# Output with index got error

**URL:** <https://discuss.elastic.co/t/output-with-index-got-error/142873>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 3, 2018, 8:44am UTC](https://discuss.elastic.co/t/output-with-index-got-error/142873 "2018-08-03T08:44:12Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [August 3, 2018, 8:44am UTC](https://discuss.elastic.co/t/output-with-index-got-error/142873/1 "2018-08-03T08:44:12Z")

</div>

I am using filebeat to collect nginx log and sent to ealsticsearch.  
when config output.elasticsearch.index as : index: "onwards" , everything is fine, and kibana can catch the message.  
But when I change "onwards" to "onwards-%{[beat.version]}-%{[+yyyy.MM.dd]}", then I got an error:

Bulk item insert failed (i=0, status=500): {"type":"string\_index\_out\_of\_bounds\_exception","reason":"String index out of range: 0"}

And check the item was insert into elasticsearch as default index name, filebeat-6.3.2-\*\*\*\*\*,  
Don't know where goes error..  
my filebeat config:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/d/6d442bf98d662b767c25fcc5d551cb23a805ed7c.png)

---

<div class="post-metadata">

**Author:** ![Charaf\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charaf_ahmed/32/30467_2.png) [@Charaf\_Ahmed](https://discuss.elastic.co/u/Charaf_Ahmed)\
**Post date:** [August 3, 2018, 9:10am UTC](https://discuss.elastic.co/t/output-with-index-got-error/142873/2 "2018-08-03T09:10:55Z")

</div>

> [@cythwell](#):
>
> "onwards-%{[beat.version]}-%{[+yyyy.MM.dd]}"

try it instead : `onwards-%{[beat.version]}-%{+YYYY.MM.dd}`

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [August 3, 2018, 9:16am UTC](https://discuss.elastic.co/t/output-with-index-got-error/142873/3 "2018-08-03T09:16:47Z")

</div>

Not work. Actually I had already try  
onwards-%{[beat.version]}  
onwards-%{[yyyy.MM.dd]}

all fail..

---

<div class="post-metadata">

**Author:** ![Charaf\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charaf_ahmed/32/30467_2.png) [@Charaf\_Ahmed](https://discuss.elastic.co/u/Charaf_Ahmed)\
**Post date:** [August 3, 2018, 9:21am UTC](https://discuss.elastic.co/t/output-with-index-got-error/142873/4 "2018-08-03T09:21:17Z")

</div>

removed [] in {[yyyy.MM.dd]}

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [August 3, 2018, 9:22am UTC](https://discuss.elastic.co/t/output-with-index-got-error/142873/5 "2018-08-03T09:22:08Z")

</div>

> [@cythwell](#):
>
> onwards-%{[beat.version]}

you see. onwards-%{[beat.version]} also not work..

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [August 3, 2018, 9:47am UTC](https://discuss.elastic.co/t/output-with-index-got-error/142873/6 "2018-08-03T09:47:29Z")

</div>

I tried onwards-%{[beat.version]} , also not work. So it may not relate to []

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [August 6, 2018, 1:20am UTC](https://discuss.elastic.co/t/output-with-index-got-error/142873/7 "2018-08-06T01:20:34Z")

</div>

Anyone can help...  
I am new to filebeat. Any really dont know what happen..

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [August 6, 2018, 9:35am UTC](https://discuss.elastic.co/t/output-with-index-got-error/142873/8 "2018-08-06T09:35:51Z")

</div>

Hi, I had resolved this problem. Actually there are two problem.

1. As @Charaf_Ahmed said, the time define is not correct.
2. About the beat.version. As I had drop "beat" field on the below configuration , then "beat.version" no more available.

thanks @Charaf_Ahmed again for help.

---

<div class="post-metadata">

**Author:** ![Charaf\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charaf_ahmed/32/30467_2.png) [@Charaf\_Ahmed](https://discuss.elastic.co/u/Charaf_Ahmed)\
**Post date:** [August 7, 2018, 7:06am UTC](https://discuss.elastic.co/t/output-with-index-got-error/142873/9 "2018-08-07T07:06:13Z")

</div>

> [@cythwell](#):
>
> Hi, I had resolved this problem. Actually there are two problem.
> 
> 1. As @Charaf_Ahmed said, the time define is not correct.
> 2. About the beat.version. As I had drop "beat" field on the below configuration , then "beat.version" no more available.

it's cool !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2018, 7:06am UTC](https://discuss.elastic.co/t/output-with-index-got-error/142873/10 "2018-09-04T07:06:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
