# Custom index does NOT show in Kibana

**URL:** <https://discuss.elastic.co/t/custom-index-does-not-show-in-kibana/281490>\
**Category:** Kibana\
**Created:** [August 15, 2021, 8:01pm UTC](https://discuss.elastic.co/t/custom-index-does-not-show-in-kibana/281490 "2021-08-15T20:01:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 15, 2021, 8:01pm UTC](https://discuss.elastic.co/t/custom-index-does-not-show-in-kibana/281490/1 "2021-08-15T20:01:28Z")

</div>

I'm outputting a custom index from Logstash to Elastisearch but it won't show in KIbana's main dashboards (e.g. Security panel / data sources). ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/6/86d2e1b80fbca46ddff52be6e19987bf4f367e21.png)

While it will **show** in index management in settings.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88c5d84e334d3c96717df83f0f7e402ad17fba37.png)

Here is the how output data into the index from logstash:

```auto
output{

    elasticsearch{
        hosts => ["https://localhost:9200"]
        index => "logstash-misp-enriched"
        user => logstash_user
        password => "apass"
        ssl => true
        cacert => "./elasticsearch-ca.pem"
        http_compression => true
	sniffing => false
    }
}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 15, 2021, 8:13pm UTC](https://discuss.elastic.co/t/custom-index-does-not-show-in-kibana/281490/2 "2021-08-15T20:13:11Z")

</div>

Did you create and index pattern?  
Index patterns is what dashboards work with not individual indices

> **[Create an index pattern | Kibana Guide \[7.14\] | Elastic](https://www.elastic.co/guide/en/kibana/current/index-patterns.html)**

---

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 15, 2021, 10:52pm UTC](https://discuss.elastic.co/t/custom-index-does-not-show-in-kibana/281490/3 "2021-08-15T22:52:18Z")

</div>

Thanks for the answer. It cleared a lot of things in my head.  
One more question:

I make my own custom schema in terms of event fields. So do i have to use the ECS, or few of the ECS's fields, or i can make my own visualizations in Kibana with custom fields?

What do you suggest?  
Thanks again

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 15, 2021, 11:08pm UTC](https://discuss.elastic.co/t/custom-index-does-not-show-in-kibana/281490/4 "2021-08-15T23:08:56Z")

</div>

Glad we could help.

That's a bit bigger question. 🙂

There are certainly advantaged of mapping to ECS If you want to take advantage of the security analytics applications within Kibana and some of the default detections and other features etc.

But it's not required if you want to do everything custom.

You can read about that here

> **[Elastic Security fields and object schemas | Elastic Security Solution \[7.14\]...](https://www.elastic.co/guide/en/security/current/security-ref-intro.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 12, 2021, 11:09pm UTC](https://discuss.elastic.co/t/custom-index-does-not-show-in-kibana/281490/5 "2021-09-12T23:09:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
