# Unable to create index pattern in kibana 7.2

**URL:** <https://discuss.elastic.co/t/unable-to-create-index-pattern-in-kibana-7-2/193269>\
**Category:** Kibana\
**Created:** [August 1, 2019, 7:42am UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-in-kibana-7-2/193269 "2019-08-01T07:42:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![BS\_Lee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bs_lee/32/51401_2.png) [@BS\_Lee](https://discuss.elastic.co/u/BS_Lee)\
**Post date:** [August 1, 2019, 7:42am UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-in-kibana-7-2/193269/1 "2019-08-01T07:42:05Z")

</div>

Hi, all  
I am trying to make an ELK stack sample after installation of ELK and Filebeat.  
But I couldn’t “create an index pattern” in Kibana(version 7.2)  
Please let me know what’s wrong in my configuration?  
I really appreciate your kind help and assistance before ahead.

Regards,  
Bryan

Please refer to my log and config as below.

1. [http://localhost:9200/\_cat/indices?v](http://localhost:9200/_cat/indices?v)

health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
yellow open test 1lU0a11JRe2Bs9GrwBokFA 1 1 0 0 283b 283b  
green open kibana\_sample\_data\_ecommerce eNObCUqUQM6M5k67uSXraA 1 0 0 0 283b 283b  
yellow open seoul-metro-2014 XvPGIidFTuilKpiU-exncA 1 1 0 0 283b 283b  
green open .kibana\_task\_manager o98jbwBFSLSaIlSKcptBWA 1 0 2 4 74.2kb 74.2kb  
green open .kibana\_1 iN1f-hqmSTi4V4St\_IFeYw 1 0 19 8 52.8kb 52.8kb

Question1 : Why docs.count is zero?

1. elastic search log

[2019-08-01T15:42:42,572][INFO][o.e.c.r.a.DiskThresholdMonitor] [MacBook-Pro.local] low disk watermark [85%] exceeded on [ic5dz2\_-SpuzfMRaNjTurw][icpsui-MacBook-Pro.local][/elastic-demo/elasticsearch-7.2.0/data/nodes/0] free: 13.5gb[13.3%], replicas will not be assigned to this node  
[2019-08-01T15:43:12,603][INFO][o.e.c.r.a.DiskThresholdMonitor] [MacBook-Pro.local] low disk watermark [85%] exceeded on [ic5dz2\_-SpuzfMRaNjTurw][icpsui-MacBook-Pro.local][/elastic-demo/elasticsearch-7.2.0/data/nodes/0] free: 12.5gb[12.3%], replicas will not be assigned to this node  
[2019-08-01T15:43:42,634][INFO][o.e.c.r.a.DiskThresholdMonitor] [MacBook-Pro.local] low disk watermark [85%] exceeded on [ic5dz2\_-SpuzfMRaNjTurw][icpsui-MacBook-Pro.local][/elastic-demo/elasticsearch-7.2.0/data/nodes/0] free: 11.2gb[11.1%], replicas will not be assigned to this node  
[2019-08-01T15:44:12,651][INFO][o.e.c.r.a.DiskThresholdMonitor] [MacBook-Pro.local] low disk watermark [85%] exceeded on [ic5dz2\_-SpuzfMRaNjTurw][icpsui-MacBook-Pro.local][/elastic-demo/elasticsearch-7.2.0/data/nodes/0] free: 11.2gb[11.1%], replicas will not be assigned to this node  
[2019-08-01T15:44:42,721][INFO][o.e.c.r.a.DiskThresholdMonitor] [MacBook-Pro.local] low disk watermark [85%] exceeded on [ic5dz2\_-SpuzfMRaNjTurw][icpsui-MacBook-Pro.local][/elastic-demo/elasticsearch-7.2.0/data/nodes/0] free: 11.2gb[11.1%], replicas will not be assigned to this node  
[2019-08-01T15:45:12,762][INFO][o.e.c.r.a.DiskThresholdMonitor] [MacBook-Pro.local] low disk watermark [85%] exceeded on [ic5dz2\_-SpuzfMRaNjTurw][icpsui-MacBook-Pro.local][/elastic-demo/elasticsearch-7.2.0/data/nodes/0] free: 11.2gb[11.1%], replicas will not be assigned to this node  
[2019-08-01T15:45:42,795][INFO][o.e.c.r.a.DiskThresholdMonitor] [MacBook-Pro.local] low disk watermark [85%] exceeded on [ic5dz2\_-SpuzfMRaNjTurw][icpsui-MacBook-Pro.local][/elastic-demo/elasticsearch-7.2.0/data/nodes/0] free: 12.2gb[12%], replicas will not be assigned to this node

