# Dashboard: Could not locate that index-pattern-field (id: system.syslog.hostname) and other errors

**URL:** <https://discuss.elastic.co/t/dashboard-could-not-locate-that-index-pattern-field-id-system-syslog-hostname-and-other-errors/153119>\
**Category:** Kibana\
**Created:** [October 19, 2018, 6:45am UTC](https://discuss.elastic.co/t/dashboard-could-not-locate-that-index-pattern-field-id-system-syslog-hostname-and-other-errors/153119 "2018-10-19T06:45:36Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![09958a6c84c61fe52414](https://avatars.discourse-cdn.com/v4/letter/0/cdc98d/32.png) [@09958a6c84c61fe52414](https://discuss.elastic.co/u/09958a6c84c61fe52414)\
**Post date:** [October 19, 2018, 6:45am UTC](https://discuss.elastic.co/t/dashboard-could-not-locate-that-index-pattern-field-id-system-syslog-hostname-and-other-errors/153119/1 "2018-10-19T06:45:36Z")

</div>

Hi all.  
In my Dasbords I have lot of messages like

`Could not locate that index-pattern-field (id: system.syslog.hostname)`

I'am using  
Kibana 6.4.2  
Logstash 6.4.2  
Elasticsearch 6.4.2.

While setting up Filebeat 6.4.2 I made it to use Logstash, so I uploaded indexes manualy like this:  
`filebeat setup --template -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=["localhost:9200"]'`

and uploaded Dashboards like this:

```
filebeat setup -e \
  -E output.logstash.enabled=false \
  -E output.elasticsearch.hosts=['127.0.0.1:9200'] \
  -E setup.kibana.host=elk.mydomain.ru:5601

```

So new data is seen in Discovery but there are errors in Dashboards like I've mentioned in subj.

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [October 19, 2018, 3:52pm UTC](https://discuss.elastic.co/t/dashboard-could-not-locate-that-index-pattern-field-id-system-syslog-hostname-and-other-errors/153119/2 "2018-10-19T15:52:32Z")

</div>

Did you do an import at some point? It sounds like some of the visualizations on your dashboard are pointing to an index pattern that doesn't exist. For each of those visualizations you can go into the saved object editor and change the index pattern ID to the correct one.

---

<div class="post-metadata">

**Author:** ![09958a6c84c61fe52414](https://avatars.discourse-cdn.com/v4/letter/0/cdc98d/32.png) [@09958a6c84c61fe52414](https://discuss.elastic.co/u/09958a6c84c61fe52414)\
**Post date:** [October 22, 2018, 7:15am UTC](https://discuss.elastic.co/t/dashboard-could-not-locate-that-index-pattern-field-id-system-syslog-hostname-and-other-errors/153119/3 "2018-10-22T07:15:39Z")

</div>

For "clean experiment" I've stoped Filebeat, completely deleted all Visualizations, Dashboards, cleared indexes with  
`curl -XDELETE 'http://localhost:9200/filebeat-*'`

After It I've added indexes:  
# curl -XDELETE '[http://localhost:9200/filebeat-\*](http://localhost:9200/filebeat-*)'  
{"acknowledged":true}  
# curl -XPUT -H 'Content-Type: application/json' [http://localhost:9200/\_template/filebeat-6.4.2](http://localhost:9200/_template/filebeat-6.4.2) -d@filebeat.template.json  
{"acknowledged":true}

