# Discover does not show any data for an index

**URL:** <https://discuss.elastic.co/t/discover-does-not-show-any-data-for-an-index/181222>\
**Category:** Kibana\
**Created:** [May 15, 2019, 2:45pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-an-index/181222 "2019-05-15T14:45:04Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![userelastic](https://avatars.discourse-cdn.com/v4/letter/u/c4cdca/32.png) [@userelastic](https://discuss.elastic.co/u/userelastic)\
**Post date:** [May 15, 2019, 2:45pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-an-index/181222/1 "2019-05-15T14:45:04Z")

</div>

Newbie here; I am am trying vulnwhisperer ([https://github.com/HASecuritySolutions/VulnWhisperer](https://github.com/HASecuritySolutions/VulnWhisperer)) which consolidates all vulnerability data into elastic; I have gone through the install process. Data is being downloaded and ingested into elastic through logstash. What I see odd is that when I go to Discover and select index "logstash-vulnwhisperer-_"; it shows no records.  
If I go to dev tools and run following:  
GET logstash-vulnwhisperer-_/\_search  
{  
"query": {  
"match\_all": {}  
}  
I get lots of records. What can cause this issue with Discover? and how to fix that? any advice?

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [May 15, 2019, 2:55pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-an-index/181222/2 "2019-05-15T14:55:26Z")

</div>

Hi @userelastic,

> I go to Discover and select index "logstash-vulnwhisperer- _";_

Discover works with index patterns, not indices. Have you created a correct [Index Pattern](https://www.elastic.co/guide/en/kibana/current/tutorial-define-index.html) for your index? How does it look like?

Best,  
Oleg

---

<div class="post-metadata">

**Author:** ![userelastic](https://avatars.discourse-cdn.com/v4/letter/u/c4cdca/32.png) [@userelastic](https://discuss.elastic.co/u/userelastic)\
**Post date:** [May 15, 2019, 3:48pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-an-index/181222/3 "2019-05-15T15:48:17Z")

</div>

Hi @azasypkin; thanks for the reply; yes Index Pattern is created; I have attached the screenshot.

 ![kibana-index-pattern](https://us1.discourse-cdn.com/elastic/original/3X/7/4/7476292ac3e4269b2d52bff4d6b17a6abc33acb4.jpeg)

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [May 15, 2019, 4:01pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-an-index/181222/4 "2019-05-15T16:01:57Z")

</div>

Good, I'm off for today, will give it a thought tomorrow. But can you double check that the time range (date/time picker at the top panel) in Discover actually covers the data you have (e.g. choose a very long one, 5 years or something like this)?

---

<div class="post-metadata">

**Author:** ![userelastic](https://avatars.discourse-cdn.com/v4/letter/u/c4cdca/32.png) [@userelastic](https://discuss.elastic.co/u/userelastic)\
**Post date:** [May 15, 2019, 4:13pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-an-index/181222/5 "2019-05-15T16:13:46Z")

</div>

Yes; I tried that by setting period to last 5 years. Thanks for your help and hope to hear from you tomorrow.

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [May 16, 2019, 7:27am UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-an-index/181222/6 "2019-05-16T07:27:02Z")

</div>

Hey,

- Can you please also share a screenshot of the Discover page?
- And, if possible, a tiny fraction of the data that is returned from this query:

```auto
POST logstash-vulnwhisperer-*/_search
{
  "query": {
    "match_all": {}
  }
}

```

And also check whether you have any errors in the browser dev console, just in case. A

---

<div class="post-metadata">

**Author:** ![userelastic](https://avatars.discourse-cdn.com/v4/letter/u/c4cdca/32.png) [@userelastic](https://discuss.elastic.co/u/userelastic)\
**Post date:** [May 16, 2019, 1:33pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-an-index/181222/7 "2019-05-16T13:33:18Z")

</div>

Hi @azasypkin; I end up removing everything and started from scratch; this time it worked fine and all the data is there including the dashboards too. Thanks for your help.

---

<div class="post-metadata">

**Author:** ![azasypkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/azasypkin/32/42216_2.png) [@azasypkin](https://discuss.elastic.co/u/azasypkin)\
**Post date:** [May 16, 2019, 1:35pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-an-index/181222/8 "2019-05-16T13:35:54Z")

</div>

Ha, good to hear that you sorted it out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 13, 2019, 1:36pm UTC](https://discuss.elastic.co/t/discover-does-not-show-any-data-for-an-index/181222/9 "2019-06-13T13:36:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