Question2 : How can I handle the limitation of “the low disk watermark”?

---

<div class="post-metadata">

**Author:** ![kimjmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimjmin/32/15223_2.png) [@kimjmin](https://discuss.elastic.co/u/kimjmin)\
**Post date:** [August 5, 2019, 11:35pm UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-in-kibana-7-2/193269/2 "2019-08-05T23:35:13Z")

</div>

1. First, too low disk space. Elasticsearch does not allocates shards if free disk space is under 15%

2. If you are creating new dashboards from the beginning, try to erase .kibana\_1 index and load kibana again. But it can erase all your past works. so be careful.

---

<div class="post-metadata">

**Author:** ![BS\_Lee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bs_lee/32/51401_2.png) [@BS\_Lee](https://discuss.elastic.co/u/BS_Lee)\
**Post date:** [August 5, 2019, 11:40pm UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-in-kibana-7-2/193269/3 "2019-08-05T23:40:06Z")

</div>

I really appreciated your soon and kind reply.  
I will try to solve this problems according to your guide.  
After test, I'd like to share the result in this posting.

---

<div class="post-metadata">

**Author:** ![kumar8055](https://avatars.discourse-cdn.com/v4/letter/k/278dde/32.png) [@kumar8055](https://discuss.elastic.co/u/kumar8055)\
**Post date:** [August 6, 2019, 4:56am UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-in-kibana-7-2/193269/4 "2019-08-06T04:56:27Z")

</div>

Hi BS\_Lee,

Try to increase the memory of your cluster or delete the unnecessary indices. ES never allows the docs because shards will not distributed as it is having low memory.

Clear the memory or increase it. It will work

---

<div class="post-metadata">

**Author:** ![BS\_Lee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bs_lee/32/51401_2.png) [@BS\_Lee](https://discuss.elastic.co/u/BS_Lee)\
**Post date:** [August 6, 2019, 5:02am UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-in-kibana-7-2/193269/5 "2019-08-06T05:02:30Z")

</div>

thanks for your kind information.

---

<div class="post-metadata">

**Author:** ![BS\_Lee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bs_lee/32/51401_2.png) [@BS\_Lee](https://discuss.elastic.co/u/BS_Lee)\
**Post date:** [August 6, 2019, 7:35am UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-in-kibana-7-2/193269/6 "2019-08-06T07:35:58Z")

</div>

Thanks to your comments, I could fix these problems.  
But I am facing a new problem as below.  
Please let me know how to handle it.

[2019-08-06T16:31:48,432][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"seoul-metro-2014", :\_type=\>"seoul-metro", :routing=\>nil}, #LogStash::Event:0x79591b45], :response=\>{"index"=\>{"\_index"=\>"seoul-metro-2014", "\_type"=\>"seoul-metro", "\_id"=\>"YenXZWwBhpFyamYfV0v1", "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"mapper [station\_geo] of different type, current\_type [geo\_point], merged\_type [ObjectMapper]"}}}}

My configuration is something wrong or the index and its type is not correct?

I truly hope to finish the issues.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 3, 2019, 7:36am UTC](https://discuss.elastic.co/t/unable-to-create-index-pattern-in-kibana-7-2/193269/7 "2019-09-03T07:36:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
