# ERROR: Could not locate that index-pattern-field on filebeat

**URL:** https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380
**Category:** Beats
**Tags:** filebeat
**Created:** [July 17, 2017, 10:56am UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380 "2017-07-17T10:56:09Z")
**Posts on this page:** 19
**Page:** 1

<div class="post-metadata">

### Author: ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)
#### Post date: [July 17, 2017, 10:56am UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/1 "2017-07-17T10:56:09Z")

</div>

Hi All,

I have installed ELK stack 5.5.0 Version and beats as of the only file beat installed on my machine.

When i import file beat dashboard and visualization of 5.5.0 version, I'm getting below error while clicking on those visualization and dashboards.

Please check and let us know how do we solve this.

Could not locate that index-pattern-field (id: system.syslog.hostname)

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8bbe4d149d938cc0e7ef8bed5b972fe5c9213f68.png)

And also it shows for all the fields which i click on visualizations and dashboards.

---

<div class="post-metadata">

### Author: ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)
#### Post date: [July 18, 2017, 2:08pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/2 "2017-07-18T14:08:47Z")

</div>

Hi Team,

Can someone reply us, please.?

---

<div class="post-metadata">

### Author: ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)
#### Post date: [July 20, 2017, 11:46am UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/3 "2017-07-20T11:46:18Z")

</div>

Any update on the above issue, please.?

---

<div class="post-metadata">

### Author: ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)
#### Post date: [July 20, 2017, 1:32pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/4 "2017-07-20T13:32:27Z")

</div>

Can you show us which commands you used to load the dashboards?

---

<div class="post-metadata">

### Author: ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)
#### Post date: [July 20, 2017, 3:25pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/5 "2017-07-20T15:25:43Z")

</div>

Hi Tudor,

I use below command for importing filebeat dashboard and visualizations.

PS D:\ELK-Stack5.5\filebeat-5.5.0-windows-x86\_64\scripts\> .\import\_dashboards -dir "D:\ELK-Stack5.5\beats-dashboards-5.5.0\filebeat"

---

<div class="post-metadata">

### Author: ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)
#### Post date: [July 20, 2017, 3:28pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/6 "2017-07-20T15:28:37Z")

</div>

Did you happen to refresh the index pattern (in Kibana) by any chance? If yes, can you try reloading the dashboards again, without refreshing the index pattern.

---

<div class="post-metadata">

### Author: ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)
#### Post date: [July 20, 2017, 3:31pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/7 "2017-07-20T15:31:33Z")

</div>

I have tried both Tudor, even with refresh the index pattern and also deleted the index pattern and created new file beat index pattern and imported again only the dashboard and visualization and searches still this issue comes when i click on any visualizations.

---

<div class="post-metadata">

### Author: ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)
#### Post date: [July 21, 2017, 9:19am UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/8 "2017-07-21T09:19:40Z")

</div>

@Sujith I can't reproduce the issue with ES, Kibana, and Filebeat all at version 5.5.0. Do you have the same? I didn't test on Windows, but I don't expect that to make a difference.

Btw, is there a reason you used the `-dir` option? if you just run `.\import_dashboards`, it downloads the dashboards for you. Can you try that, please?

---

<div class="post-metadata">

### Author: ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)
#### Post date: [July 21, 2017, 12:12pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/9 "2017-07-21T12:12:43Z")

</div>

@tudor Yes, as per the process in document i used -dir option where as to import from local path location.

Since then if i don't use -dir and directly use the command as .\import\_dashboards, then i get below error.

PS D:\ELK-Stack5.5\filebeat-5.5.0-windows-x86\_64\scripts\> .\import\_dashboards.exe  
Created temporary directory C:\Users\skumar10\AppData\Local\Temp\tmp457694015  
Downloading [https://artifacts.elastic.co/downloads/beats/beats-dashboards/beats-dashboards-5.5.0.zip](https://artifacts.elastic.co/downloads/beats/beats-dashboards/beats-dashboards-5.5.0.zip)  
.\import\_dashboards.exe : Error importing URL/file: Failed to download file:  
[https://artifacts.elastic.co/downloads/beats/beats-dashboards/beats-dashboards-5.5.0.zip](https://artifacts.elastic.co/downloads/beats/beats-dashboards/beats-dashboards-5.5.0.zip). Error: Get  
[https://artifacts.elastic.co/downloads/beats/beats-dashboards/beats-dashboards-5.5.0.zip:](https://artifacts.elastic.co/downloads/beats/beats-dashboards/beats-dashboards-5.5.0.zip:) dial tcp 184.73.227.9:443: i/o timeout  
At line:1 char:1

- .\import\_dashboards.exe
- 

```auto
  + CategoryInfo : NotSpecified: (Error importing...43: i/o timeout:String) [], RemoteException
  + FullyQualifiedErrorId : NativeCommandError

```

Exiting

PS D:\ELK-Stack5.5\filebeat-5.5.0-windows-x86\_64\scripts\>

---

<div class="post-metadata">

### Author: ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)
#### Post date: [July 21, 2017, 12:16pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/10 "2017-07-21T12:16:13Z")

</div>

Ok, can you try using the `-file` option where you pass it the zip directly? Something like: `.\import_dashboards.exe -file beats-dashboards-5.5.0.zip`

The error seems to indicate that the index pattern is not correctly loaded, but I have no idea why that would be the case.

---

<div class="post-metadata">

### Author: ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)
#### Post date: [July 21, 2017, 1:12pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/11 "2017-07-21T13:12:10Z")

</div>

@tudor i have used -file too still no luck of importing .

