# \[Solved\] "message":"write EPIPE","name":"Error"

**URL:** <https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343>\
**Category:** Kibana\
**Created:** [November 17, 2016, 7:50am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343 "2016-11-17T07:50:26Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![ironbeast](https://avatars.discourse-cdn.com/v4/letter/i/b5a626/32.png) [@ironbeast](https://discuss.elastic.co/u/ironbeast)\
**Post date:** [November 17, 2016, 7:50am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/1 "2016-11-17T07:50:26Z")

</div>

Dear Al

After I removed mij filebeat index from kibana, kibana doesn't load the webinterface anymore

 ![](https://us1.discourse-cdn.com/elastic/original/2X/f/f4d08384079f4f858112337c2666037b1cd5bea7.png)

This is the error I have i my logs:

> {"type":"log","@timestamp":"2016-11-17T07:45:32Z","tags":["connection","client","error"],"pid":20281,"level":"error","message":"write EPIPE","error":{"message":"write EPIPE","name":"Error","stack":"Error: write EPIPE\n at exports.\_errnoException (util.js:1026:11)\n at WriteWrap.afterWrite (net.js:799:14)","code":"EPIPE"}}

I have no Idea what went wrong. Just removed the filebeat index. I still have 5 other indexes in kibana, but as you can see, nothing is loaded...

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2016, 8:01am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/2 "2016-11-17T08:01:27Z")

</div>

Are you able to go to the Management console and change the default index pattern? Is this an on-premise or cloud deployment? Is this a fresh 5.0.0 install or did you upgrade from a previous version?

---

<div class="post-metadata">

**Author:** ![ironbeast](https://avatars.discourse-cdn.com/v4/letter/i/b5a626/32.png) [@ironbeast](https://discuss.elastic.co/u/ironbeast)\
**Post date:** [November 17, 2016, 8:46am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/3 "2016-11-17T08:46:41Z")

</div>

This is on premise. I can't do anything. Only have the screen in the screen shot and on all the possible menu items, I get the error shown in the logs

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2016, 9:13am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/4 "2016-11-17T09:13:48Z")

</div>

The reason I asked these questions is that I had a very similar issue a while ago, but has not able to reproduce it once I got it resolved. I was able to 'unlock' the UI by inserting a dummy record into an index covered by the default index pattern and then change the default index pattern in the management panel.

Would it be possible for you to upload Kibana and Elasticsearch logs somewhere so we can have a look at them?

---

<div class="post-metadata">

**Author:** ![ironbeast](https://avatars.discourse-cdn.com/v4/letter/i/b5a626/32.png) [@ironbeast](https://discuss.elastic.co/u/ironbeast)\
**Post date:** [November 17, 2016, 9:22am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/5 "2016-11-17T09:22:30Z")

</div>

You can find the kibana logs here. This is all the log I have after falsing the silent option in kibana:

> [https://nextcloud.brusselsairport.be/index.php/s/ust0hBzCtvvvMBQ](https://nextcloud.brusselsairport.be/index.php/s/ust0hBzCtvvvMBQ)

No logging is showing up in elasticsearch

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2016, 9:27am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/6 "2016-11-17T09:27:45Z")

</div>

Did the workaround 'unlock' Kibana or are you still stuck?

---

<div class="post-metadata">

**Author:** ![ironbeast](https://avatars.discourse-cdn.com/v4/letter/i/b5a626/32.png) [@ironbeast](https://discuss.elastic.co/u/ironbeast)\
**Post date:** [November 17, 2016, 9:36am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/7 "2016-11-17T09:36:53Z")

</div>

I can't do anything in the Management UI... So... 🙂 No, not yet. I reran the script for creating the beats dashboard and index in kibana, bu t no luck...

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2016, 9:38am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/8 "2016-11-17T09:38:24Z")

</div>

I just had to add some data into one of the default indices. I did not make any changes to Kibana. Can you turn on a beat to get some data indexed? Once you have changed the default index pattern you can always delete it again.

---

<div class="post-metadata">

**Author:** ![ironbeast](https://avatars.discourse-cdn.com/v4/letter/i/b5a626/32.png) [@ironbeast](https://discuss.elastic.co/u/ironbeast)\
**Post date:** [November 17, 2016, 9:44am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/9 "2016-11-17T09:44:39Z")

</div>

There is data coming in for the filebeat index in elasticsearch. I just can't do anything in the gui to change or add the index ☹ .

