# Couldn't find any Elasticsearch data

**URL:** <https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020>\
**Category:** Kibana\
**Created:** [February 22, 2018, 9:40am UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020 "2018-02-22T09:40:28Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rajkumar\_idsil](https://avatars.discourse-cdn.com/v4/letter/r/919ad9/32.png) [@Rajkumar\_idsil](https://discuss.elastic.co/u/Rajkumar_idsil)\
**Post date:** [February 22, 2018, 9:40am UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/1 "2018-02-22T09:40:28Z")

</div>

when i start kibana and looking in management tab it is displaying message :  
"Couldn't find any Elasticsearch data  
You'll need to index some data into Elasticsearch before you can create an index pattern "

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/2/828daa932f664a0679430e290605b4f2dfb243a3.png)

kindly support me to resolve this issue ,i am using elasticsearch,logstash and kibana

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 22, 2018, 3:45pm UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/2 "2018-02-22T15:45:10Z")

</div>

Can you check that you can see the data in your Elasticsearch cluster with something like this in your browser;

`http://localhost:9200/_cat/indices?v`

You should see something like this;

```auto
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
green open logstash-0 4fOMSVMoQ3S0ZNpb73WjDA 1 0 14005 0 56mb 56mb
green open .kibana Zd2muayFR7SlPBGq1f6ShQ 1 0 3 1 26.2kb 26.2kb
yellow open shakespeare LmuYM18vTN6SOJU8mw20Pg 5 1 111396 0 21.2mb 21.2mb

```

The important thing is that you see your logstash index and that it has some docs.count.

If you see that OK, the next step would be to see if your Kibana is connecting to your Elasticsearch cluster OK by checking the logs. Where the logs are located depends on your operating system and how you installed Kibana.

---

<div class="post-metadata">

**Author:** ![Rajkumar\_idsil](https://avatars.discourse-cdn.com/v4/letter/r/919ad9/32.png) [@Rajkumar\_idsil](https://discuss.elastic.co/u/Rajkumar_idsil)\
**Post date:** [February 23, 2018, 5:46am UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/3 "2018-02-23T05:46:11Z")

</div>

Thanks,  
i need one more help .  
i have .txt file which contain any type of data and my requirement is to display .txt data into kabina kindly suggest generic way to read any type of data in kibana

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 23, 2018, 2:17pm UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/4 "2018-02-23T14:17:27Z")

</div>

Logstash and Filebeat can both read in text files. If you have specific questions on how to configure them you should ask on the Logstash and/or Beats channels.

---

<div class="post-metadata">

**Author:** ![lesly](https://avatars.discourse-cdn.com/v4/letter/l/e19adc/32.png) [@lesly](https://discuss.elastic.co/u/lesly)\
**Post date:** [February 26, 2018, 9:47am UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/5 "2018-02-26T09:47:06Z")

</div>

Helo,  
If witht his command [http://localhost:9200/\_cat/indices?v](http://localhost:9200/_cat/indices?v) I don't have any output what can I do?

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 26, 2018, 5:14pm UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/6 "2018-02-26T17:14:16Z")

</div>

What operating system are you installing Elasticsearch and Kibana on?

How did you install Elasticsearch and how did you start it?

If you Elasticsearch is running on the same host, you should be able to open a browser and go to [http://localhost:9200](http://localhost:9200). The response is in JSON format which some browsers may display, or some (like Internet Explorer) might just save as a download.

That response should look something like this;

```auto
{
  "name": "jhDXnrd",
  "cluster_name": "elasticsearch",
  "cluster_uuid": "E1ckHApoQm2BeBU8m2BcBA",
  "version": {
  "number": "6.2.2",
  "build_hash": "10b1edd",
  "build_date": "2018-02-16T19:01:30.685723Z",
  "build_snapshot": false,
  "lucene_version": "7.2.1",
  "minimum_wire_compatibility_version": "5.6.0",
  "minimum_index_compatibility_version": "5.0.0"
},
  "tagline": "You Know, for Search"
}

```

If you don't see that, you should check if your Elasticsearch is actually running.  
If it is running, you should check the Elasticsearch log files to see if there's any errors.

Please let me know and I'll try to help some more.

