# LS agent successfully started but ES index not created

**URL:** <https://discuss.elastic.co/t/ls-agent-successfully-started-but-es-index-not-created/135658>\
**Category:** Logstash\
**Created:** [June 13, 2018, 8:58am UTC](https://discuss.elastic.co/t/ls-agent-successfully-started-but-es-index-not-created/135658 "2018-06-13T08:58:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ambuj\_Saxena](https://avatars.discourse-cdn.com/v4/letter/a/ee59a6/32.png) [@Ambuj\_Saxena](https://discuss.elastic.co/u/Ambuj_Saxena)\
**Post date:** [June 13, 2018, 8:58am UTC](https://discuss.elastic.co/t/ls-agent-successfully-started-but-es-index-not-created/135658/1 "2018-06-13T08:58:30Z")

</div>

Hi,

I am new here. The first time I ran through the LS guide, first time I push to all data into elasticsearch but my all data point are string & can't do much about it. So delete the index page and try again this time. Logstash is saying agent successfully started, but I did not saw any index page. I thought I did something wrong.

Here is my config file:

> input {  
> file {  
> path =\> ["C:\elk\_stack\data\Fr\_apr\_18.csv"]  
> start\_position =\> "beginning"  
> type =\> "logs"  
> }  
> }  
> filter {  
> csv{  
> columns =\>["log\_id","response\_time\_in\_secs","response\_date\_time","string","ID","Version","data"]  
> separator =\> ","  
> }  
> date {  
> match =\> ["response\_date\_time", "yyyy/MM/dd HH:mm:ss"]  
> target =\> "response\_date\_time"  
> }  
> mutate {convert =\> ["log\_id", "integer"]}  
> mutate {convert =\> ["response\_time\_in\_secs", "float"]}  
> mutate {convert =\> ["ID", "integer"]}  
> }  
> output {  
> elasticsearch {  
> hosts =\> "localhost"  
> index =\> "logstash-test-1"  
> }  
> stdout { }  
> }/\<

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 13, 2018, 9:01am UTC](https://discuss.elastic.co/t/ls-agent-successfully-started-but-es-index-not-created/135658/2 "2018-06-13T09:01:23Z")

</div>

Have a look at [this blog post](https://www.elastic.co/blog/a-practical-introduction-to-logstash) which walks you through how to work with Logstash and get your data into Elasticsearch in the expected format.

---

<div class="post-metadata">

**Author:** ![Ambuj\_Saxena](https://avatars.discourse-cdn.com/v4/letter/a/ee59a6/32.png) [@Ambuj\_Saxena](https://discuss.elastic.co/u/Ambuj_Saxena)\
**Post date:** [June 13, 2018, 9:13am UTC](https://discuss.elastic.co/t/ls-agent-successfully-started-but-es-index-not-created/135658/3 "2018-06-13T09:13:55Z")

</div>

Thanks for responding @Christian_Dahlqvist

I am using ELK 5.1.2 due to my system is windows 7 32 bit.

And I did not get what I did wrong, I already go through this tut.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 13, 2018, 9:17am UTC](https://discuss.elastic.co/t/ls-agent-successfully-started-but-es-index-not-created/135658/4 "2018-06-13T09:17:32Z")

</div>

What is the result if you remove the index name from your Elasticsearch output plugin and index into the default Logstash index?

---

<div class="post-metadata">

**Author:** ![Ambuj\_Saxena](https://avatars.discourse-cdn.com/v4/letter/a/ee59a6/32.png) [@Ambuj\_Saxena](https://discuss.elastic.co/u/Ambuj_Saxena)\
**Post date:** [June 13, 2018, 9:26am UTC](https://discuss.elastic.co/t/ls-agent-successfully-started-but-es-index-not-created/135658/5 "2018-06-13T09:26:25Z")

</div>

![q](https://us1.discourse-cdn.com/elastic/original/3X/2/5/25ecc02ba733c9b9460e2aa5b6d091b3f884b044.jpg)

Now I am finding this error.  
whether I am using index name or not doesn't matter

---

<div class="post-metadata">

**Author:** ![rijinmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rijinmp/32/24634_2.png) [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Post date:** [June 13, 2018, 5:02pm UTC](https://discuss.elastic.co/t/ls-agent-successfully-started-but-es-index-not-created/135658/6 "2018-06-13T17:02:42Z")

</div>

did you enter your conf file path in logstash.yml ?

---

<div class="post-metadata">

**Author:** ![rijinmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rijinmp/32/24634_2.png) [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Post date:** [June 13, 2018, 5:05pm UTC](https://discuss.elastic.co/t/ls-agent-successfully-started-but-es-index-not-created/135658/7 "2018-06-13T17:05:47Z")

</div>

Put your elasticsearch port number also in conf file .

output {  
stdout{ codec =\> rubydebug }  
elasticsearch { hosts =\> ["127.0.0.1:9200"]  
index =\> "logstash-test-1"  
}  
}

"stdout{ codec =\> rubydebug }" by this command you can see the parsed log when logstash started .

---

<div class="post-metadata">

**Author:** ![Ambuj\_Saxena](https://avatars.discourse-cdn.com/v4/letter/a/ee59a6/32.png) [@Ambuj\_Saxena](https://discuss.elastic.co/u/Ambuj_Saxena)\
**Post date:** [June 14, 2018, 6:44am UTC](https://discuss.elastic.co/t/ls-agent-successfully-started-but-es-index-not-created/135658/8 "2018-06-14T06:44:38Z")

</div>

@rijinmp I thought I miss this one.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2018, 6:44am UTC](https://discuss.elastic.co/t/ls-agent-successfully-started-but-es-index-not-created/135658/9 "2018-07-12T06:44:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
