# APM Agent logs shown on Discover but not on APM UI

**URL:** <https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706>\
**Category:** APM\
**Tags:** java\
**Created:** [November 19, 2021, 3:17pm UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706 "2021-11-19T15:17:36Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![jorsec](https://avatars.discourse-cdn.com/v4/letter/j/9f8e36/32.png) [@jorsec](https://discuss.elastic.co/u/jorsec)\
**Post date:** [November 19, 2021, 3:17pm UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/1 "2021-11-19T15:17:36Z")

</div>

Hello all, Currently i am using ELK APM for my java application running on tomcat, with centos 7 as a linux distrubution and its my fresh installation but while apm java agent transfer the logs to apm server -\> elastricsearch , i can see all the apm-\* on discover menu with its logs/mertrics but i cant see any services on the APM UI, as it shows service not available.

Kibana version: 7.13.3  
Elasticsearch version: 7.13.3  
APM Server version: 7.13.3  
APM Agent Java and version: 1.27.0

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/e/1e6bdbb00d7a82248ebbc8fb08b8caf1cb65c466.png)

---

<div class="post-metadata">

**Author:** ![gil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gil/32/41911_2.png) [@gil](https://discuss.elastic.co/u/gil)\
**Post date:** [November 19, 2021, 7:57pm UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/2 "2021-11-19T19:57:46Z")

</div>

A common cause for this issue is a missing index mapping. Can you verify the mapping for the `service.name` field with:

```auto
GET apm-*/_mapping/field/service.name

```

If this returns a text mapping:

```auto
    "mappings" : {
      "service.name" : {
        "full_name" : "service.name",
        "mapping" : {
          "name" : {
            "type" : "text",
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          }
        }
      }
    }

```

then that is your issue and you'll need to recreate them - deleting the existing ones and restarting APM Server with the default configuration will accomplish that.

---

<div class="post-metadata">

**Author:** ![jorsec](https://avatars.discourse-cdn.com/v4/letter/j/9f8e36/32.png) [@jorsec](https://discuss.elastic.co/u/jorsec)\
**Post date:** [November 20, 2021, 4:04am UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/3 "2021-11-20T04:04:46Z")

</div>

Hi @gil, thanks for the quick response , yeah i got this:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/b/5bfdf4b4acbdcb8ab75ebea0b18dcafb1428cd01.png)

when i run this get request to my service name , i got this issue

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55031bdb4d9881783f62869d569faadca5ac8cf5.png)

Could you please tell me how to delete the existing ones and recreate , as i am new to elk-Apm, Looking forward to hear form you.

---

<div class="post-metadata">

**Author:** ![gil](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gil/32/41911_2.png) [@gil](https://discuss.elastic.co/u/gil)\
**Post date:** [November 20, 2021, 4:36am UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/4 "2021-11-20T04:36:19Z")

</div>

Ok great, then you've confirmed the cause. To recover:

1. Stop your APM Server(s) so they are not writing any new documents
2. Delete your existing apm-\* indices either with `DELETE apm-*` in dev console or via the stack management UI, which looks like this: ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/3/f37ce4b99936805b6bd8c3ead453597b349d1718.png)
3. Start APM Server and ensure template setup is enabled - it's on by default, so make sure you don't have `setup.template.enabled: false` in your APM Server config (usually `apm-server.yml`)
4. Verify the correct index templates were installed. That's either `GET _template/apm-*` in dev console or again via stack mangement UI, you're looking for their presence under "legacy index templates" like this:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/8/a851ebd0cf578ab43da88379304b903ac159e071.png)

---

<div class="post-metadata">

**Author:** ![jorsec](https://avatars.discourse-cdn.com/v4/letter/j/9f8e36/32.png) [@jorsec](https://discuss.elastic.co/u/jorsec)\
**Post date:** [November 22, 2021, 5:39am UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/5 "2021-11-22T05:39:42Z")

</div>

i did all those steps which you have included above but still i can't get any service name in apm GUI ,

