# Create index pattern

**URL:** https://discuss.elastic.co/t/create-index-pattern/132506
**Category:** Elasticsearch
**Created:** [May 18, 2018, 2:58pm UTC](https://discuss.elastic.co/t/create-index-pattern/132506 "2018-05-18T14:58:13Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![roshannk](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@roshannk](https://discuss.elastic.co/u/roshannk)
#### Post date: [May 18, 2018, 2:58pm UTC](https://discuss.elastic.co/t/create-index-pattern/132506/1 "2018-05-18T14:58:13Z")

</div>

Hello,  
this is my first time using ELK.  
When I try to make an index pattern I get the following;

> **Summary**
>
> Create index pattern  
> Kibana uses index patterns to retrieve data from Elasticsearch indices for things like visualizations.
> 
> Include system indices  
> Couldn't find any Elasticsearch data  
> You'll need to index some data into Elasticsearch before you can create an index pattern. Learn how.

localhost:9200/\_cat/indices?v is empty but localhost:9200 without the /\_cat shows the following;

> **Summary**
>
> rosh@pfsense:~$ curl -X GET [http://localhost:9200](http://localhost:9200)  
> {  
> "name" : "UAPo9\_B",  
> "cluster\_name" : "elasticsearch",  
> "cluster\_uuid" : "2LjtRfscRk-sQEiNdBZ3xg",  
> "version" : {  
> "number" : "6.2.4",  
> "build\_hash" : "ccec39f",  
> "build\_date" : "2018-04-12T20:37:28.497551Z",  
> "build\_snapshot" : false,  
> "lucene\_version" : "7.2.1",  
> "minimum\_wire\_compatibility\_version" : "5.6.0",  
> "minimum\_index\_compatibility\_version" : "5.0.0"  
> },  
> "tagline" : "You Know, for Search"  
> }

I followed these steps;

> **[pf (Firewall logs) + Elasticsearch + Logstash + Kibana](http://pfelk.3ilson.com/)**
>
> pf (Firewall logs) + Elasticsearch + Logstash + Kibana

  
And saw the post @ [https://www.elastic.co/guide/en/kibana/6.x/tutorial-load-dataset.html](https://www.elastic.co/guide/en/kibana/6.x/tutorial-load-dataset.html) and [https://www.elastic.co/guide/en/kibana/6.2/connect-to-elasticsearch.html](https://www.elastic.co/guide/en/kibana/6.2/connect-to-elasticsearch.html) and a few posts that were similar to mine.

I am using the latest version of ubuntu server.

Everything is a fresh install and services are up and running.

Can someone help me with this issue? I would really appreciate your help, like, a lot.

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [May 20, 2018, 9:01am UTC](https://discuss.elastic.co/t/create-index-pattern/132506/2 "2018-05-20T09:01:34Z")

</div>

> [@roshannk](#):
>
> localhost:9200/\_cat/indices?v is empty

Sounds like you haven't pushed any data into Elasticsearch, so you may need to check Logstash.

---

<div class="post-metadata">

### Author: ![roshannk](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@roshannk](https://discuss.elastic.co/u/roshannk)
#### Post date: [May 22, 2018, 8:04am UTC](https://discuss.elastic.co/t/create-index-pattern/132506/3 "2018-05-22T08:04:36Z")

</div>

Thank you for the reply.

I've pushed data into Elasticsearch.

Now I have a different problem, I followed [http://pfelk.3ilson.com/](http://pfelk.3ilson.com/) this tutorial and when I open up my dashboard I see the following;

Could not locate that index-pattern-field (id: geoip.location)

Could not locate that index-pattern-field (id: geoip.country\_code3.raw)

and when I try to install x-pack I get this;

> **Summary**
>
> > Downloading x-pack from elastic  
> > [=================================================] 100%  
> > @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@  
> > @ WARNING: plugin requires additional permissions @  
> > @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
> 
> - java.io.FilePermission \.\pipe\* read,write
> - java.lang.RuntimePermission accessClassInPackage.com.sun.activation.registries
> - java.lang.RuntimePermission getClassLoader
> - java.lang.RuntimePermission setContextClassLoader
> - java.lang.RuntimePermission setFactory
> - java.net.SocketPermission \* connect,accept,resolve
> - java.security.SecurityPermission createPolicy.JavaPolicy
> - java.security.SecurityPermission getPolicy
> - java.security.SecurityPermission putProviderProperty.BC
> - java.security.SecurityPermission setPolicy
> - java.util.PropertyPermission \* read,write  
> See [Permissions in the JDK](http://docs.oracle.com/javase/8/docs/technotes/guides/security/permissions.html)  
> for descriptions of what these permissions allow and the associated risks.

Not sure what to do

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [May 22, 2018, 8:33am UTC](https://discuss.elastic.co/t/create-index-pattern/132506/4 "2018-05-22T08:33:30Z")

</div>

> [@roshannk](#):
>
> and when I try to install x-pack I get this;
> 
> Summary
> 
> Not sure what to do

Did you accept the permissions request?

---

<div class="post-metadata">

### Author: ![roshannk](https://avatars.discourse-cdn.com/v4/letter/r/e8c25b/32.png) [@roshannk](https://discuss.elastic.co/u/roshannk)
#### Post date: [May 22, 2018, 8:49am UTC](https://discuss.elastic.co/t/create-index-pattern/132506/5 "2018-05-22T08:49:01Z")

</div>

Oh yeah that was kinda silly on my end. Its extracting as of right now

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 19, 2018, 8:49am UTC](https://discuss.elastic.co/t/create-index-pattern/132506/6 "2018-06-19T08:49:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
