# Not able to create index with logstash.conf

**URL:** <https://discuss.elastic.co/t/not-able-to-create-index-with-logstash-conf/61103>\
**Category:** Logstash\
**Created:** [September 21, 2016, 10:32am UTC](https://discuss.elastic.co/t/not-able-to-create-index-with-logstash-conf/61103 "2016-09-21T10:32:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sahilarora0928](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@sahilarora0928](https://discuss.elastic.co/u/sahilarora0928)\
**Post date:** [September 21, 2016, 10:32am UTC](https://discuss.elastic.co/t/not-able-to-create-index-with-logstash-conf/61103/1 "2016-09-21T10:32:52Z")

</div>

Doing a poc need some help asap.

I have logstash.conf file with following stuff.

input {  
file {  
path =\> "D:/elasticsearch/logstash-tutorial.log/nginxAccess.log"  
start\_position =\> "beginning"  
type =\> "logs"  
}  
}  
filter {  
grok{  
match=\>{  
"message"=\>"%{IP:clientip} - - [%{NOTSPACE:date} -%{INT}] "%{WORD:action} /%{WORD}/%{WORD}/%{NOTSPACE:login} %{WORD:protocol}/%{NUMBER:protocolNum}" %{NUMBER:status} %{NUMBER} "%{NOTSPACE}" "%{NOTSPACE:client} (%{WORD}; %{WORD:clientOs}%{GREEDYDATA}"  
}  
add\_field=\>{  
"eventName"=\>"groke"  
}  
}  
geoip {  
source =\> "clientip"  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\>["test-index"]  
}  
}

when I am running this file through cmd using this command ..../bin\>logstash -f logstash.conf

It gets start with the message  
**Settings: Default pipeline workers: 8**  
**Pipeline main started**

But i dont see any index with this name **test-index** is created in **[http://localhost:9200/\_cat/indices?v](http://localhost:9200/_cat/indices?v)**

Please help me with this as this is urgent.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 21, 2016, 11:05am UTC](https://discuss.elastic.co/t/not-able-to-create-index-with-logstash-conf/61103/2 "2016-09-21T11:05:59Z")

</div>

This is an extremely common difficulty that people have and the question is asked at least a few times per week. Please consult the archives of this forum for clues. Good keywords include sincedb, sincedb\_path, and ignore\_older.

---

<div class="post-metadata">

**Author:** ![sahilarora0928](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@sahilarora0928](https://discuss.elastic.co/u/sahilarora0928)\
**Post date:** [September 22, 2016, 6:18am UTC](https://discuss.elastic.co/t/not-able-to-create-index-with-logstash-conf/61103/3 "2016-09-22T06:18:16Z")

</div>

Hi,

Thanks for the reply but could not get anything from the existing questions.  
The problem is I have one other file as well from where i am able to create the index in Elastic Search ::

input {  
twitter {  
consumer\_key =\> "GgxvFNgtahQwrbnN4hE5bo8wr"  
consumer\_secret =\> "d10jYAbsym6T4b3qi0brUDFRyKq6ccZbOuUlFTqEaFoGZEMnqv"  
keywords =\> ["#IndiasBiggestSale"]  
oauth\_token =\> "111380564-GSbQ1vin3w1MZtJsefdT1NXr7G9nzCQlHeCntURA"  
oauth\_token\_secret =\> "i4a4gnB5lRxXPRPivq0pxiY0ApibPv0olJwDFsPOUKRDJ"  
}  
beats {  
port =\> "5043"  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> ["twitter-index"]  
}  
file {  
path =\> "D:/elasticsearch/logstash-tutorial.log/twitter.log"  
}  
}

Here everything is working fine index created, twitter.log file is being populated.  
But in other file I have used filter with regex, tested this file as well using command  
**..bin\>logstash logstash.conf --configtest**

It outputs Configuration OK. But the index is not created.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:37am UTC](https://discuss.elastic.co/t/not-able-to-create-index-with-logstash-conf/61103/4 "2017-07-06T04:37:27Z")

</div>


