# How to check logstash sends logs?

**URL:** <https://discuss.elastic.co/t/how-to-check-logstash-sends-logs/77314>\
**Category:** Logstash\
**Created:** [March 3, 2017, 1:10pm UTC](https://discuss.elastic.co/t/how-to-check-logstash-sends-logs/77314 "2017-03-03T13:10:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [March 3, 2017, 1:10pm UTC](https://discuss.elastic.co/t/how-to-check-logstash-sends-logs/77314/1 "2017-03-03T13:10:49Z")

</div>

Hi,

In Kibana I don't recieve any logs so I can't start with the dashboard. How can I check that Logstash is sending something to Elasticsearch?

Thanks

---

<div class="post-metadata">

**Author:** ![MaciejM](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maciejm/32/15923_2.png) [@MaciejM](https://discuss.elastic.co/u/MaciejM)\
**Post date:** [March 3, 2017, 1:46pm UTC](https://discuss.elastic.co/t/how-to-check-logstash-sends-logs/77314/2 "2017-03-03T13:46:31Z")

</div>

Have you tried using any services that listen on a network to see what is being sent and where? Two such examples are wireshark and fiddler.

---

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [March 3, 2017, 1:49pm UTC](https://discuss.elastic.co/t/how-to-check-logstash-sends-logs/77314/3 "2017-03-03T13:49:54Z")

</div>

Hi, I have logstash, elasticsearch and Kibana on the same server.  
My problem is that Kibana is saying: unable to fetch mapping, do you have any indices pattern?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2017, 6:29am UTC](https://discuss.elastic.co/t/how-to-check-logstash-sends-logs/77314/4 "2017-03-07T06:29:11Z")

</div>

Check your Logstash logs. If Logstash can't send anything to ES it'll tell you about it in the log. If that checks out okay, list the indexes you have in Elasticsearch. Perhaps Logstash is inserting data, just not to the right index?

---

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [March 7, 2017, 5:56pm UTC](https://discuss.elastic.co/t/how-to-check-logstash-sends-logs/77314/5 "2017-03-07T17:56:55Z")

</div>

Hi Magnus,

This thread can be closed. It is the same problem as in the following post:

> [@Can't load an invalid configuration (:reason=\>"Expected one of #](https://discuss.elastic.co/t/cant-load-an-invalid-configuration-reason-expected-one-of/77422/5):
>
> Hmm there i have the problem. I don't really understand the grokking patterns and the config files from Logstash. So I don't know how I can do that what you want me to do. So if someone has some hints for me concerning commenting out which parts and test, I'm open to do it. In Kibana i have the following sentence: unable to fetch mapping. Do you have indices matching the pattern?

Thanks for closing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2017, 5:56pm UTC](https://discuss.elastic.co/t/how-to-check-logstash-sends-logs/77314/6 "2017-04-04T17:56:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
