# Could not locate that index-pattern (auditbeat,filebat)

**URL:** <https://discuss.elastic.co/t/could-not-locate-that-index-pattern-auditbeat-filebat/121485>\
**Category:** Beats\
**Tags:** auditbeat\
**Created:** [February 26, 2018, 12:36pm UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-auditbeat-filebat/121485 "2018-02-26T12:36:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![illiash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/illiash/32/22821_2.png) [@illiash](https://discuss.elastic.co/u/illiash)\
**Post date:** [February 26, 2018, 12:36pm UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-auditbeat-filebat/121485/1 "2018-02-26T12:36:47Z")

</div>

Hi ,  
It looks like when using custom pattern in auditbeat of filebeat, that ID for dashboards which are created with auditbeat or filebeat are created with extra space in the begging ,

For example in auditbeat I'm using:

```
output.elasticsearch.index: "my-testbeat-%{[beat.version]}-%{+yyyy.MM.dd}"
setup.template.name: "my-testbeat"
setup.template.pattern: "my-testbeat-*"
setup.dashboards.index: "my-testbeat-*"
setup.template.overwrite: true

```

then run:  
auditbeat setup --dashboards

Then in Kibana dashboards I get:

![01](https://us1.discourse-cdn.com/elastic/original/3X/3/e/3e3b00cebd47227c7ebac9e0103f852b0effae06.png)

Could not locate that index-pattern (id: my-testbeat-_), c , however if I create new index pattern with name smth like my-test_ and define the index pattern ID with space in the begining like in an error:  
==\> "id: my-testbeat-\*" , it start working.

with default name for index "auditbeat" it's working ok.

is a bug os smth ? I'm using the latest 6.2.2 auditbeat.

BR,  
Illia

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [February 27, 2018, 3:56am UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-auditbeat-filebat/121485/2 "2018-02-27T03:56:13Z")

</div>

When loading the dashboards, the index pattern names must be replaced. I wonder if there is a problem with this name replacement. In kibana managent tab you can see object internals + json encoding of dashboards. I wonder if the patterns are correct.

Dashboard/Index-pattern loading wrosk differently per Kibana/Elasticsearch versions. Which versions are you using?

---

<div class="post-metadata">

**Author:** ![illiash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/illiash/32/22821_2.png) [@illiash](https://discuss.elastic.co/u/illiash)\
**Post date:** [February 27, 2018, 10:40am UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-auditbeat-filebat/121485/3 "2018-02-27T10:40:04Z")

</div>

I'm using latest auditbeat 6.2.2 , and elastic+kibana 5.6.5.

In Kibana --\> Managment --\> saved objects --\> in json for dashboard only id's no names:  
[  
{  
"col": 1,  
"id": "97680df0-c1c0-11e7-8995-936807a28b16",  
"panelIndex": 1,  
"row": 1,  
"size\_x": 6,  
"size\_y": 4,  
"type": "visualization"  
},  
{  
"col": 7,  
"id": "08679220-c25a-11e7-8692-232bd1143e8a",  
"panelIndex": 2,  
"row": 1,  
"size\_x": 6,  
"size\_y": 4,  
"type": "visualization"  
},  
{  
"col": 1,  
"columns": [  
"beat.hostname",  
"auditd.summary.actor.primary",  
"auditd.summary.actor.secondary",  
"event.action",  
"auditd.summary.object.type",  
"auditd.summary.object.primary",  
"auditd.summary.object.secondary",  
"auditd.summary.how",  
"auditd.result"  
],  
"id": "0f10c430-c1c3-11e7-8995-936807a28b16",  
"panelIndex": 3,  
"row": 5,  
"size\_x": 12,  
"size\_y": 6,  
"sort": [  
"@timestamp",  
"desc"  
],  
"type": "search"  
}  
]

* * *

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 5:15am UTC](https://discuss.elastic.co/t/could-not-locate-that-index-pattern-auditbeat-filebat/121485/4 "2022-11-04T05:15:10Z")

</div>