Is there a way to change the default index or add the index for filebeat trough the command line?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2016, 9:47am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/10 "2016-11-17T09:47:37Z")

</div>

So there is now data in the indices that make up the default index pattern? Have you tried restarting Kibana?

---

<div class="post-metadata">

**Author:** ![ironbeast](https://avatars.discourse-cdn.com/v4/letter/i/b5a626/32.png) [@ironbeast](https://discuss.elastic.co/u/ironbeast)\
**Post date:** [November 17, 2016, 9:56am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/11 "2016-11-17T09:56:08Z")

</div>

Yes, there was never no data in the index. I removed the index because there was a problem with the geo mapping. And I wanted to force a new index for filebeat (Like I did with the previous version). But this time the interface went blank 😃

---

<div class="post-metadata">

**Author:** ![ironbeast](https://avatars.discourse-cdn.com/v4/letter/i/b5a626/32.png) [@ironbeast](https://discuss.elastic.co/u/ironbeast)\
**Post date:** [November 17, 2016, 9:59am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/12 "2016-11-17T09:59:18Z")

</div>

Timelion is the only thing that is still working.

> [root@elasticsearch01prod filebeat]# curl 'localhost:9200/\_cat/indices?v'  
> health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
> green open maillog-2016.10.14 XfmXZ89iQXGolI5h7PHhjg 2 1 548701 0 566.5mb 283.2mb  
> green open ovirt-2016.10.25 s8Qkw4knSfWEhKGqyv1fyw 5 1 5315342 0 4.1gb 2gb  
> green open syslog-2016.11.04 y7IrzfmaRsKUE-cUmPfpkw 5 1 12 0 160.8kb 80.4kb  
> green open syslog-2016.10.14 YdUtHsRiTfGiDHvmf3KSAw 5 1 791209 0 539.7mb 269.8mb  
> green open maillog-2016.10.25 T0fT6wo7SQCEGVGjBm6P\_g 2 1 553579 0 575.9mb 287.9mb  
> green open basis-2016.11.15 LF7NM0zKTJaoL6G5TWo1og 5 1 26009 0 48.7mb 24.2mb  
> green open .marvel-es-1-2016.10.12 gP4581yRQqOeS7e66PAnYA 1 1 0 0 318b 159b  
> green open spipe 6tIo\_k97RbSwnYKKy8-YeQ 5 1 0 0 1.5kb 795b  
> green open basis-2016.10.15 gu9g4oNTT4y-Zf8FQf6Djg 5 1 30829 0 61.8mb 30.9mb  
> green open .marvel-es-1-2016.10.17 OgP7drHYQpq-zUSpYqC7lg 1 1 304561 8330 290mb 145mb  
> green open .marvel-es-1-2016.10.11 auPZP4MfQmG4EEQbeZu0eA 1 1 0 0 318b 159b  
> green open maillog-2016.10.26 zW8pinIuRLGHCfi5Vy3L1w 2 1 562399 0 586.5mb 293.2mb  
> green open syslog-2016.11.12 -kF0sB0iRDadBgJjCkjXug 5 1 24487 0 25.5mb 12.6mb  
> green open syslog-2016.09.27 DfS7Cvq8TT2Jj-0xmdXywA 5 1 763356 0 505mb 252.5mb  
> green open syslog-2016.09.17 JknGRtIwS2-nSgJ4ocrVJg 5 1 675540 0 445.4mb 222.7mb  
> green open filebeat-2016.11.16 1DFKRGmRTouH1FvbGg5YBg 5 1 47891656 0 25.8gb 12.9g

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2016, 10:02am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/13 "2016-11-17T10:02:11Z")

</div>

Try inserting a single dummy record , e.g. `'{"field1":1}'` into an index covered by the default pattern you have configured. That worked for me. If it does not for you, it is most likely a different issue.