---

<div class="post-metadata">

**Author:** ![lesly](https://avatars.discourse-cdn.com/v4/letter/l/e19adc/32.png) [@lesly](https://discuss.elastic.co/u/lesly)\
**Post date:** [February 27, 2018, 8:26am UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/7 "2018-02-27T08:26:19Z")

</div>

Hello,  
I am using Debian 9 and I install elasticsearch with the debian package. My elasticsearch is running and I have the response in the browser.

curl -X GET [http://localhost:9200](http://localhost:9200)  
{  
"name" : "NoVgygD",  
"cluster\_name" : "elasticsearch",  
"cluster\_uuid" : "94BD3suKTgW4g9tTcDmcRw",  
"version" : {  
"number" : "6.2.2",  
"build\_hash" : "10b1edd",  
"build\_date" : "2018-02-16T19:01:30.685723Z",  
"build\_snapshot" : false,  
"lucene\_version" : "7.2.1",  
"minimum\_wire\_compatibility\_version" : "5.6.0",  
"minimum\_index\_compatibility\_version" : "5.0.0"  
},  
"tagline" : "You Know, for Search"  
}

But with de kibana I have the error "kibana could not connect to elasticsearch data".  
Thank you!!!!

---

<div class="post-metadata">

**Author:** ![gopi.yeguru](https://avatars.discourse-cdn.com/v4/letter/g/8baadc/32.png) [@gopi.yeguru](https://discuss.elastic.co/u/gopi.yeguru)\
**Post date:** [February 27, 2018, 10:08am UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/8 "2018-02-27T10:08:17Z")

</div>

HI  
I am getting same error above you mentioned. please help me. I have data in elastic search but in kibana,  
i am unable to add index pattern in kibana

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/9/592523780109f1bb1da828c1a52bdb2b43b0f4a4.png)

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [February 27, 2018, 6:05pm UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/9 "2018-02-27T18:05:17Z")

</div>

OK, so if your Elasticsearch is up, the next step is the `/_cat/indices?v` . If you ran logstash and it successfully loaded data into Elasticsearch you should see the index in that output. If you still don't see that you might want to post a question on the logstash channel.

Another option is to just post some data into Elasticsearch using the Kibana Dev Tools Console.

```auto
POST test/doc
{
  "myField": "myData"
}

```

If you post that small doc above, you should see the `test` index in the output of `_cat/indices`  
And you should be able to create the index pattern for `test`.

---

<div class="post-metadata">

**Author:** ![RayS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rays/32/28268_2.png) [@RayS](https://discuss.elastic.co/u/RayS)\
**Post date:** [February 28, 2018, 7:38pm UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/10 "2018-02-28T19:38:58Z")

</div>

Same issue here. I had ElasticSearch and Kibana running with WinlogBeat and Heartbeat sending data to Elasticsearch for about 2 days. I had the index Pattern setup and the Heartbeat dashboard working.

I then install x-pack and they no longer show data.

I decided to delete both the winLogbeat-\* and the heartbeat-\* indexes from Kibana hoping to recreate them and now Kibana (under Management, Index Patterns) says "Couldn't find any Elasticsearch data".

Here is a print out of my \_cat/indices?v

health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
green open .watches bE3Lgf64RAWbIjDB9Fvzdw 1 0 6 0 109.5kb 109.5kb  
yellow open winlogbeat-6.2.2-2018.02.27 HzeZJ60BRGaPtY73iIQh\_A 3 1 261 0 386kb 386kb  
green open .monitoring-kibana-6-2018.02.28 otP9zcAtTBaUlbMgaAh90Q 1 0 1314 0 479.9kb 479.9kb  
green open .kibana 0X29PuB2T9Wewbv6LYBIbw 1 0 8 0 22.5kb 22.5kb  
close .watcher-history-7-2018.02.27 HjtfVtelTSCeHHGOTeIGtg  
yellow open heartbeat-6.2.2-2018.02.28 P\_n9wIFRSK-S\_XSuJhH0Fw 1 1 12953 0 4.1mb 4.1mb  
green open .watcher-history-7-2018.02.28 EbW5DGEoTqS4qR-daSZc6w 1 0 2372 0 3.5mb 3.5mb  
yellow open heartbeat-6.2.2-2018.02.27 OX2fK8UpQkK7V56B7wETjQ 1 1 457 0 127.4kb 127.4kb  
green open .monitoring-es-6-2018.02.27 UZTXaTYoRh6Ghrk\_XyHzOw 1 0 1064 12 683.4kb 683.4kb  
green open .monitoring-es-6-2018.02.28 \_jYbGX7YRqGGcw6zmX6C5w 1 0 30189 200 17.9mb 17.9mb  
green open .monitoring-alerts-6 NYagRVGsTkW1DC11OdA90Q 1 0 4 1 30.5kb 30.5kb  
green open .security-6 2esDuIDERNSUg7cgYIcFCw 1 0 3 0 9.9kb 9.9kb  
green open .triggered\_watches IrsUvtdqS\_GsxSOjrU2t8Q 1 0 0 0 144.9kb 144.9kb  
yellow open winlogbeat-6.2.2-2018.02.28 nGSBJiE4T2amkAYGIbwo9w 3 1 177 0 449.6kb 449.6kb

