# An ECS compliant Kibana index pattern must be configured to view event data on the map

**URL:** <https://discuss.elastic.co/t/an-ecs-compliant-kibana-index-pattern-must-be-configured-to-view-event-data-on-the-map/209969>\
**Category:** SIEM\
**Created:** [November 29, 2019, 1:01pm UTC](https://discuss.elastic.co/t/an-ecs-compliant-kibana-index-pattern-must-be-configured-to-view-event-data-on-the-map/209969 "2019-11-29T13:01:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![MarcusCaepio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcuscaepio/32/32458_2.png) [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Post date:** [November 29, 2019, 1:01pm UTC](https://discuss.elastic.co/t/an-ecs-compliant-kibana-index-pattern-must-be-configured-to-view-event-data-on-the-map/209969/1 "2019-11-29T13:01:42Z")

</div>

Hi all,  
I am using Filebeat module cisco to get logs. I am not storing this logs in an index called `filebeat-*` but `cisco-*`. To get the correct mapping for this pattern, I exported the filebeat template and imported it for the pattern `cisco-*`. Anyway, the SIEM Network Map tells me that

> An ECS compliant Kibana index pattern must be configured to view event data on the map. When using beats, you can run the following setup commands to create the required Kibana index patterns, otherwise you can configure them manually within Kibana settings.

I already added `cisco-*` to the default SIEM index search in management. But this doesn't seem to be solution. How can I add the `cisco-*` to the map?

Cheers,  
Marcus

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [November 29, 2019, 2:14pm UTC](https://discuss.elastic.co/t/an-ecs-compliant-kibana-index-pattern-must-be-configured-to-view-event-data-on-the-map/209969/2 "2019-11-29T14:14:54Z")

</div>

Hi Marcus,

To confirm, you need two things:

1. Add `cisco-*` for "SIEM Elasticsearch indices" under the Kibana Advanced Settings
2. A Kibana index pattern for `cisco-*`, which you can add under Kibana Management / Index Patterns.

Do you have both?

---

<div class="post-metadata">

**Author:** ![MarcusCaepio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcuscaepio/32/32458_2.png) [@MarcusCaepio](https://discuss.elastic.co/u/MarcusCaepio)\
**Post date:** [November 29, 2019, 3:23pm UTC](https://discuss.elastic.co/t/an-ecs-compliant-kibana-index-pattern-must-be-configured-to-view-event-data-on-the-map/209969/3 "2019-11-29T15:23:38Z")

</div>

Seems, it was my fault.  
I added `cisco-*` to my SIEM settings, but the index pattern was set to `cisco-asa-*`. After changing it to `cisco-*` the error disappeared.

Cheers,  
Marcus

---

<div class="post-metadata">

**Author:** ![wconnell](https://avatars.discourse-cdn.com/v4/letter/w/f4b2a3/32.png) [@wconnell](https://discuss.elastic.co/u/wconnell)\
**Post date:** [December 4, 2019, 7:23pm UTC](https://discuss.elastic.co/t/an-ecs-compliant-kibana-index-pattern-must-be-configured-to-view-event-data-on-the-map/209969/4 "2019-12-04T19:23:52Z")

</div>

I'm seeing this same error after upgrading to v7.5. I think it's due to an inconsistency in the field name that the visualization is looking for. ECS normalizes destination fields to the **destination** base name, but the documentation in v7.5 suddenly says to use the **dest** base field. See the screenshot attached.

 ![ecs_geo_error](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dc74e4f37ffe433b04c06aa2c523ace4b900a4ed.png)

I have geolocation data stored as a geo\_point field at destination.geo.location. I've got a custom visualization in my other dashboards that renders data from the same index just fine.

---

<div class="post-metadata">

**Author:** ![Ben\_Skelker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben_skelker/32/46274_2.png) [@Ben\_Skelker](https://discuss.elastic.co/u/Ben_Skelker)\
**Post date:** [December 5, 2019, 2:02pm UTC](https://discuss.elastic.co/t/an-ecs-compliant-kibana-index-pattern-must-be-configured-to-view-event-data-on-the-map/209969/5 "2019-12-05T14:02:14Z")

</div>

Thanks for pointing that out. I've opened a [PR](https://github.com/elastic/stack-docs/pull/729) to fix it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2020, 2:02pm UTC](https://discuss.elastic.co/t/an-ecs-compliant-kibana-index-pattern-must-be-configured-to-view-event-data-on-the-map/209969/6 "2020-01-02T14:02:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
