# Default Index pattern not found?

**URL:** <https://discuss.elastic.co/t/default-index-pattern-not-found/132126>\
**Category:** Kibana\
**Created:** [May 16, 2018, 1:05pm UTC](https://discuss.elastic.co/t/default-index-pattern-not-found/132126 "2018-05-16T13:05:48Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![NotPete](https://avatars.discourse-cdn.com/v4/letter/n/8baadc/32.png) [@NotPete](https://discuss.elastic.co/u/NotPete)\
**Post date:** [May 16, 2018, 1:05pm UTC](https://discuss.elastic.co/t/default-index-pattern-not-found/132126/1 "2018-05-16T13:05:48Z")

</div>

Hello Everyone,

I am still new to ELK Stack so please be gentle 🙂

I have all components "working" without error now, however, when I go to Kibana it says "No default index pattern. You must select or create one to continue".

I can't get Kibana to see the "logstash-\*" index.

If I select the "Include system indices" checkbox, I can see all the monitoring indices, but not the "logstash-\*" ones that have my data in them:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a1b7c224e16212383d759644587fee20fdaa3fab.png)

BUT, when I go to Dev Tools and run "\_cat/indices" I see them:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d2555c70f7ef17f6a2b26fa78f39fa4846ca31af.png)

Please let me know what I've missed, or if you require any more info.

Thank you

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [May 16, 2018, 11:08pm UTC](https://discuss.elastic.co/t/default-index-pattern-not-found/132126/2 "2018-05-16T23:08:07Z")

</div>

Based on the output of `_cat/indices` I'm guessing that the problem is that the `logstash-*` indices don't have any documents, the line for my logstash index looks like this:

```auto
green open logstash-0 bDLwXNEjSEKcyV-6AvRGpA 1 0 14005 0 48.2mb 48.2mb

```

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [May 16, 2018, 11:08pm UTC](https://discuss.elastic.co/t/default-index-pattern-not-found/132126/3 "2018-05-16T23:08:47Z")

</div>

@chrisronline any ideas here?

---

<div class="post-metadata">

**Author:** ![NotPete](https://avatars.discourse-cdn.com/v4/letter/n/8baadc/32.png) [@NotPete](https://discuss.elastic.co/u/NotPete)\
**Post date:** [May 17, 2018, 11:08am UTC](https://discuss.elastic.co/t/default-index-pattern-not-found/132126/4 "2018-05-17T11:08:18Z")

</div>

@spalger

Thank you for the reply, however when I run that from the CLI I get the following showing that there are documents:

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3c5e660ee3e0f7132353cd398c95ee0725de2372.png)

---

<div class="post-metadata">

**Author:** ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)\
**Post date:** [May 17, 2018, 3:18pm UTC](https://discuss.elastic.co/t/default-index-pattern-not-found/132126/5 "2018-05-17T15:18:54Z")

</div>

This looks related: [https://github.com/elastic/kibana/issues/15666](https://github.com/elastic/kibana/issues/15666)

Right now, if you try and search against an empty index, it will not show up as a result. If you put at least one document in the index, it should start working.

---

<div class="post-metadata">

**Author:** ![NotPete](https://avatars.discourse-cdn.com/v4/letter/n/8baadc/32.png) [@NotPete](https://discuss.elastic.co/u/NotPete)\
**Post date:** [May 17, 2018, 4:33pm UTC](https://discuss.elastic.co/t/default-index-pattern-not-found/132126/6 "2018-05-17T16:33:16Z")

</div>

Thank you both for your reply.

However, maybe I'm missing something.

I can't see the screenshots in my previous posts for some reason, but...

Both of you are saying that my index is empty, however, from my previous screenshot it shows that they have documents.

I ran a search on one and I get responses.

Here is the "count" from the 3 indices that are created so far:

```
> curl -X GET "localhost:9200/_cat/count/logstash-2018.05.15?v" -u elastic
Enter host password for user 'elastic':
epoch timestamp count
1526574595 12:29:55 634
> curl -X GET "localhost:9200/_cat/count/logstash-2018.05.16?v" -u elastic
Enter host password for user 'elastic':
epoch timestamp count
1526574612 12:30:12 1864
> curl -X GET "localhost:9200/_cat/count/logstash-2018.05.17?v" -u elastic
Enter host password for user 'elastic':
epoch timestamp count
1526574621 12:30:21 13

```

Please let me know if I am not understanding what you both are trying to explain to me.

Thank you

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [May 17, 2018, 5:10pm UTC](https://discuss.elastic.co/t/default-index-pattern-not-found/132126/7 "2018-05-17T17:10:20Z")

</div>

Yeah, based on the updated screenshot from your terminal I'm seeing docs, but do you see that same info when you run `GET _cat/count/logstash-2018.05.15` in the dev tools?

Are you signing into Kibana with the `elastic` user like you are in the terminal?

---

<div class="post-metadata">

**Author:** ![NotPete](https://avatars.discourse-cdn.com/v4/letter/n/8baadc/32.png) [@NotPete](https://discuss.elastic.co/u/NotPete)\
**Post date:** [May 17, 2018, 6:41pm UTC](https://discuss.elastic.co/t/default-index-pattern-not-found/132126/8 "2018-05-17T18:41:54Z")

</div>

@spalger

Thank you for the quick response, you were correct.

I was using the "kibana" user to log into Kibana and i got a 403 when trying query from the dev tools.

I logged in as the "elastic" user and I can now add the default index pattern.

Before I set the default index pattern, is this how I'm supposed to log into Kibana, with the "elastic" user?

Or, is there something wrong with the permissions on the "kibana" user?

Thank you

---

<div class="post-metadata">

**Author:** ![spalger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spalger/32/14092_2.png) [@spalger](https://discuss.elastic.co/u/spalger)\
**Post date:** [May 18, 2018, 1:05pm UTC](https://discuss.elastic.co/t/default-index-pattern-not-found/132126/9 "2018-05-18T13:05:51Z")

</div>

Nothing wrong with the permissions, it just doesn’t have access to anything it doesn’t need. I suggest using the `elastic` user while you’re getting to know Kibana, and then once you’re ready to start sharing access with others checkout the Management \> Users section and creat a some new users with the specific privileges they will need.

---

<div class="post-metadata">

**Author:** ![NotPete](https://avatars.discourse-cdn.com/v4/letter/n/8baadc/32.png) [@NotPete](https://discuss.elastic.co/u/NotPete)\
**Post date:** [May 18, 2018, 1:34pm UTC](https://discuss.elastic.co/t/default-index-pattern-not-found/132126/10 "2018-05-18T13:34:43Z")

</div>

@spalger

Thank you for your assistance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2018, 1:34pm UTC](https://discuss.elastic.co/t/default-index-pattern-not-found/132126/11 "2018-06-15T13:34:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
