# Winlogbeats indices created but docs appear as deleted

**URL:** <https://discuss.elastic.co/t/winlogbeats-indices-created-but-docs-appear-as-deleted/81230>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 4, 2017, 11:12pm UTC](https://discuss.elastic.co/t/winlogbeats-indices-created-but-docs-appear-as-deleted/81230 "2017-04-04T23:12:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mkorayem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkorayem/32/85774_2.png) [@mkorayem](https://discuss.elastic.co/u/mkorayem)\
**Post date:** [April 4, 2017, 11:12pm UTC](https://discuss.elastic.co/t/winlogbeats-indices-created-but-docs-appear-as-deleted/81230/1 "2017-04-04T23:12:01Z")

</div>

Hi

**Problem:**  
Indices are created, and I see traffic on port 5044 but all docs are created as deleted

 ![](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9ecd02750b9aaaaf6a269ffcc51d820c2347d01d.PNG)

**Configuration**  
I configured the system as follows:

Winlogbeats --\> Logstash --\> Elasticsearch --\> Kibana

Installed the winlogbeats on the server Windows 2012 R2 64bit

and invoked this command on Powershell as per doucmentation and it passed

Invoke-WebRequest -Method Put -InFile winlogbeat.template.json -Uri [http://elk:9200/\_template/winlogbeat?pretty](http://elk:9200/_template/winlogbeat?pretty)

**Winlogbeats**

```auto
winlogbeat.event_logs:
  - name: Application
    #ignore_older: 72h
  - name: Security
  - name: System

#----------------------------- Logstash output --------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["elk:5044"]

#================================ Logging =====================================
logging.to_files: true
logging.files:
    path: C:\ProgramData\winlogbeat\Logs
logging.level: info

```

Logstash

```auto
input
{
    beats
    {
        ssl => false
        host => "0.0.0.0"
        port => 5044
    }
    gelf
    {
        host => "0.0.0.0"
        port => 12201
    }
    http
    {
        ssl => false
        host => "0.0.0.0"
        port => 8888
    }
    tcp
    {
        mode => "server"
        host => "0.0.0.0"
        port => 5010
    }
    udp
    {
        host => "0.0.0.0"
        port => 5000
    }
}
filter {
        if [type] == "syslog"
        {
                mutate { add_tag => "syslog_tag" }
                grok
                {
                        match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
                        add_field => ["received_at", "%{@timestamp}"]
                        add_field => ["received_from", "%{host}"]
                }
                syslog_pri { }
                date
                {
                        match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
                }
        }
        if [type] == "eventlog"
        {
                grok
                {
                        match => ["TimeCreated", "Date\(%{NUMBER:timestamp}\)"]
                }
                date
                {
                        match => ["timestamp", "UNIX_MS"]
                }
        }
}
output
{
        if "syslog_tag" in [tags]
        {
                elasticsearch
                        {
                                hosts => ["localhost:9200"]
                                sniffing => true
                                manage_template => false
                                index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
                                document_type => "%{[@metadata][type]}"
                        }
        }
        if [type] == "wineventlog"
        {
                elasticsearch
                {
                        hosts => ["127.0.0.1:9200"]
                        document_id => "%{logstash_checksum}"
                        index => "winlogbeat-%{+YYYY.MM.dd}"
                }
        }
        if [type] == "eventlog"
        {
                elasticsearch
                {
                        hosts => ["127.0.0.1:9200"]
                        index => "winbeatlog-%{+YYYY.MM.dd}"
                }
        }
        elasticsearch
        {
                hosts => ["127.0.0.1:9200"]
                document_id => "%{logstash_checksum}"
                index => "logstash-%{+YYYY.MM.dd}"
        }

}

```

**ElasticSearch**

```auto
cluster.name: elasticsearch
# ---------------------------------- Network -----------------------------------
network.host: 0.0.0.0
network.publish_host: 192.168.10.137
http.port: 9200
transport.tcp.port: 9300

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 4, 2017, 11:29pm UTC](https://discuss.elastic.co/t/winlogbeats-indices-created-but-docs-appear-as-deleted/81230/2 "2017-04-04T23:29:49Z")

</div>

Try removing the `document_id` from the elasticsearch output for the `winlogbeat` type. In accordance with the [docs](https://www.elastic.co/guide/en/beats/libbeat/5.3/logstash-installation.html#logstash-setup) you should use:

```auto
  elasticsearch {
    hosts => "localhost:9200"
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}" 
    document_type => "%{[@metadata][type]}" 
  }

```

So add `manage_template` and `document_type` and remove `document_id`.

---

<div class="post-metadata">

**Author:** ![mkorayem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mkorayem/32/85774_2.png) [@mkorayem](https://discuss.elastic.co/u/mkorayem)\
**Post date:** [April 5, 2017, 7:09am UTC](https://discuss.elastic.co/t/winlogbeats-indices-created-but-docs-appear-as-deleted/81230/3 "2017-04-05T07:09:51Z")

</div>

Thank you, It worked like charm

Would you please tell me why the document\_id was making a problem?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2017, 7:09am UTC](https://discuss.elastic.co/t/winlogbeats-indices-created-but-docs-appear-as-deleted/81230/4 "2017-05-03T07:09:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
