# Documents are stored on elasticsearch, can be checked via query, but Kibana does not find it in the discovery tab

**URL:** <https://discuss.elastic.co/t/documents-are-stored-on-elasticsearch-can-be-checked-via-query-but-kibana-does-not-find-it-in-the-discovery-tab/235206>\
**Category:** Kibana\
**Created:** [June 1, 2020, 4:46pm UTC](https://discuss.elastic.co/t/documents-are-stored-on-elasticsearch-can-be-checked-via-query-but-kibana-does-not-find-it-in-the-discovery-tab/235206 "2020-06-01T16:46:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![toshi78](https://avatars.discourse-cdn.com/v4/letter/t/b5e925/32.png) [@toshi78](https://discuss.elastic.co/u/toshi78)\
**Post date:** [June 1, 2020, 4:46pm UTC](https://discuss.elastic.co/t/documents-are-stored-on-elasticsearch-can-be-checked-via-query-but-kibana-does-not-find-it-in-the-discovery-tab/235206/1 "2020-06-01T16:46:20Z")

</div>

Hi!

I'm facing an issue on Kibana: Looks like statistics show that a number of documents are available:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/c/5c528a0393dcaaaff5ec508dd2711a0e8655446d.png)

However, on the `Discover` tab, it does not find any document, no matter the date range set:

> No results match your search criteria

But when I perform the following query (inside the `Dev Tools` tab), it find my documents:

```auto
GET myMapping/_search
{
  "query": {
    "match_all": {}
  }
}

```

Result:

```auto
{
  "took" : 11,
  "timed_out" : false,
  "_shards" : {
    "total" : 9,
    "successful" : 9,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 150,
      "relation" : "eq"
    },
    "max_score" : 1.0,
    "hits" : [
      { ...

```

My mapping is accepted by elasticsearch, and when I setup Kibana's Index, my index and Date field are well recognized:

> curl -u elastic -XPUT "[https://localhost:9200/myMapping](https://localhost:9200/myMapping)" -d @cfg/elastic/myMapping.json -H 'Content-Type: application/json' --cacert docker/ca.crt  
> Enter host password for user 'elastic':

> {"acknowledged":true,"shards\_acknowledged":true,"index":"myMapping"}

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dc23f40c37ab307446edd194fe99d36a108711e9.png)

What's the problem here? How can I find what's wrong?

Thank you in advance.

Note: Im using Docker for the ELK infrastructure, and has 3 nodes. The mapping's settings is set to:

```auto
"settings": {
    "index" : {
        "number_of_shards" : 9,
        "number_of_replicas" : 3
    }
}

```

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [June 1, 2020, 5:04pm UTC](https://discuss.elastic.co/t/documents-are-stored-on-elasticsearch-can-be-checked-via-query-but-kibana-does-not-find-it-in-the-discovery-tab/235206/2 "2020-06-01T17:04:21Z")

</div>

It looks like you have set the field `collectedTime` as the primary time field for your Kibana index pattern: almost all Kibana apps use the time field as a filter on the set of visible documents. It sounds like this might not be what you were expecting, so here are the options I can think of for you:

- Make sure your time fields are being indexed correctly in Elasticsearch
- If you don't want to filter any documents by time, you can choose not to have a primary time field. You would need to delete the index pattern and re-create it without a time field.
- You can change the primary time field by deleting and re-creating the index pattern

---

<div class="post-metadata">

**Author:** ![toshi78](https://avatars.discourse-cdn.com/v4/letter/t/b5e925/32.png) [@toshi78](https://discuss.elastic.co/u/toshi78)\
**Post date:** [June 1, 2020, 5:50pm UTC](https://discuss.elastic.co/t/documents-are-stored-on-elasticsearch-can-be-checked-via-query-but-kibana-does-not-find-it-in-the-discovery-tab/235206/3 "2020-06-01T17:50:04Z")

</div>

I've re-created the index pattern without a time field, and I do see now my documents.

However, I need to use the `collectedTime` field as a primary time field: How can I check what's wrong with it?

Here's a part of my mapping about the Date fields:

```auto
"mappings": {
    "properties": {
	"collectedTime": {
	    "type": "date",
	    "format": "yyyy-MM-dd HH:mm:ss.SSSSSSZ"
	},
	"publish_date": {
	    "type": "date",
	    "format": "yyyy-MM-dd HH:mm:ss.SSSSSSZ"
	},
...

```

And an example of a stored document:

```auto
{
  "_index": "myMapping",
  "_type": "_doc",
  "_id": "wcGacHIBy-QMce-LlAim",
  "_version": 1,
  "_score": 0,
  "_source": {
    "collectedTime": "2020-06-01 17:57:14.792395+0000",
    "publishDate": "2020-05-28 07:01:00.000000+0100",
    ...

```

Note: Kibana well recognized the date format when I setup the `Time filter field`:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/9/190995e030825a2b23b58abc648ff301a37413ab.png)

---

<div class="post-metadata">

**Author:** ![toshi78](https://avatars.discourse-cdn.com/v4/letter/t/b5e925/32.png) [@toshi78](https://discuss.elastic.co/u/toshi78)\
**Post date:** [June 1, 2020, 6:28pm UTC](https://discuss.elastic.co/t/documents-are-stored-on-elasticsearch-can-be-checked-via-query-but-kibana-does-not-find-it-in-the-discovery-tab/235206/4 "2020-06-01T18:28:45Z")

</div>

Well, it suddently worked after several re-creation of the index... I just had a warning when I opened the Discovery tab:

> "fac45350-a42f-11ea-b147-dd0899ebf563" is not a configured index pattern ID  
> Showing the default index pattern: "myMapping" (46d9eb10-a435-11ea-b147-dd0899ebf563)

Any idea of what happened? Maybe the Discovery tab was "stucked" with an old index pattern?

---

<div class="post-metadata">

**Author:** ![wylie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wylie/32/81794_2.png) [@wylie](https://discuss.elastic.co/u/wylie)\
**Post date:** [June 2, 2020, 2:08pm UTC](https://discuss.elastic.co/t/documents-are-stored-on-elasticsearch-can-be-checked-via-query-but-kibana-does-not-find-it-in-the-discovery-tab/235206/5 "2020-06-02T14:08:52Z")

</div>

To use a field as a time field, every document needs to have correct timestamps. I would recommend checking it by using a time range query:

```auto
POST myMapping/_search
{
  "query": {
    "range": {
      "collectedTime": {
        "gte": "now-7d",
        "lte": "now"
      }
    }
  },
  "size": 10
}

```

I think you can work around that error message by switching to a different pattern and back, or by clearing the URL parameters.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2020, 2:09pm UTC](https://discuss.elastic.co/t/documents-are-stored-on-elasticsearch-can-be-checked-via-query-but-kibana-does-not-find-it-in-the-discovery-tab/235206/6 "2020-06-30T14:09:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