uploaded Dashboards:  
# filebeat setup -e   
\> -E output.logstash.enabled=false   
\> -E output.elasticsearch.hosts=['127.0.0.1:9200']   
\> -E [setup.kibana.host:5601=elk.zonatelecom.ru](http://setup.kibana.host:5601=elk.zonatelecom.ru)  
2018-10-22T10:06:15.979+0300 INFO instance/beat.go:544 Home path: [/usr/share/filebeat] Config path: [/etc/filebeat] Data path: [/var/lib/filebeat] Logs path: [/var/log/filebeat]  
2018-10-22T10:06:15.979+0300 INFO instance/beat.go:551 Beat UUID: bded7bde-a6e8-43e5-aadb-1807a1d5ed35  
2018-10-22T10:06:15.979+0300 INFO [beat] instance/beat.go:768 Beat info {"system\_info": {"beat": {"path": {"config": "/etc/filebeat", "data": "/var/lib/filebeat", "home": "/usr/share/filebeat", "logs": "/var/log/filebeat"}, "type": "filebeat", "uuid": "bded7bde-a6e8-43e5-aadb-1807a1d5ed35"}}}  
2018-10-22T10:06:15.980+0300 INFO [beat] instance/beat.go:777 Build info {"system\_info": {"build": {"commit": "e193f6d68b25b7ddbe3a3ed8d60bc07fea1ef800", "libbeat": "6.4.2", "time": "2018-09-26T12:42:46.000Z", "version": "6.4.2"}}}  
2018-10-22T10:06:15.980+0300 INFO [beat] instance/beat.go:780 Go runtime info {"system\_info": {"go": {"os":"linux","arch":"amd64","max\_procs":64,"version":"go1.10.3"}}}  
2018-10-22T10:06:15.984+0300 INFO [beat] instance/beat.go:784 Host info {"system\_info": {"host": {"architecture":"x86\_64","boot\_time":"2018-10-18T15:43:48+03:00","containerized":false,"hostname":"[elk.zonatelecom.ru](http://elk.zonatelecom.ru)","ips":["127.0.0.1/8","::1/128","172.20.71.119/24","fe80::92b1:1cff:fefd:8942/64"],"kernel\_version":"4.9.0-7-amd64","mac\_addresses":["90:b1:1c:fd:89:42","90:b1:1c:fd:89:44","90:b1:1c:fd:89:46","90:b1:1c:fd:89:48"],"os":{"family":"debian","platform":"debian","name":"Debian GNU/Linux","version":"9 (stretch)","major":9,"minor":0,"patch":0,"codename":"stretch"},"timezone":"MSK","timezone\_offset\_sec":10800,"id":"1484af230da94415825fe965660c4e4d"}}}  
2018-10-22T10:06:15.985+0300 INFO [beat] instance/beat.go:813 Process info {"system\_info": {"process": {"capabilities": {"inheritable":null,"permitted":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend","audit\_read"],"effective":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend","audit\_read"],"bounding":["chown","dac\_override","dac\_read\_search","fowner","fsetid","kill","setgid","setuid","setpcap","linux\_immutable","net\_bind\_service","net\_broadcast","net\_admin","net\_raw","ipc\_lock","ipc\_owner","sys\_module","sys\_rawio","sys\_chroot","sys\_ptrace","sys\_pacct","sys\_admin","sys\_boot","sys\_nice","sys\_resource","sys\_time","sys\_tty\_config","mknod","lease","audit\_write","audit\_control","setfcap","mac\_override","mac\_admin","syslog","wake\_alarm","block\_suspend","audit\_read"],"ambient":null}, "cwd": "/root", "exe": "/usr/share/filebeat/bin/filebeat", "name": "filebeat", "pid": 46516, "ppid": 14709, "seccomp": {"mode":"disabled"}, "start\_time": "2018-10-22T10:06:15.740+0300"}}}  
2018-10-22T10:06:15.985+0300 INFO instance/beat.go:273 Setup Beat: filebeat; Version: 6.4.2  
2018-10-22T10:06:15.986+0300 INFO elasticsearch/client.go:163 Elasticsearch url: [http://127.0.0.1:9200](http://127.0.0.1:9200)  
2018-10-22T10:06:15.986+0300 INFO pipeline/module.go:98 Beat name: [elk.zonatelecom.ru](http://elk.zonatelecom.ru)  
2018-10-22T10:06:15.986+0300 INFO elasticsearch/client.go:163 Elasticsearch url: [http://127.0.0.1:9200](http://127.0.0.1:9200)  
2018-10-22T10:06:15.989+0300 INFO elasticsearch/client.go:712 Connected to Elasticsearch version 6.4.2  
2018-10-22T10:06:15.993+0300 INFO template/load.go:129 Template already exists and will not be overwritten.  
Loaded index template  
Loading dashboards (Kibana must be running and reachable)  
2018-10-22T10:06:15.996+0300 INFO elasticsearch/client.go:163 Elasticsearch url: [http://127.0.0.1:9200](http://127.0.0.1:9200)  
2018-10-22T10:06:15.998+0300 INFO elasticsearch/client.go:712 Connected to Elasticsearch version 6.4.2  
2018-10-22T10:06:15.998+0300 INFO kibana/client.go:113 Kibana url: [http://elk.zonatelecom.ru:5601](http://elk.zonatelecom.ru:5601)  
2018-10-22T10:06:44.142+0300 INFO instance/beat.go:659 Kibana dashboards successfully loaded.  
Loaded dashboards  
2018-10-22T10:06:44.143+0300 INFO elasticsearch/client.go:163 Elasticsearch url: [http://127.0.0.1:9200](http://127.0.0.1:9200)  
2018-10-22T10:06:44.145+0300 INFO elasticsearch/client.go:712 Connected to Elasticsearch version 6.4.2  
2018-10-22T10:06:44.145+0300 INFO kibana/client.go:113 Kibana url: [http://elk.zonatelecom.ru:5601](http://elk.zonatelecom.ru:5601)  
2018-10-22T10:06:44.206+0300 WARN fileset/modules.go:388 X-Pack Machine Learning is not enabled  
2018-10-22T10:06:44.263+0300 WARN fileset/modules.go:388 X-Pack Machine Learning is not enabled  
Loaded machine learning job configurations

