works just fine. Please...

regards,  
fung

---

<div class="post-metadata">

**Author:** ![Nww\_Pot\_Fung\_Nng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nww_pot_fung_nng/32/128628_2.png) [@Nww\_Pot\_Fung\_Nng](https://discuss.elastic.co/u/Nww_Pot_Fung_Nng)\
**Post date:** [June 28, 2016, 8:08am UTC](https://discuss.elastic.co/t/logstash-shield-index-not-found-exception/53952/3 "2016-06-28T08:08:58Z")

</div>

It seems only me are having the problem.  
It turns out to be the action.auto\_create\_index setting.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:43pm UTC](https://discuss.elastic.co/t/logstash-shield-index-not-found-exception/53952/4 "2017-07-06T13:43:19Z")

</div>


