# Unable to create index after x-pack

**URL:** <https://discuss.elastic.co/t/unable-to-create-index-after-x-pack/76559>\
**Category:** Logstash\
**Created:** [February 26, 2017, 9:46pm UTC](https://discuss.elastic.co/t/unable-to-create-index-after-x-pack/76559 "2017-02-26T21:46:52Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankitc7](https://avatars.discourse-cdn.com/v4/letter/a/71c47a/32.png) [@ankitc7](https://discuss.elastic.co/u/ankitc7)\
**Post date:** [February 26, 2017, 9:46pm UTC](https://discuss.elastic.co/t/unable-to-create-index-after-x-pack/76559/1 "2017-02-26T21:46:52Z")

</div>

Hello, Filebeat, Logstash, Elasticsearch were working sucessfully until I installed x-pack.  
Now when I try to index data, I get this:  
[2017-02-26T16:10:45,438][WARN][logstash.outputs.elasticsearch] Failed action. {:status=\>404, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-2017.02.26", :\_type=\>"log", :\_routing=\>nil}, 2017-02-26T21:10:39.878Z student 86.1.76.62 - - [04/Jan/2015:05:30:37 +0000] "GET /style2.css HTTP/1.1" 200 4877 "[http://www.semicomplete.com/projects/xdotool/](http://www.semicomplete.com/projects/xdotool/)" "Mozilla/5.0 (X11; Linux x86\_64; rv:24.0) Gecko/20140205 Firefox/24.0 Iceweasel/24.3.0"], :response=\>{"index"=\>{"\_index"=\>"logstash-2017.02.26", "\_type"=\>"log", "\_id"=\>nil, "status"=\>404, "error"=\>{"type"=\>"index\_not\_found\_exception", "reason"=\>"no such index", "resource.type"=\>"index\_expression", "[resource.id](http://resource.id)"=\>"logstash-2017.02.26", "index\_uuid"=\>"_na_", "index"=\>"logstash-2017.02.26"}}}}

I have setup new user & role for logstash per [documentation](https://www.elastic.co/guide/en/x-pack/current/logstash.html)  
I also updated .conf to include credentials:  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
user =\> logstash\_internal  
password =\> changeme  
}

Can you you help why Logstash is not able to create new index?

Thanks,  
AC

---

<div class="post-metadata">

**Author:** ![jkuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkuang/32/72637_2.png) [@jkuang](https://discuss.elastic.co/u/jkuang)\
**Post date:** [February 28, 2017, 7:17pm UTC](https://discuss.elastic.co/t/unable-to-create-index-after-x-pack/76559/2 "2017-02-28T19:17:10Z")

</div>

Did you update the index name before running the post ? If not, you only have permission to create an index starting with logstash-\*.

```auto
POST _xpack/security/role/logstash_reader
{
  "indices": [
    {
      "names": ["logstash-*"], 
      "privileges": ["read","view_index_metadata"]
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![ankitc7](https://avatars.discourse-cdn.com/v4/letter/a/71c47a/32.png) [@ankitc7](https://discuss.elastic.co/u/ankitc7)\
**Post date:** [February 28, 2017, 10:02pm UTC](https://discuss.elastic.co/t/unable-to-create-index-after-x-pack/76559/3 "2017-02-28T22:02:57Z")

</div>

Jimmy,

I'm not sure which index to rename. So logstash is supposed to create a new index from the data coming from filebeat. It should have created index logstash-2017.02.26 but I don't think it's able to create the index.

Here's the .conf:  
input {  
beats {  
port =\> "5077"  
}  
}

filter {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}"}  
}  
geoip {  
source =\> "clientip"  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
user =\> logstash\_internal  
password =\> changeme  
}

}

I also added logstash\_reader role as you suggested and assigned to logstash\_internal?

Ankit

---

<div class="post-metadata">

**Author:** ![jkuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkuang/32/72637_2.png) [@jkuang](https://discuss.elastic.co/u/jkuang)\
**Post date:** [February 28, 2017, 10:42pm UTC](https://discuss.elastic.co/t/unable-to-create-index-after-x-pack/76559/4 "2017-02-28T22:42:09Z")

</div>

Since the data is coming in from beat, the index that will be created will be something "beat" .e.g. packetbeat-\*.

If you followed the directions on the doc, the post api only created the role with permission to logstash-\* indices . The problem is your user does not have access to create the "beat" indice e.g. packbeat-\* .

You will need to go into Kibana \> Management \> roles \> and put " \* " for the indices field or specify the exact beat e.g. packetbeat-\* and not logstash-\*.

---

<div class="post-metadata">

**Author:** ![ankitc7](https://avatars.discourse-cdn.com/v4/letter/a/71c47a/32.png) [@ankitc7](https://discuss.elastic.co/u/ankitc7)\
**Post date:** [February 28, 2017, 10:55pm UTC](https://discuss.elastic.co/t/unable-to-create-index-after-x-pack/76559/5 "2017-02-28T22:55:04Z")

</div>

I changed the indices AND privileges field to \* for both logstash\_writer and logstash\_reader but no luck.  
Also, before x-pack, when everything was running okay, filebeat was pushing data into logstash and indices were getting created with logstash- prefix. And I think that's was logstash is still trying to create the index but not able to.

Any other ideas?

---

<div class="post-metadata">

**Author:** ![jkuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkuang/32/72637_2.png) [@jkuang](https://discuss.elastic.co/u/jkuang)\
**Post date:** [February 28, 2017, 11:09pm UTC](https://discuss.elastic.co/t/unable-to-create-index-after-x-pack/76559/6 "2017-02-28T23:09:30Z")

</div>

Yes, you are right . From beat \> logstash \> indices will have logstash-prefix. When going from beat \> ES \> indices will have _beat-prefix e.g. packetbeat-_

You can't change privileges to \* . You have to select the drop down option "all". For the indices field you can set to \* .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2017, 11:09pm UTC](https://discuss.elastic.co/t/unable-to-create-index-after-x-pack/76559/7 "2017-03-28T23:09:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
