# 404 GET \_fields\_for\_wildcards error in kibana

**URL:** <https://discuss.elastic.co/t/404-get-fields-for-wildcards-error-in-kibana/134513>\
**Category:** Kibana\
**Created:** [June 5, 2018, 2:50am UTC](https://discuss.elastic.co/t/404-get-fields-for-wildcards-error-in-kibana/134513 "2018-06-05T02:50:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![kesha](https://avatars.discourse-cdn.com/v4/letter/k/f0a364/32.png) [@kesha](https://discuss.elastic.co/u/kesha)\
**Post date:** [June 5, 2018, 2:50am UTC](https://discuss.elastic.co/t/404-get-fields-for-wildcards-error-in-kibana/134513/1 "2018-06-05T02:50:22Z")

</div>

#### Kibana version: 6.2.3

#### Elasticsearch version:6.2.3

#### Bowser version: Firefox 60.0.1 (64-bit)

#### OS: CentOS 6

#### Apache Reverse Proxy Conf:

\<Location /elasticsearch\>  
ProxyPass [http://localhost:5601/elasticsearch](http://localhost:5601/elasticsearch)  
ProxyPassReverse [http://localhost:5601/elasticsearch](http://localhost:5601/elasticsearch)  
\<Location /app/kibana\>  
ProxyPass [http://localhost:5601/app/kibana](http://localhost:5601/app/kibana)  
ProxyPassReverse [http://localhost:5601/app/kibana](http://localhost:5601/app/kibana)  
\<Location /api/saved\_objects\>  
ProxyPass [http://localhost:5601/api/saved\_objects](http://localhost:5601/api/saved_objects)  
ProxyPassReverse [http://localhost:5601/api/saved\_objects](http://localhost:5601/api/saved_objects)  
\<Location /ui/fonts/open\_sans/\>  
ProxyPass [http://localhost:5601/ui/fonts/open\_sans/](http://localhost:5601/ui/fonts/open_sans/)  
ProxyPassReverse [http://localhost:5601/ui/fonts/open\_sans/](http://localhost:5601/ui/fonts/open_sans/)  
\<Location /bundles\>  
ProxyPass [http://localhost:5601/bundles](http://localhost:5601/bundles)  
ProxyPassReverse [http://localhost:5601/bundles](http://localhost:5601/bundles)

#### Description of the problem:

I put Kibana behind the apache reverse proxy. Many things seem fine, I can access kibana through [https://XXXXX/app/kibana](https://XXXXX/app/kibana) and I can also find my indexes in elasticsearch through Management -\> Create New Index, I can also find data in Discover. Everything's fine until maybe some configs I don't know have been changed. When I want to refresh an index, there will be 404 GET \_fields\_for\_wildcards error. If I go create a new index, hit the create index pattern button, there will also be 404 Get \_fields\_for\_wildcards error.

In kibana.yml, only server.name is enabled. Before the crash, I've set the server.bathPath to "/kibana" and it works fine. But when crash happens it keeps prompting the red label "kibana is not loaded properly, balabala" until I comment the server.bathPath. I'm very confused about that sudden crash.

Refresh iptables index:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/e/eec981e0317508b99c9507cd7612cc2c2080c5a8.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/6/66c3b35e2e1e9474a3e61884d50cf543cbcf2961.png)

Create dnsq index:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/d/7d2e01d9973003a6c0091602fe61b5fd47a6f34c.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/1/01722f52aa9384660336b7b662b58326570e36f3.png)

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 5, 2018, 11:01am UTC](https://discuss.elastic.co/t/404-get-fields-for-wildcards-error-in-kibana/134513/2 "2018-06-05T11:01:19Z")

</div>

Hey @kesha, you're only proxying specific URLs to Kibana, which is really brittle, is there any reason why you aren't doing something similar to the following?

```auto
<Location />
  ProxyPass http://localhost:5601/
  ProxyPassReverse http://localhost:5601/
</Location>

```

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 5, 2018, 11:23am UTC](https://discuss.elastic.co/t/404-get-fields-for-wildcards-error-in-kibana/134513/3 "2018-06-05T11:23:01Z")

</div>

Or, if you'd like to host Kibana on a virtual directory, you can set the following in your kibana.yml

```auto
server.basePath: /kibana

```

and then use the following Apache configuration:

```auto
<Location /kibana/ >
  ProxyPass http://localhost:5601/
  ProxyPassReverse http://localhost:5601/
</Location>

```

---

<div class="post-metadata">

**Author:** ![kesha](https://avatars.discourse-cdn.com/v4/letter/k/f0a364/32.png) [@kesha](https://discuss.elastic.co/u/kesha)\
**Post date:** [June 5, 2018, 10:56pm UTC](https://discuss.elastic.co/t/404-get-fields-for-wildcards-error-in-kibana/134513/4 "2018-06-05T22:56:37Z")

</div>

Hi @Brandon_Kobel, thank you for the reply! I've modified the apache config and kibana.yml just as you said and they work perfectly. Actually I want to proxy kibana on a real+virtual directory, like [https://XXXXX/](https://XXXXX/){real directory}/{virtual directory}/, for product purpose. I'm figuring out how to do this. But I'm a newbie and I'm still learning. I'm still confused about the difference between [https://XXXXX/kibana/](https://XXXXX/kibana/) and [https://XXXXX/app/kibana/](https://XXXXX/app/kibana/). Why the latter URL is brittle and the former is good?

Thanks!  
Ke

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 6, 2018, 11:10am UTC](https://discuss.elastic.co/t/404-get-fields-for-wildcards-error-in-kibana/134513/5 "2018-06-06T11:10:13Z")

</div>

Hey @kesha, hosting Kibana at a basePath of /kibana/ makes [https://XXXXX/kibana/](https://XXXXX/kibana/) and a viable hosting strategy, and all Kibana URLS will be generated as children of [https://XXXXX/kibana/](https://XXXXX/kibana/), so you get [https://XXXXX/kibana/app/kibana](https://XXXXX/kibana/app/kibana), [https://XXXXX/kibana/api/saved\_objects](https://XXXXX/kibana/api/saved_objects), etc.

the /app/kibana route is an internal route that we use, so taking your previous approach you have to ensure that all internal routes are designated to be proxied to Kibana. That's what was happening previously, there was an api/index\_patterns route which you missed, and it was causing the 404s to appear.

---

<div class="post-metadata">

**Author:** ![kesha](https://avatars.discourse-cdn.com/v4/letter/k/f0a364/32.png) [@kesha](https://discuss.elastic.co/u/kesha)\
**Post date:** [June 6, 2018, 4:17pm UTC](https://discuss.elastic.co/t/404-get-fields-for-wildcards-error-in-kibana/134513/6 "2018-06-06T16:17:01Z")

</div>

Thanks @Brandon_Kobel! That really helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2018, 4:17pm UTC](https://discuss.elastic.co/t/404-get-fields-for-wildcards-error-in-kibana/134513/7 "2018-07-04T16:17:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