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/3/e3a18289228b885d0e48b587eaa69e1916fc1e40.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/c/2c6bfbb844fba6bbef2554b1f0b5e61cc7280fd7.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/6/66bc4b168bbfc3621bdd2fdd01f5fef512aa0a69.png)

here is also yml file scrnshot:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/4/24f5afc25e79801e7eace0e99c6f4a0d05c86c1e.png)

but still i am facing this issue

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/4/4491a4a7e6e090dafe19462ddd35bad8782e5cc1.png)

---

<div class="post-metadata">

**Author:** ![Sylvain\_Juge](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylvain_juge/32/55521_2.png) [@Sylvain\_Juge](https://discuss.elastic.co/u/Sylvain_Juge)\
**Post date:** [November 22, 2021, 7:58am UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/6 "2021-11-22T07:58:51Z")

</div>

Hi @jorsec

Can you elaborate a bit on this part please :

> [@jorsec](#):
>
> apm java agent transfer the logs to apm server

To be a bit more specific:

- Just to be sure, are you using Elastic agent or Elastic APM Java agent ?.
- how is the Java agent configured ? Can you provide it's configuration (with credentials removed) ?
- is there any error/warning in the Java agent log output ?
- can you [capture agent debug logs] ?([Troubleshooting | APM Java Agent Reference [1.x] | Elastic](https://www.elastic.co/guide/en/apm/agent/java/current/trouble-shooting.html#trouble-shooting-logging-procedure))
- the Java agent does not send application logs by default, however metrics are sent when the java agent starts, do you have any document created in the `metrics-*` indices ? Once metrics are sent the service becomes visible in Kibana.

Also, it might be worth checking our [troubleshooting documentation](https://www.elastic.co/guide/en/apm/agent/java/current/trouble-shooting.html) if you haven't already.

---

<div class="post-metadata">

**Author:** ![jorsec](https://avatars.discourse-cdn.com/v4/letter/j/9f8e36/32.png) [@jorsec](https://discuss.elastic.co/u/jorsec)\
**Post date:** [November 22, 2021, 8:48am UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/7 "2021-11-22T08:48:32Z")

</div>

Hi @Sylvain_Juge thanks for the respose, currenlty i am using elastic apm java agent with this configuration in tomcat:

```auto
export CATALINA_OPTS="$CATALINA_OPTS -javaagent:/opt/apmagent/elastic-apm-agent-1.27.0.jar"
export CATALINA_OPTS="$CATALINA_OPTS -Delastic.apm.service_name=zan"
export CATALINA_OPTS="$CATALINA_OPTS -Delastic.apm.application_packages=com.example.zan"
export CATALINA_OPTS="$CATALINA_OPTS -Delastic.apm.server_url=http://hostname:8200"

```

when i start the tomcat server, it's get connected to apm server without throwing any errors on catalina.out

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/c/ac082ca22aef46b0cfdc05d04582a7a89e77325b.png)

i have metrics-\* indices created but i dont have any metrics-\* while verifying it throught the discover tab:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4a425b80b98d7be59bf0c50ff024bfb183d7e056.png)

Thanks ,

---

<div class="post-metadata">

**Author:** ![Sylvain\_Juge](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylvain_juge/32/55521_2.png) [@Sylvain\_Juge](https://discuss.elastic.co/u/Sylvain_Juge)\
**Post date:** [November 22, 2021, 11:16am UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/8 "2021-11-22T11:16:01Z")

</div>

Disclamer: I'm not an expert about the index patterns used for APM.

With a recent stack deployment (7.15.2), the APM metrics do not seem to be readable in the `metrics-*` index pattern, can you try with the following ?  
`traces-apm*,logs-apm*,metrics-apm*,apm-*`

Normally this index pattern should have been automatically created for you on deployment.