Well I opened Dashboard (for example [Filebeat System] SSH login attempts) I see  
`#### No results found`  
It's OK - I have no data collected yet.

I've started Filebeat:  
`# systemctl start filebeat`

In Discovery I can see new data;

Now I go to Dashboards / [Filebeat System] SSH login attempts and see...  
Could not locate that index-pattern-field (id: system.auth.ssh.event)  
Could not locate that index-pattern-field (id: system.auth.ssh.method)  
Could not locate that index-pattern-field (id: system.auth.user)  
Could not locate that index-pattern-field (id: system.auth.ssh.geoip.location)

What am I doing wrong?  
How can I fix this Issue?

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [October 22, 2018, 4:12pm UTC](https://discuss.elastic.co/t/dashboard-could-not-locate-that-index-pattern-field-id-system-syslog-hostname-and-other-errors/153119/4 "2018-10-22T16:12:24Z")

</div>

Hmm, could you try going into your index pattern settings and refresh the index pattern?

---

<div class="post-metadata">

**Author:** ![09958a6c84c61fe52414](https://avatars.discourse-cdn.com/v4/letter/0/cdc98d/32.png) [@09958a6c84c61fe52414](https://discuss.elastic.co/u/09958a6c84c61fe52414)\
**Post date:** [October 23, 2018, 6:00am UTC](https://discuss.elastic.co/t/dashboard-could-not-locate-that-index-pattern-field-id-system-syslog-hostname-and-other-errors/153119/5 "2018-10-23T06:00:13Z")

</div>

I've tried Management - Index Patterns - Refresh field list (you mean this, yes?) - I still have lots of error like  
`Could not locate that index-pattern-field (id: system.auth.ssh.event)`  
in Dashboards

---

<div class="post-metadata">

**Author:** ![09958a6c84c61fe52414](https://avatars.discourse-cdn.com/v4/letter/0/cdc98d/32.png) [@09958a6c84c61fe52414](https://discuss.elastic.co/u/09958a6c84c61fe52414)\
**Post date:** [October 23, 2018, 8:42am UTC](https://discuss.elastic.co/t/dashboard-could-not-locate-that-index-pattern-field-id-system-syslog-hostname-and-other-errors/153119/6 "2018-10-23T08:42:17Z")

</div>

So I've found simple solution:

I've deleted all indices, visualusations, dashboards. In **/etc/filebeat/filebeat.yml** I've configured  
**output.elasticsearch** and commented **output.logstash**.  
Then I've just run  
**filebeat setup**  
It uploaded template and dashboards. I've started filebeat and so new data in Deiscovery - and no errors in Dashboards!

So I came back to **/etc/filebeat/filebeat.yml** , commented **output.elasticsearch** and uncommented **output.logstash**.

No it works fine, sending data to **Logstash**

Thank you for help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2018, 8:42am UTC](https://discuss.elastic.co/t/dashboard-could-not-locate-that-index-pattern-field-id-system-syslog-hostname-and-other-errors/153119/7 "2018-11-20T08:42:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