Open to any suggestions

In the past when this has happened I did an uninstall of the x-pack and it worked again.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [March 7, 2018, 11:37pm UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/11 "2018-03-07T23:37:47Z")

</div>

When you install x-pack, it becomes very important what user you log in to Kibana with and what roles that user has.

In @gopi.yeguru screenshot I see the `kibana` user. That built-in user only has the `kibana_system` role which is for the kibana server to connect to Elasticsearch. It's NOT the user that users should log in as. That user doesn't have access to things like your winlogbeat data.

You could log in as the `elastic` `superuser` and then you should have full access to all your data.

You should then also go to `Management > Roles` and create a role that has only the privileges needed. For example, if you have winlogbeat data I would create a `winlogbeat_reader` role which has `read` and `view_index_metadata` on that index.  
Then create a user and give them at least the `kibana_user` role and the `winlogbeat_reader` role.

---

<div class="post-metadata">

**Author:** ![RayS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rays/32/28268_2.png) [@RayS](https://discuss.elastic.co/u/RayS)\
**Post date:** [March 8, 2018, 2:03am UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/12 "2018-03-08T02:03:02Z")

</div>

Where could I find the password for "elastic superuser" or does it have one by default. Also, where is that addresses in the documentation? I started down the path a little bit today but got lost in the weeds when reading it.

---

<div class="post-metadata">

**Author:** ![RayS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rays/32/28268_2.png) [@RayS](https://discuss.elastic.co/u/RayS)\
**Post date:** [March 8, 2018, 2:06am UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/13 "2018-03-08T02:06:52Z")

</div>

Scratch the password for elastic superuser. I understand which one that is when I set the passwords.

This solved my issue.

Thank you very very much.

---

<div class="post-metadata">

**Author:** ![aaltonen](https://avatars.discourse-cdn.com/v4/letter/a/e19b73/32.png) [@aaltonen](https://discuss.elastic.co/u/aaltonen)\
**Post date:** [March 29, 2018, 7:25am UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/14 "2018-03-29T07:25:53Z")

</div>

Hi，I also encountered this issue. And I can just see one line "health status index uuid pri rep docs.count docs.deleted store.size pri.store.size" in my browser. When I deployed elk, I just installed the three components by RPMs and not start any service by hand. So I think logstash is not connected with elasticsearch correctly now. Do you have any ideas?

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [April 10, 2018, 1:32pm UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/15 "2018-04-10T13:32:27Z")

</div>

Hi aaltonen,

Sorry nobody saw your post for this long. I'm guessing you've probably solved your problem by now, but if not, or for anyone else who finds this...

If you install "ELK stack" Elasticsearch, Logstash, Kibana by installing the rpm packages you have to start each service. But I don't think Logstash comes with any default configuration that will load any data. I think you always have to tell it what data to get and then start it up.

Besides the ELK stack we also have "Beats". And some of them like Metricbeat have a default configuration which will load data into Elasticsearch. So for someone just trying to get a stack working, I think Metricbeat is a bit easier than Logstash.

Lee

---

<div class="post-metadata">

**Author:** ![Blisk](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@Blisk](https://discuss.elastic.co/u/Blisk)\
**Post date:** [April 16, 2018, 5:52pm UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/16 "2018-04-16T17:52:50Z")

</div>

I also have the same problem and all runs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2018, 5:52pm UTC](https://discuss.elastic.co/t/couldnt-find-any-elasticsearch-data/121020/17 "2018-05-14T17:52:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