---

<div class="post-metadata">

**Author:** ![jorsec](https://avatars.discourse-cdn.com/v4/letter/j/9f8e36/32.png) [@jorsec](https://discuss.elastic.co/u/jorsec)\
**Post date:** [November 22, 2021, 12:25pm UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/9 "2021-11-22T12:25:56Z")

</div>

hi @Sylvain_Juge , as this indices are created by default , while i check the apm indices:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4aed2c576810be298b4fb2bfd804032478fc4d57.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/3/6300bcab6a5918658603919dc350ecafd2b99593.png)

and those indices are also pointed to apm-\*, but i cant figure it out why it is not showing any service name in apm GUI

Thanks,

---

<div class="post-metadata">

**Author:** ![jorsec](https://avatars.discourse-cdn.com/v4/letter/j/9f8e36/32.png) [@jorsec](https://discuss.elastic.co/u/jorsec)\
**Post date:** [November 23, 2021, 3:17am UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/10 "2021-11-23T03:17:05Z")

</div>

Hi @Sylvain_Juge & @gil ,

Any updates from your side , what i need to do to solve this issue.

Thanks,

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 23, 2021, 5:17pm UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/11 "2021-11-23T17:17:16Z")

</div>

You said you can see the "logs" in Discover  
What happens when you simply go to Discover  
Index Pattern `apm-*`  
KQL bar

`service.name:*`

Do you see entries?

what about this

`service.name : * and processor.event : "transaction"`

I also noticed that you had very few documents in `apm-transaction-7.13.1-000001` so make sure your time range is set correctly to contain the events BTW services will not show up in the APM UI if they are not within the specified time range.

---

<div class="post-metadata">

**Author:** ![jorsec](https://avatars.discourse-cdn.com/v4/letter/j/9f8e36/32.png) [@jorsec](https://discuss.elastic.co/u/jorsec)\
**Post date:** [November 24, 2021, 4:14am UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/12 "2021-11-24T04:14:40Z")

</div>

Hello @stephenb ,  
when i used this index pattern apm-\* and service.name:\* and processor.event : "transaction" in KQL bar i can see all their respective results,

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/1/f110769788eff0841bd7fbe8df304744f4c51602.png)

but when i go to apm interface i cant get any servicename and their respective results.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37da5f1428f7f801fca38273d0e203e0ae3392bd.png)

Regarding the documents again i have delete those old documents, and again restarted the server but even cant see any service name in apm interface.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 24, 2021, 4:39am UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/13 "2021-11-24T04:39:47Z")

</div>

The fact there are still all those `.keyword` field means to me you are still not setup correctly they should not be there.

Also when you say you see all them what are the `service.name`

---

<div class="post-metadata">

**Author:** ![nityakaiyang](https://avatars.discourse-cdn.com/v4/letter/n/3da27b/32.png) [@nityakaiyang](https://discuss.elastic.co/u/nityakaiyang)\
**Post date:** [December 2, 2021, 6:37am UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/14 "2021-12-02T06:37:36Z")

</div>

I have a problem like you, APM UI on kibana show "No service found" but discover menu have log metric agent. How can I fix this problem ?

Elastic version 7.15.1  
Kibana version 7.15.1  
APM Server version 7.15.1

GET apm-\*/\_mapping/field/service.name

```auto
`{
  "apm-7.15.1-onboarding-2021.12.02" : {
    "mappings" : { }
  },
  "apm-7.15.1-profile-000001" : {
    "mappings" : { }
  },
  "apm-7.15.1-metric-000001" : {
    "mappings" : {
      "service.name" : {
        "full_name" : "service.name",
        "mapping" : {
          "name" : {
            "type" : "text",
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          }
        }
      }
    }
  },
  "apm-7.15.1-span-000001" : {
    "mappings" : {
      "service.name" : {
        "full_name" : "service.name",
        "mapping" : {
          "name" : {
            "type" : "text",
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          }
        }
      }
    }
  },
  "apm-7.15.1-error-000001" : {
    "mappings" : {
      "service.name" : {
        "full_name" : "service.name",
        "mapping" : {
          "name" : {
            "type" : "text",
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          }
        }
      }
    }
  },
  "apm-7.15.1-transaction-000001" : {
    "mappings" : {
      "service.name" : {
        "full_name" : "service.name",
        "mapping" : {
          "name" : {
            "type" : "text",
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          }
        }
      }
    }
  }
}
`