---

<div class="post-metadata">

**Author:** ![ironbeast](https://avatars.discourse-cdn.com/v4/letter/i/b5a626/32.png) [@ironbeast](https://discuss.elastic.co/u/ironbeast)\
**Post date:** [November 17, 2016, 10:09am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/14 "2016-11-17T10:09:56Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> '{"field1":1}'

[root@elasticsearch01prod ~]# curl -XPUT 'localhost:9200/filebeat/foo/1?pretty' -d'

> {"field1":1}'  
> {  
> "\_index" : "filebeat",  
> "\_type" : "foo",  
> "\_id" : "1",  
> "\_version" : 1,  
> "result" : "created",  
> "\_shards" : {  
> "total" : 2,  
> "successful" : 2,  
> "failed" : 0  
> },  
> "created" : true  
> }

Still same error in kibana.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2016, 10:24am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/15 "2016-11-17T10:24:08Z")

</div>

And your default index pattern was`'filebeat*'` and not`'filebeat-*'` or something similar?

---

<div class="post-metadata">

**Author:** ![ironbeast](https://avatars.discourse-cdn.com/v4/letter/i/b5a626/32.png) [@ironbeast](https://discuss.elastic.co/u/ironbeast)\
**Post date:** [November 17, 2016, 10:33am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/16 "2016-11-17T10:33:49Z")

</div>

No you are right... The deafult index is filebeat-_... But what am I doing wrong here...?  
[root@elasticsearch01prod ~]# curl -XPUT '[http://localhost:9200/filebeat-](http://localhost:9200/filebeat-)_/foo/1?pretty' -d'  
{"field1":1}'  
{  
"error" : {  
"root\_cause" : [  
{  
"type" : "invalid\_index\_name\_exception",  
"reason" : "Invalid index name [filebeat-_], must not contain the following characters [, ", , \, \<, |, ,, \>, /, ?]",  
"index\_uuid" : "na",  
"index" : "filebeat-"  
}  
],  
"type" : "invalid\_index\_name\_exception",  
"reason" : "Invalid index name [filebeat-_], must not contain the following characters [, ", _, \, \<, |, ,, \>, /, ?]",  
"index\_uuid" : "na",  
"index" : "filebeat-_"  
},  
"status" : 400  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2016, 10:42am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/17 "2016-11-17T10:42:49Z")

</div>

You can not have a index name with a star in it. Index into `filebeat-2016.11.17` instead, which should match the pattern.

---

<div class="post-metadata">

**Author:** ![ironbeast](https://avatars.discourse-cdn.com/v4/letter/i/b5a626/32.png) [@ironbeast](https://discuss.elastic.co/u/ironbeast)\
**Post date:** [November 17, 2016, 11:15am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/18 "2016-11-17T11:15:20Z")

</div>

Well, that I did first:

> [root@elasticsearch01prod ~]# curl -XPUT 'localhost:9200/filebeat-2016.11.17/foo/1?pretty' -d'  
> {"field1":1}'  
> {  
> "\_index" : "filebeat-2016.11.17",  
> "\_type" : "foo",  
> "\_id" : "1",  
> "\_version" : 1,  
> "result" : "created",  
> "\_shards" : {  
> "total" : 2,  
> "successful" : 2,  
> "failed" : 0  
> },  
> "created" : true  
> }

But that still gave nothing... So I thought I tried the next best thing :-)...  
Restarted kibana... Still the same... ☹  
{"type":"log","@timestamp":"2016-11-17T10:47:13Z","tags":["connection","client","error"],"pid":31767,"level":"error","message":"write EPIPE","error":{"message":"write EPIPE","name":"Error","stack":"Error: write EPIPE\n at exports.\_errnoException (util.js:1026:11)\n at WriteWrap.afterWrite (net.js:799:14)","code":"EPIPE"}}  
{"type":"log","@timestamp":"2016-11-17T11:14:52Z","tags":["connection","client","error"],"pid":31767,"level":"error","message":"write EPIPE","error":{"message":"write EPIPE","name":"Error","stack":"Error: write EPIPE\n at exports.\_errnoException (util.js:1026:11)\n at WriteWrap.afterWrite (net.js:799:14)","code":"EPIPE"}}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2016, 11:30am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/19 "2016-11-17T11:30:49Z")

</div>

Does Kibana connect directly to Elasticsearch or is there some kind of proxy in between? Are they on the same host?

---

<div class="post-metadata">

**Author:** ![ironbeast](https://avatars.discourse-cdn.com/v4/letter/i/b5a626/32.png) [@ironbeast](https://discuss.elastic.co/u/ironbeast)\
**Post date:** [November 17, 2016, 11:36am UTC](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343/20 "2016-11-17T11:36:11Z")

</div>

Directly.

[Next page](https://discuss.elastic.co/t/solved-message-write-epipe-name-error/66343.md?page=2)
