# Can't find data when doing simple KQL query ( can see the log in general search)

**URL:** <https://discuss.elastic.co/t/cant-find-data-when-doing-simple-kql-query-can-see-the-log-in-general-search/260034>\
**Category:** Kibana\
**Created:** [January 3, 2021, 7:29am UTC](https://discuss.elastic.co/t/cant-find-data-when-doing-simple-kql-query-can-see-the-log-in-general-search/260034 "2021-01-03T07:29:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)\
**Post date:** [January 3, 2021, 7:29am UTC](https://discuss.elastic.co/t/cant-find-data-when-doing-simple-kql-query-can-see-the-log-in-general-search/260034/1 "2021-01-03T07:29:26Z")

</div>

im using the filebeat-\* index .  
when i watch the logs in discover i can see logs from the pods  
when i try to create simple query to get logs by namespace/name/container name  
i don't get any result  
i follow this thread post :

> [@Is wildcard queries not supporting in kibana discovery search ? want to search the all pods/container names in particular namespace](https://discuss.elastic.co/t/is-wildcard-queries-not-supporting-in-kibana-discovery-search-want-to-search-the-all-pods-container-names-in-particular-namespace/226847):
>
> Want to search the all pods/container names in particular namespace in kibana discovery search expection :- should display all available resources as per query/wildcard Search qurie :- kubernetes.namespace\_name.keyword : "dev" and kubernetes.pod\_name.keyword :dev-web\* by providing any \* at the end should display all possible name like dev-web-0 dev-web-1 dev-web-2 dev-web-3 but not displaying anything .. tried some possible search like kubernetes.namespace\_name.keyword : "dev" and …

i tried :

```auto
kubernetes.namespace_name.keyword : my_name_space and kubernetes.pod_name.keyword : prod* 

```

(which i can see that they exist )

but when i do simple query like :

```auto
agent.name: ip-11-Xxx-0-xxx.ec2.internal

```

it does return results

what do i missing here ?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [January 4, 2021, 7:50am UTC](https://discuss.elastic.co/t/cant-find-data-when-doing-simple-kql-query-can-see-the-log-in-general-search/260034/2 "2021-01-04T07:50:02Z")

</div>

What version of Kibana are you running? Can you share the mapping of your index?

In general, make sure your search bar is set to KQL, not Lucene (you can see this to the right of input)

---

<div class="post-metadata">

**Author:** ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)\
**Post date:** [January 4, 2021, 10:18am UTC](https://discuss.elastic.co/t/cant-find-data-when-doing-simple-kql-query-can-see-the-log-in-general-search/260034/3 "2021-01-04T10:18:35Z")

</div>

Thank you for answering  
After digging deeper into the problem, i found out that the ELK + Filebeat stoped to work from 1/1/2021  
Looking at the logs in one of the filebeat pods i can see this:

```auto
2021-01-04T10:10:52.754Z DEBUG [add_cloud_metadata] add_cloud_metadata/providers.go:129 add_cloud_metadata: fetchMetadata ran for 2.351101ms
2021-01-04T10:10:52.754Z INFO [add_cloud_metadata] add_cloud_metadata/add_cloud_metadata.go:93 add_cloud_metadata: hosting provider type detected as openstack, metadata={"ava
ilability_zone":"us-east-1c","instance":{"id":"i-08f536567bd9945df","name":"ip-10-101-2-178.ec2.internal"},"machine":{"type":"m5.2xlarge"},"provider":"openstack"}
2021-01-04T10:10:52.755Z DEBUG [processors] processors/processor.go:120 Generated new processors: add_cloud_metadata={"availability_zone":"us-east-1c","instance":{"id":"i-08f5
36567bd9945df","name":"ip-10-101-2-178.ec2.internal"},"machine":{"type":"m5.2xlarge"},"provider":"openstack"}, add_docker_metadata=[match_fields=[] match_pids=[process.pid, process.ppid]]    
2021-01-04T10:10:52.755Z INFO instance/beat.go:392 filebeat stopped.
2021-01-04T10:10:52.755Z ERROR instance/beat.go:956 Exiting: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (pat
h.data).
Exiting: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data).

```

as you can see the filebeat stopped with an error :

```auto
data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data).

```

After searching the problem in github/forum i found this :

> [@Data path already locked by another beat](https://discuss.elastic.co/t/data-path-already-locked-by-another-beat/219852/4):
>
> Hmmm, you're right that this [important breaking change](https://github.com/elastic/beats/pull/14069) is not in the release notes or breaking changes doc for 7.6.0. I'm terribly sorry about that and am [working](https://github.com/elastic/beats/pull/16424) to get it documented ASAP! As for fixing your setup to account for this change, please edit both your Filebeat configuration files and add a path.data setting. Make sure to set it's values to unique directory locations. Then you should set filebeat.registry.path to start with ${path.data}/. Shaunak

Which looks like my problem,  
Im using the default filebeat-kubernetes.yaml , and there is no information in your docs on how to add unique paths in the filebeat-kubernetes.yaml  
where do i add them and how do i make them unique?  
Thanks  
@flash1293

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [January 4, 2021, 1:01pm UTC](https://discuss.elastic.co/t/cant-find-data-when-doing-simple-kql-query-can-see-the-log-in-general-search/260034/4 "2021-01-04T13:01:56Z")

</div>

As this is a beats question, could you post it in the beats category? [https://discuss.elastic.co/c/elastic-stack/beats/28](https://discuss.elastic.co/c/elastic-stack/beats/28)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2021, 1:02pm UTC](https://discuss.elastic.co/t/cant-find-data-when-doing-simple-kql-query-can-see-the-log-in-general-search/260034/5 "2021-02-01T13:02:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
