# New index not created; data pushed into the existing index

**URL:** <https://discuss.elastic.co/t/new-index-not-created-data-pushed-into-the-existing-index/186158>\
**Category:** Logstash\
**Created:** [June 17, 2019, 9:08pm UTC](https://discuss.elastic.co/t/new-index-not-created-data-pushed-into-the-existing-index/186158 "2019-06-17T21:08:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![suryagprakash](https://avatars.discourse-cdn.com/v4/letter/s/8797f3/32.png) [@suryagprakash](https://discuss.elastic.co/u/suryagprakash)\
**Post date:** [June 17, 2019, 9:08pm UTC](https://discuss.elastic.co/t/new-index-not-created-data-pushed-into-the-existing-index/186158/1 "2019-06-17T21:08:27Z")

</div>

Hi,

I have setup ELK stack with 7.0 version.  
When I setup it created index with name logstash-2019.06.16-000001 post that its not create any indexes for 17th June. All the new data generated for 17th june is written to the 16 index.

Can you please help me how I can resolve this issue?  
Everything was working fine with ELK 6.6 version.

Below is the logstash config details.

input{  
beats{  
port =\> 5151  
}  
}

filter  
{

if [atomtype] == "or\_ash" {  
grok {  
###patterns\_dir =\> "E:\software\patterns"  
#pattern =\> "%{OR\_ASH}"  
match =\> {"message" =\> ["%{WORD:database\_name}%{SPACE};%{SPACE}%{BASE10NUM:or\_no\_of\_cpus:int}%{SPACE};%{DATESTAMP:snaptime}%{SPACE};%{SPACE}%{BASE10NUM:instance\_id:int};%{SPACE}%{BASE10NUM:or\_ash\_cpu:float};%{SPACE}%{BASE10NUM:or\_ash\_scheduler:float};%{SPACE}%{BASE10NUM:or\_ash\_user\_io:float};%{SPACE}%{BASE10NUM:or\_ash\_system\_io:float};%{SPACE}%{BASE10NUM:or\_ash\_concurrency:float};%{SPACE}%{BASE10NUM:or\_ash\_application:float};%{SPACE}%{BASE10NUM:or\_ash\_commit:float};%{SPACE}%{BASE10NUM:or\_ash\_configuration:float};%{SPACE}%{BASE10NUM:or\_ash\_administrative:float};%{SPACE}%{BASE10NUM:or\_ash\_network:float};%{SPACE}%{BASE10NUM:or\_ash\_queueing:float};%{SPACE}%{BASE10NUM:or\_ash\_cluster:float};%{SPACE}%{BASE10NUM:or\_ash\_other:float}"]}  
}  
date {  
match =\> ["snaptime", "dd/MM/yyyy-HH:mm:ss"]  
timezone =\> "UTC"  
}  
mutate {  
remove\_field =\> ["host"]  
}

}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9305"]  
index =\> "logstash-%{+YYYY.MM.dd}"  
}  
stdout { codec =\> rubydebug }  
}

Can someone please help me to solve this problem?

Please let me know if you need any further information.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 15, 2019, 9:08pm UTC](https://discuss.elastic.co/t/new-index-not-created-data-pushed-into-the-existing-index/186158/2 "2019-07-15T21:08:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