```

---

<div class="post-metadata">

**Author:** ![nityakaiyang](https://avatars.discourse-cdn.com/v4/letter/n/3da27b/32.png) [@nityakaiyang](https://discuss.elastic.co/u/nityakaiyang)\
**Post date:** [December 2, 2021, 1:55pm UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/15 "2021-12-02T13:55:03Z")

</div>

Now I can solved this problem  
index name “apm-7.15.1-onboarding-2021.12.02” and “apm-7.15.1-profile-000001” not have mapping field “service.name”. I check index setting for index name “apm-7.15.1-onboarding-2021.12.02” and “apm-7.15.1-profile-000001” on Kibana Dev Tools menu with

GET apm-7.15.1-onboarding-2021.12.02/\_settings  
GET apm-7.15.1-profile-000001/\_settings

I found index name “apm-7.15.1-onboarding-2021.12.02” and “apm-7.15.1-profile-000001” not use index template name apm-7.15.1 (this template default by Elastic). Usually index setting "index.mapping.total\_fields.limit" default = 1000 but index name “apm-7.15.1-onboarding-2021.12.02” and “apm-7.15.1-profile-000001” have total field over 1000 fields.

so another index template if you not setting  
"index.mapping.total\_fields.limit" your index template use default = 1000. if using index template: apm-7.15.1, it is set "index.mapping.total\_fields.limit": 2000  
After understanding this problem I solved it by this step

1. Stop apm server
2. Delete index apm-\* on Dev Tools menu with

DELETE apm-\*

1. Unset index\_template for index name: apm-\*  
(index name apm-\* must use default index\_template name: apm-7.15.1)
2. Start apm server
3. Check index setting use template: apm-\* on Kibana Dev Tools menu with

GET apm-7.15.1-onboarding-2021.12.02/\_settings

GET apm-7.15.1-profile-000001/\_settings

after checked index name “apm-7.15.1-onboarding-2021.12.02” and “apm-7.15.1-profile-000001” have index mapping “index.mapping.total\_fields.limit”: 2000

1. Check mapping field all index name apm-\* have field service.name

GET apm-\*/\_mapping/field/service.name

```auto
{
  "apm-7.15.1-onboarding-2021.12.02" : {
    "mappings" : {
      "service.name" : {
        "full_name" : "service.name",
        "mapping" : {
          "name" : {
            "type" : "keyword",
            "ignore_above" : 1024
          }
        }
      }
    }
  },
  "apm-7.15.1-profile-000001" : {
    "mappings" : {
      "service.name" : {
        "full_name" : "service.name",
        "mapping" : {
          "name" : {
            "type" : "keyword",
            "ignore_above" : 1024
          }
        }
      }
    }
  },
  "apm-7.15.1-span-000001" : {
    "mappings" : {
      "service.name" : {
        "full_name" : "service.name",
        "mapping" : {
          "name" : {
            "type" : "keyword",
            "ignore_above" : 1024
          }
        }
      }
    }
  },
  "apm-7.15.1-metric-000001" : {
    "mappings" : {
      "service.name" : {
        "full_name" : "service.name",
        "mapping" : {
          "name" : {
            "type" : "keyword",
            "ignore_above" : 1024
          }
        }
      }
    }
  },
  "apm-7.15.1-error-000001" : {
    "mappings" : {
      "service.name" : {
        "full_name" : "service.name",
        "mapping" : {
          "name" : {
            "type" : "keyword",
            "ignore_above" : 1024
          }
        }
      }
    }
  },
  "apm-7.15.1-transaction-000001" : {
    "mappings" : {
      "service.name" : {
        "full_name" : "service.name",
        "mapping" : {
          "name" : {
            "type" : "keyword",
            "ignore_above" : 1024
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 23, 2021, 9:55am UTC](https://discuss.elastic.co/t/apm-agent-logs-shown-on-discover-but-not-on-apm-ui/289706/16 "2021-12-23T09:55:56Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
