# Empty column "Last failed source"

**URL:** <https://discuss.elastic.co/t/empty-column-last-failed-source/222550>\
**Category:** Kibana\
**Created:** [March 7, 2020, 8:56am UTC](https://discuss.elastic.co/t/empty-column-last-failed-source/222550 "2020-03-07T08:56:40Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![NogNeetMachinaal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nogneetmachinaal/32/58893_2.png) [@NogNeetMachinaal](https://discuss.elastic.co/u/NogNeetMachinaal)\
**Post date:** [March 7, 2020, 8:56am UTC](https://discuss.elastic.co/t/empty-column-last-failed-source/222550/1 "2020-03-07T08:56:40Z")

</div>

See also attached screenshot:  
I would expect IP-adresses in the column "Last failed source". This expectations is based on the timestamp in the column "Last failure".

Since this is not the case: what would it take to make that happen?

I'm running ES with Kibana version 7.6.1.; including the respective Auditbeat and Packetbeat shippers.

 ![failed-with-empty-column](https://us1.discourse-cdn.com/elastic/original/3X/f/3/f3c098e207e201fe327ae88888bda49a61655f1c.png)

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 12, 2020, 2:54pm UTC](https://discuss.elastic.co/t/empty-column-last-failed-source/222550/2 "2020-03-12T14:54:57Z")

</div>

Hi, this is a question more about the data collection than Kibana (which only displays what data there is in ES).  
You should try asking this in the Beats sub-forum.

---

<div class="post-metadata">

**Author:** ![NogNeetMachinaal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nogneetmachinaal/32/58893_2.png) [@NogNeetMachinaal](https://discuss.elastic.co/u/NogNeetMachinaal)\
**Post date:** [March 12, 2020, 5:29pm UTC](https://discuss.elastic.co/t/empty-column-last-failed-source/222550/3 "2020-03-12T17:29:15Z")

</div>

Thank you for the response Marius.

While a valid possibility in itself, it is not the case here.

The data seems to be there - I have checked this with Discovery on the index Auditbeat =\> this is the data source for this part.

However, I'm not aware of something that can be used for a crosscheck =\> is Kibana reading from the same tables as Auditbeat is writing to.

I have a similar issue with Packetbeat and TLS: there seems to be a mismatch in the datascheme.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 12, 2020, 11:48pm UTC](https://discuss.elastic.co/t/empty-column-last-failed-source/222550/4 "2020-03-12T23:48:22Z")

</div>

Ah, I just realized now that you are in the SIEM app. I apologize, at first sight it seemed like a table created in Discover. It might be the same issue, I'll ping the SIEM team about it.

---

<div class="post-metadata">

**Author:** ![NogNeetMachinaal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nogneetmachinaal/32/58893_2.png) [@NogNeetMachinaal](https://discuss.elastic.co/u/NogNeetMachinaal)\
**Post date:** [March 13, 2020, 7:30pm UTC](https://discuss.elastic.co/t/empty-column-last-failed-source/222550/5 "2020-03-13T19:30:59Z")

</div>

Thanks Marius.  
Let me know if there is anything I can do to help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2020, 7:31pm UTC](https://discuss.elastic.co/t/empty-column-last-failed-source/222550/6 "2020-04-10T19:31:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
