# Missing data from logstash to elasticsearch

**URL:** <https://discuss.elastic.co/t/missing-data-from-logstash-to-elasticsearch/124954>\
**Category:** Elasticsearch\
**Created:** [March 21, 2018, 9:56am UTC](https://discuss.elastic.co/t/missing-data-from-logstash-to-elasticsearch/124954 "2018-03-21T09:56:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![amine1](https://avatars.discourse-cdn.com/v4/letter/a/e47774/32.png) [@amine1](https://discuss.elastic.co/u/amine1)\
**Post date:** [March 21, 2018, 9:56am UTC](https://discuss.elastic.co/t/missing-data-from-logstash-to-elasticsearch/124954/1 "2018-03-21T09:56:15Z")

</div>

![Capture%20du%202018-03-21%2010-53-23](https://us1.discourse-cdn.com/elastic/original/3X/1/9/19aeb6b56b48671d19901ae5983bff39c9c14f18.png) ![Capture%20du%202018-03-21%2010-52-36](https://us1.discourse-cdn.com/elastic/original/3X/3/d/3d66a7bbf9a804d38ad241c859fcffa7570bdc8b.png) ![Capture%20du%202018-03-21%2010-53-52](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7a389061996e7707b0763ae5b7750fe52b62c0b5.png)

Not all of data are passing from logstash to elasticsearch

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 21, 2018, 10:22am UTC](https://discuss.elastic.co/t/missing-data-from-logstash-to-elasticsearch/124954/2 "2018-03-21T10:22:37Z")

</div>

Please don't post images of text as they are hardly readable and not searchable.

Instead paste the text and format it with `</>` icon. Check the preview window.

---

<div class="post-metadata">

**Author:** ![amine1](https://avatars.discourse-cdn.com/v4/letter/a/e47774/32.png) [@amine1](https://discuss.elastic.co/u/amine1)\
**Post date:** [March 21, 2018, 10:54am UTC](https://discuss.elastic.co/t/missing-data-from-logstash-to-elasticsearch/124954/3 "2018-03-21T10:54:11Z")

</div>

pfelogsvn.conf  
\<input {  
file {  
path =\> "/home/mohamed/Bureau/logstash/logstash-6.1.3/logsvn.log"  
start\_position =\> beginning  
sincedb\_path =\> "dev/null"

}

}  
filter {

grok{

match =\> [ "message", "%{USERNAME:user} | %{GREEDYDATA:statut} | %{GREEDYDATA:date} %{TIME:heure} +%{INT:temps} (%{GREEDYDATA:jour}) | %{GREEDYDATA:nbl}",  
"message", "%{GREEDYDATA:nb}"]

}  
if [message] == "------------------------------------------------------------------------" {  
drop { }  
}  
if [nb] == "------------------------------------------------------------------------" {  
drop { }  
}  
if [message] =~ /^\s\*$/ {  
drop { }  
}  
if [nb] == "^$" {  
drop { }  
}  
}  
output {  
elasticsearch {  
hosts =\>["localhost:9200"]  
manage\_template =\>false  
index =\> "pfe7"  
document\_type=\>"system\_logs"

}  
stdout { codec =\> rubydebug }  
}\>

i have used this configuration to run data from logstash to elasticsearsh but i have met a problem ,not all the data is passing to elasticsearch

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 21, 2018, 11:33am UTC](https://discuss.elastic.co/t/missing-data-from-logstash-to-elasticsearch/124954/4 "2018-03-21T11:33:53Z")

</div>

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

**There's a live preview panel for exactly this reasons**.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

---

<div class="post-metadata">

**Author:** ![amine1](https://avatars.discourse-cdn.com/v4/letter/a/e47774/32.png) [@amine1](https://discuss.elastic.co/u/amine1)\
**Post date:** [March 21, 2018, 12:42pm UTC](https://discuss.elastic.co/t/missing-data-from-logstash-to-elasticsearch/124954/6 "2018-03-21T12:42:17Z")

</div>

i didn't understand your request

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 21, 2018, 1:21pm UTC](https://discuss.elastic.co/t/missing-data-from-logstash-to-elasticsearch/124954/7 "2018-03-21T13:21:53Z")

</div>

Your code is not correctly formatted. No indentation, hard to read.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 18, 2018, 2:03pm UTC](https://discuss.elastic.co/t/missing-data-from-logstash-to-elasticsearch/124954/9 "2018-04-18T14:03:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
