# App Search - API logs and Analytics are empty

**URL:** <https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141>\
**Category:** Elastic Search\
**Tags:** elastic-app-search\
**Created:** [November 20, 2020, 3:26pm UTC](https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141 "2020-11-20T15:26:40Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![aq1652](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@aq1652](https://discuss.elastic.co/u/aq1652)\
**Post date:** [November 20, 2020, 3:26pm UTC](https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141/1 "2020-11-20T15:26:40Z")

</div>

Hi, I've been struggling with this for a few days and no luck. As the title suggests, my self-hsoted app search is not displaying any API logs and the analytics are empty!

The data is definitely being stored somewhere, as Kibana is able to display stuff from filebeat when I make a search via the api but it doesn't show in my App Search UI. I am using the PHP client to make API calls. Also, the analytics are empty.

I'm on enterprise-search v7.7. As far as I can tell everything is configured properly...but clearly something is not right.

Thanks.

---

<div class="post-metadata">

**Author:** ![aq1652](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@aq1652](https://discuss.elastic.co/u/aq1652)\
**Post date:** [November 22, 2020, 4:14pm UTC](https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141/2 "2020-11-22T16:14:39Z")

</div>

Bump

---

<div class="post-metadata">

**Author:** ![qhoxie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/qhoxie/32/47252_2.png) [@qhoxie](https://discuss.elastic.co/u/qhoxie)\
**Post date:** [November 25, 2020, 3:27pm UTC](https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141/3 "2020-11-25T15:27:36Z")

</div>

Hello,

Did you upgrade from App Search to Enterprise Search?

---

<div class="post-metadata">

**Author:** ![aq1652](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@aq1652](https://discuss.elastic.co/u/aq1652)\
**Post date:** [November 25, 2020, 3:38pm UTC](https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141/4 "2020-11-25T15:38:33Z")

</div>

Yes, I'm on enterprise search

---

<div class="post-metadata">

**Author:** ![qhoxie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/qhoxie/32/47252_2.png) [@qhoxie](https://discuss.elastic.co/u/qhoxie)\
**Post date:** [November 25, 2020, 4:34pm UTC](https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141/5 "2020-11-25T16:34:22Z")

</div>

Sorry, I was unclear. Were you originally on App Search (pre-7.7) and subsequently upgraded to Enterprise Search (7.7 onward)? See [https://www.elastic.co/guide/en/cloud-enterprise/current/ece-upgrade-appsearch.html](https://www.elastic.co/guide/en/cloud-enterprise/current/ece-upgrade-appsearch.html)

---

<div class="post-metadata">

**Author:** ![aq1652](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@aq1652](https://discuss.elastic.co/u/aq1652)\
**Post date:** [November 27, 2020, 1:29pm UTC](https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141/6 "2020-11-27T13:29:39Z")

</div>

Hello, no it was a fresh install of enterprise search v7.7  
I had not previously used search

---

<div class="post-metadata">

**Author:** ![oleksiy-elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/oleksiy-elastic/32/49074_2.png) [@oleksiy-elastic](https://discuss.elastic.co/u/oleksiy-elastic)\
**Post date:** [November 30, 2020, 4:23pm UTC](https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141/7 "2020-11-30T16:23:44Z")

</div>

Sorry you're having problems with analytics and api logs!

Here are a few things you could check to allow us to triage the issue better:

1. When you send your API requests, do you see new lines being added to the `log/filebeat.log`? Those should be long JSON-encoded structured log messages describing your API requests.

2. If you see it in the logs, can you check if there is a filebeat instance running next to the enterprise-search java process? (`ps axuww | grep filebeat` should do)

3. If filebeat is running, can you check (via Kibana) if you have indexes called something like `.ent-search-api-ecs-ilm-logs-2020.11.24-000002` in your Elasticsearch cluster.

4. If logs indexes exist, can you check if the most recent records there match what you see in `filebeat.log` (the log file is split into different streams and they are indexed into different indexes, so you will need to check analytics indexes for analytics events and api-logs for api events).

If all of the above works and you still don't see the data in the App Search UI, then it may be a bug. In that case I'd recommend upgrading to the latest 7.x release (7.10.0 as of the time of this writing) and reporting back if the issue still occurs after the upgrade.

Thank you and I hope this helps!

---

<div class="post-metadata">

**Author:** ![aq1652](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@aq1652](https://discuss.elastic.co/u/aq1652)\
**Post date:** [December 2, 2020, 8:05pm UTC](https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141/8 "2020-12-02T20:05:32Z")

</div>

Thanks for getting back to me

> [@oleksiy-elastic](#):
>
> If filebeat is running, can you check (via Kibana) if you have indexes called something like `.ent-search-api-ecs-ilm-logs-2020.11.24-000002` in your Elasticsearch cluster.

That's what I don't have. There's no index with that sort of name on Kibana

Filebeat is definitely showing API logs (via syslog). For example, my search queries are present in the syslog file.

---

<div class="post-metadata">

**Author:** ![aq1652](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@aq1652](https://discuss.elastic.co/u/aq1652)\
**Post date:** [December 5, 2020, 2:07pm UTC](https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141/9 "2020-12-05T14:07:58Z")

</div>

Hi, any ideas please?

---

<div class="post-metadata">

**Author:** ![aq1652](https://avatars.discourse-cdn.com/v4/letter/a/ecd19e/32.png) [@aq1652](https://discuss.elastic.co/u/aq1652)\
**Post date:** [December 12, 2020, 10:11pm UTC](https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141/10 "2020-12-12T22:11:46Z")

</div>

Bump

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2021, 10:11pm UTC](https://discuss.elastic.co/t/app-search-api-logs-and-analytics-are-empty/256141/11 "2021-01-09T22:11:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
