# No Index for winlogbeat-\*

**URL:** <https://discuss.elastic.co/t/no-index-for-winlogbeat/73028>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [January 27, 2017, 2:50pm UTC](https://discuss.elastic.co/t/no-index-for-winlogbeat/73028 "2017-01-27T14:50:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![craigothy](https://avatars.discourse-cdn.com/v4/letter/c/258eb7/32.png) [@craigothy](https://discuss.elastic.co/u/craigothy)\
**Post date:** [January 27, 2017, 2:50pm UTC](https://discuss.elastic.co/t/no-index-for-winlogbeat/73028/1 "2017-01-27T14:50:35Z")

</div>

For some reason, my winlogbeat indexes are not being created. I have installed the template manually and verified that it is there along with my default logstash template. I also see data hitting my logstash listening port (5170) via tcpdump. However, if I go into kibana and try to add an index pattern for winlogbeat-\* , it doesn't recognize any. Also if I request a list of indices from elasticsearch, I only see my existing logstash-\* indices and no winlogbeat-\* indices. What would be the best way to troubleshoot this? I am currently running winlogbeat/logstash/elasticsearch 5.1.2 with the following config. Thanks for any help!

```
winlogbeat:
  registry_file: C:/ProgramData/winlogbeat/.winlogbeat.yml
  event_logs:
    - name: Application
      ignore_older: 72h
    - name: Security
      ignore_older: 72h
    - name: System
      ignore_older: 72h
    - name: Microsoft-Windows-Sysmon/Operational
      ignore_older: 72h
output:
  logstash:
    hosts: ["172.30.1.101:5170"]
    worker: 1
    index: winlogbeat
logging.to_files: true
logging.files:
    path: C:/ProgramData/winlogbeat/Logs
    rotateeverybytes: 10485760 # = 10MB
    keepfiles: 3
logging.level: info

```

My logstash config (INPUT):

```
input {
      beats {
        port => 5150
        codec => json
        type => "suricata"
        tags => ["suricata"]
      }
      beats {
        port => 5170
        type => "winlogbeat"
      }
    }

```

My logstash config (OUTPUT):

```
output {
    elasticsearch { hosts => ["localhost:9200"] }
}
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 27, 2017, 3:09pm UTC](https://discuss.elastic.co/t/no-index-for-winlogbeat/73028/2 "2017-01-27T15:09:42Z")

</div>

Try using the [example config](https://www.elastic.co/guide/en/beats/libbeat/5.1/logstash-installation.html#logstash-setup) for your Elasticsearch output in the Logstash config.

Also `type => "winlogbeat"` will not do anything so you can just remove it. `type` is already set by Winlogbeat and you cannot overwrite it. See the note under the [type](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-type) docs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2017, 3:09pm UTC](https://discuss.elastic.co/t/no-index-for-winlogbeat/73028/3 "2017-02-24T15:09:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
