# Filebeat dashboards broken for 6.0

**URL:** https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535
**Category:** Beats
**Tags:** filebeat
**Created:** [December 20, 2017, 1:47am UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535 "2017-12-20T01:47:01Z")
**Posts on this page:** 14
**Page:** 1

<div class="post-metadata">

### Author: ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)
#### Post date: [December 20, 2017, 1:47am UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/1 "2017-12-20T01:47:01Z")

</div>

Looks like there are several visualizations that need to have the .keyword value appended to them. Is this a known issue? Doesn't look like there's a 6.0 folder yet so that's my guess.

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 21, 2017, 4:50am UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/2 "2017-12-21T04:50:20Z")

</div>

Which filebeat version are you using? 6.0 dashboards are only in FB 5.6.

---

<div class="post-metadata">

### Author: ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)
#### Post date: [December 21, 2017, 6:35pm UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/3 "2017-12-21T18:35:33Z")

</div>

this is the default dir. I'll just wait for the 6.0 ones and modify the default ones to work for now. Not sure if it's a high priority.

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 21, 2017, 9:02pm UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/4 "2017-12-21T21:02:28Z")

</div>

Which filebeat version do you have?

---

<div class="post-metadata">

### Author: ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)
#### Post date: [December 21, 2017, 9:22pm UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/5 "2017-12-21T21:22:15Z")

</div>

6.1 as I just upgraded. Just curious if there was a timetable for this or I should create my own method for installing custom dashboards.

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 26, 2017, 9:20pm UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/6 "2017-12-26T21:20:42Z")

</div>

So if you go with 6.1 and load the dashboards, the filebeat dashboards are still broken? If they are broken, feel free to open a Github issue or directly a PR to fix it in the beats repo.

---

<div class="post-metadata">

### Author: ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)
#### Post date: [December 26, 2017, 11:59pm UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/7 "2017-12-26T23:59:51Z")

</div>

I can do that, but should I create a 6.0 folder or modify the default? because I'm sure the change I'll make won't be backwards compatible.

---

<div class="post-metadata">

### Author: ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)
#### Post date: [December 27, 2017, 12:07am UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/8 "2017-12-27T00:07:59Z")

</div>

Actually, it kind of feels like these are generated on your end as they tend to use a specific ID hash. Not sure you want me to be making the pull requests in the .json files themselves.

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 27, 2017, 1:19am UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/9 "2017-12-27T01:19:11Z")

</div>

Can you be more specific which one of the dashboards is broken so I can try it out?

Just to be sure: You removed all dashboards you loaded with a beat \< 5.6 and loaded the dashboards with 6.1. Then you see some errors in some / all of the filebeat dashboards?

For the directory, default is the one loaded with 6.x.

---

<div class="post-metadata">

### Author: ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)
#### Post date: [December 27, 2017, 5:41pm UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/10 "2017-12-27T17:41:39Z")

</div>

both the dashboard/visualization/save searches use the wrong fields on multiple occasions under the filebeat/modules/\_meta/kibana directories. They will use a field that isn't the .keyword field so matches never occur in 6.x

Take for example:  
beats/filebeat/module/system/\_meta/kibana/5.x/visualization/f398d2f0-fa77-11e6-ae9b-81e5311e8cab.json

one of the fields it uses is:  
[system.auth.useradd.name](http://system.auth.useradd.name)  
but it should be:  
system.auth.useradd.name.keyword

Basically a 6.x version should be cut since filebeat does a version check to load in the dashboards and probably don't want to break the default ones as they are pre 5.x

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [December 29, 2017, 2:00am UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/11 "2017-12-29T02:00:00Z")

</div>

Filebeat is shipped with 2 versions of the dashboards. One is in the `5.x` directory and the other one in `default`. If you run filebeat against Kibana 6 and it loads the one from the 5.x directory this is a bug, it should load the ones from the `default` directory.

---

<div class="post-metadata">

### Author: ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)
#### Post date: [January 2, 2018, 6:30pm UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/12 "2018-01-02T18:30:53Z")

</div>

right, no it's using the default one. I'm just trying to get across the point that the default one also doesn't work quite right for 6.X for the same reasons and maybe we should cut a 6.x folder vs. fixing the default json files.

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [January 4, 2018, 12:29am UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/13 "2018-01-04T00:29:50Z")

</div>

@djtecha Thanks for your patience on this one. Some renaming of the directories to allow more flexbility is planned here: [https://github.com/elastic/beats/pull/5328](https://github.com/elastic/beats/pull/5328)

For the issue with the keyword, perhapse @monica knows more? Could you also open a Github issue with it?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 1, 2018, 12:30am UTC](https://discuss.elastic.co/t/filebeat-dashboards-broken-for-6-0/112535/14 "2018-02-01T00:30:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