PS D:\ELK-Stack5.5\filebeat-5.5.0-windows-x86\_64\scripts\> .\import\_dashboards.exe -file D:\ELK-Stack5.5\beats.zip  
Created temporary directory C:\Users\skumar10\AppData\Local\Temp\tmp340107743  
Unzip archive C:\Users\skumar10\AppData\Local\Temp\tmp340107743  
Importing Kibana from C:\Users\skumar10\AppData\Local\Temp\tmp340107743\filebeat\dashboard  
Importing Kibana from C:\Users\skumar10\AppData\Local\Temp\tmp340107743\filebeat\search  
Importing Kibana from C:\Users\skumar10\AppData\Local\Temp\tmp340107743\filebeat\visualization

PS D:\ELK-Stack5.5\filebeat-5.5.0-windows-x86\_64\scripts\> .\import\_dashboards.exe -file "D:\ELK-Stack5.5\beats.zip"  
Created temporary directory C:\Users\skumar10\AppData\Local\Temp\tmp853898895  
Unzip archive C:\Users\skumar10\AppData\Local\Temp\tmp853898895  
Importing Kibana from C:\Users\skumar10\AppData\Local\Temp\tmp853898895\filebeat\dashboard  
Importing Kibana from C:\Users\skumar10\AppData\Local\Temp\tmp853898895\filebeat\search  
Importing Kibana from C:\Users\skumar10\AppData\Local\Temp\tmp853898895\filebeat\visualization

---

<div class="post-metadata">

### Author: ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)
#### Post date: [July 24, 2017, 1:15pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/12 "2017-07-24T13:15:20Z")

</div>

@tudor please reply us what needs to be fixed for importing file beat dashboards.

---

<div class="post-metadata">

### Author: ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)
#### Post date: [July 28, 2017, 11:36am UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/13 "2017-07-28T11:36:47Z")

</div>

Hi Team,

Can anyone reply to us the solution, please? It would be great to hear from someone from ELK team about a solution to my issue regarding Filebeat Visualizations and Dashboards.

---

<div class="post-metadata">

### Author: ![gregsh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregsh/32/20827_2.png) [@gregsh](https://discuss.elastic.co/u/gregsh)
#### Post date: [August 4, 2017, 7:18pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/14 "2017-08-04T19:18:03Z")

</div>

I have the same issue with a Centos 7 instance with all 5.5.1 ELK and Filebeat. Error:  
TypeError: "field" is a required parameter  
at FieldAggParam.AggTypesParamTypesFieldProvider.FieldAggParam.write ([http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:254:4916](http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:254:4916))  
at [http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:254:2513](http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:254:2513)  
at AggParams.forEach ()  
at AggParams.AggTypesAggParamsProvider.AggParams.write ([http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:254:2471](http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:254:2471))  
at AggConfig.VisAggConfigProvider.AggConfig.write ([http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:255:10051](http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:255:10051))  
at AggConfig.VisAggConfigProvider.AggConfig.toDsl ([http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:255:10880](http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:255:10880))  
at [http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:257:7400](http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:257:7400)  
at Array.forEach ()  
at AggConfigs.VisAggConfigsProvider.AggConfigs.toDsl ([http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:257:7183](http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:257:7183))  
at [http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:257:28628](http://ec2-54-165-21-197.compute-1.amazonaws.com:5601/bundles/kibana.bundle.js?v=15382:257:28628)

---

<div class="post-metadata">

### Author: ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)
#### Post date: [August 7, 2017, 11:27am UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/15 "2017-08-07T11:27:23Z")

</div>

please anyone from the team can help us solving this error in filebeat dashboard and visualization of 5.5.0 version

---

<div class="post-metadata">

### Author: ![gregsh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregsh/32/20827_2.png) [@gregsh](https://discuss.elastic.co/u/gregsh)
#### Post date: [August 7, 2017, 2:48pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/16 "2017-08-07T14:48:50Z")

</div>

I found that deleting my Kibana indexes (and losing my past data) helped solve the problem. Once Kibana "saw" the Filebeat data it built a new index and the field parameters. I'm still learning ELK and Beats so this method is probably not correct, but it helped my issue.

---

<div class="post-metadata">

### Author: ![Sujith](https://avatars.discourse-cdn.com/v4/letter/s/77aa72/32.png) [@Sujith](https://discuss.elastic.co/u/Sujith)
#### Post date: [August 8, 2017, 6:33pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/17 "2017-08-08T18:33:10Z")

</div>

@gregsh i have tried deleting my Kibana indexes and filebeat with new index, Still no luck

---

<div class="post-metadata">

### Author: ![gregsh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregsh/32/20827_2.png) [@gregsh](https://discuss.elastic.co/u/gregsh)
#### Post date: [August 8, 2017, 7:28pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/18 "2017-08-08T19:28:41Z")

</div>

Try this, delete Kibana indexes then on a client or on the host load Filebeat (see [here](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-installation.html))  
Then run "[filebeat.sh](http://filebeat.sh) -e -modules=system,auditd -setup" - this will add the searches, visualizations and dashboards for Filebeat system and auditd.  
Start Filebeat on your client(s) and then look at Kibana after a minute. You should see it has a filebeat-\* index and that there are events in Discover. Check out the Dashboard section for the Filebeat dashboards.  
This worked for me. I have stayed away from the index refresh, it seems to corrupt things.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 5, 2017, 7:28pm UTC](https://discuss.elastic.co/t/error-could-not-locate-that-index-pattern-field-on-filebeat/93380/19 "2017-09-05T19:28:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
