# Can't find data when doing simple KQL query ( can see the log in general search)

**URL:** <https://discuss.elastic.co/t/cant-find-data-when-doing-simple-kql-query-can-see-the-log-in-general-search/260034>\
**Category:** Kibana\
**Created:** [January 3, 2021, 7:29am UTC](https://discuss.elastic.co/t/cant-find-data-when-doing-simple-kql-query-can-see-the-log-in-general-search/260034 "2021-01-03T07:29:26Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)\
**Post date:** [January 4, 2021, 10:18am UTC](https://discuss.elastic.co/t/cant-find-data-when-doing-simple-kql-query-can-see-the-log-in-general-search/260034/3 "2021-01-04T10:18:35Z")

</div>

Thank you for answering  
After digging deeper into the problem, i found out that the ELK + Filebeat stoped to work from 1/1/2021  
Looking at the logs in one of the filebeat pods i can see this:

```auto
2021-01-04T10:10:52.754Z DEBUG [add_cloud_metadata] add_cloud_metadata/providers.go:129 add_cloud_metadata: fetchMetadata ran for 2.351101ms
2021-01-04T10:10:52.754Z INFO [add_cloud_metadata] add_cloud_metadata/add_cloud_metadata.go:93 add_cloud_metadata: hosting provider type detected as openstack, metadata={"ava
ilability_zone":"us-east-1c","instance":{"id":"i-08f536567bd9945df","name":"ip-10-101-2-178.ec2.internal"},"machine":{"type":"m5.2xlarge"},"provider":"openstack"}
2021-01-04T10:10:52.755Z DEBUG [processors] processors/processor.go:120 Generated new processors: add_cloud_metadata={"availability_zone":"us-east-1c","instance":{"id":"i-08f5
36567bd9945df","name":"ip-10-101-2-178.ec2.internal"},"machine":{"type":"m5.2xlarge"},"provider":"openstack"}, add_docker_metadata=[match_fields=[] match_pids=[process.pid, process.ppid]]    
2021-01-04T10:10:52.755Z INFO instance/beat.go:392 filebeat stopped.
2021-01-04T10:10:52.755Z ERROR instance/beat.go:956 Exiting: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (pat
h.data).
Exiting: data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data).

```

as you can see the filebeat stopped with an error :

```auto
data path already locked by another beat. Please make sure that multiple beats are not sharing the same data path (path.data).

```

After searching the problem in github/forum i found this :

> [@Data path already locked by another beat](https://discuss.elastic.co/t/data-path-already-locked-by-another-beat/219852/4):
>
> Hmmm, you're right that this [important breaking change](https://github.com/elastic/beats/pull/14069) is not in the release notes or breaking changes doc for 7.6.0. I'm terribly sorry about that and am [working](https://github.com/elastic/beats/pull/16424) to get it documented ASAP! As for fixing your setup to account for this change, please edit both your Filebeat configuration files and add a path.data setting. Make sure to set it's values to unique directory locations. Then you should set filebeat.registry.path to start with ${path.data}/. Shaunak

Which looks like my problem,  
Im using the default filebeat-kubernetes.yaml , and there is no information in your docs on how to add unique paths in the filebeat-kubernetes.yaml  
where do i add them and how do i make them unique?  
Thanks  
@flash1293

---

_[View the full topic](https://discuss.elastic.co/t/cant-find-data-when-doing-simple-kql-query-can-see-the-log-in-general-search/260034)._
