# No output to Elasticsearch

**URL:** <https://discuss.elastic.co/t/no-output-to-elasticsearch/47498>\
**Category:** Logstash\
**Created:** [April 15, 2016, 12:48pm UTC](https://discuss.elastic.co/t/no-output-to-elasticsearch/47498 "2016-04-15T12:48:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![johnslippers](https://avatars.discourse-cdn.com/v4/letter/j/4da419/32.png) [@johnslippers](https://discuss.elastic.co/u/johnslippers)\
**Post date:** [April 15, 2016, 12:48pm UTC](https://discuss.elastic.co/t/no-output-to-elasticsearch/47498/1 "2016-04-15T12:48:04Z")

</div>

Hi,

I hope somebody can assist?

I have setup Elasticsearch, Kibana, Logstash and Filebeat but can't get Logstash to write to Elasticsearch.

Filebeat logs to Logstash. I know that because in my Filebeat log file I get these entries:

INFO Events sent: 2048  
2016-04-15T12:39:28Z INFO Registry file updated. 100 states written.

Kibana can access [Elasticsearch.It](http://Elasticsearch.It) complains that it is unable to fetch mapping becuase it can't find anything logstash related under "/var/lib/elasticsearch/elasticsearch/nodes/0/indices/". ther is just a .kibana directory.

The logstash log file only has one entry upon start-up: ":message=\>"Pipeline main started"}  
"

The kibana/elastic/logstash/filebeat log files doesn't have any error.

I use these versions:  
Logstash 2.3.1  
Elasticsearch 2.3.1  
Kibana 4.4.2  
Filebeat 1.2.1

## Logstash config:

input {  
beats{  
port =\> 5044 # number (required)  
codec =\> json\_lines {  
charset =\> "UTF-8"  
}  
}  
}

filter {

```
    if ("New client unix socket" in [message]) {
            drop { }
    }

    if ("Client unix socket" in [message]) {
            drop { }
    }

    if ("logstash_heartbeat" in [message]) {
          drop { }
    }

    mutate {
            gsub => ["type", "[.]","_"]
    }

    metrics {
            meter => ["%{system}.%{type}.%{logLevel}"]
            clear_interval => 300
            flush_interval => 300
            add_tag => ["perlog"]
            percentiles => [1]
    }

```

}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

I am not sure what I am doing wrong. Please help!

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [April 16, 2016, 4:56am UTC](https://discuss.elastic.co/t/no-output-to-elasticsearch/47498/2 "2016-04-16T04:56:44Z")

</div>

In logstash `output` section, you can turn on debug mode to output to stdout

```auto
output {
    stdout { codec => rubydebug }
}

```

with this you can see if Logstash processes anything or gets any error.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:01am UTC](https://discuss.elastic.co/t/no-output-to-elasticsearch/47498/3 "2017-07-06T05:01:59Z")

</div>


