# How to create filebeat index pattern in Kibana

**URL:** <https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489>\
**Category:** Beats\
**Created:** [June 21, 2016, 12:11pm UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489 "2016-06-21T12:11:05Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [June 21, 2016, 12:11pm UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/1 "2016-06-21T12:11:05Z")

</div>

Hi I am new to the ELK Stack.  
I have successfully installed the ELK services along with the shippers into my server.  
I was able to create the index patterns for topBeat, winlogBeat and packetBeat, which are of no use to me.  
I need to use filebeat for searching through our log files.  
I found in few sites that I need to run the import\_dashboards.ps1 command for importing the filebeat dashboard into kibana.  
Please help me how to create the filebeat index pattern in kibana.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 21, 2016, 12:37pm UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/2 "2016-06-21T12:37:30Z")

</div>

![](https://us1.discourse-cdn.com/elastic/original/2X/e/e26949d8f5b8abe90aa73169aa4e92cbbffc5a29.png)

Assuming you have already configured Filebeat and indexed some data into Elasticsearch, then in Kibana click on Settings, click on Indicies, change the "Index name or pattern" field from "logstash-_" to "filebeat-_". Then Kibana should auto-detect the "Time-field name". Make sure "@timestamp" is selected then click "Create".

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [June 22, 2016, 5:20am UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/3 "2016-06-22T05:20:39Z")

</div>

No, I have not done that yet.  
I have just the default filebeat.yml configuration file in my filebeat installation folder. I need help in configuring and indexing the data into Elasticsearch.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [June 22, 2016, 6:41am UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/4 "2016-06-22T06:41:06Z")

</div>

Did you follow the getting started guide here? [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-getting-started.html)

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [June 22, 2016, 9:06am UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/5 "2016-06-22T09:06:19Z")

</div>

Yes I did tried to follow the steps mentioned in that.  
I configured the basic template to use it with Elasticsearch output instead of with Logstash output.  
And after that to load the template, I get following error,

PS C:\ELK-Stack\filebeat\> Invoke-WebRequest -Method Put -InFile filebeat.template.json -Uri [http://localhost:9200/\_templ](http://localhost:9200/_templ)  
ate/filebeat?Contessa  
The term 'Invoke-WebRequest' is not recognized as the name of a cmdlet, function, script file, or operable program. Che  
ck the spelling of the name, or if a path was included, verify that the path is correct and try again.  
At line:1 char:18

- Invoke-WebRequest \<\<\<\< -Method Put -InFile filebeat.template.json -Uri [http://localhost:9200/\_template/filebeat?Cont](http://localhost:9200/_template/filebeat?Cont)  
essa
  - CategoryInfo : ObjectNotFound: (Invoke-WebRequest:String) [], CommandNotFoundException
  - FullyQualifiedErrorId : CommandNotFoundException

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 22, 2016, 1:20pm UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/6 "2016-06-22T13:20:28Z")

</div>

> [@ramanamohan](#):
>
> The term 'Invoke-WebRequest' is not recognized as the name of a cmdlet

[`Invoke-WebRequest`](https://technet.microsoft.com/en-us/library/hh849901(v=wps.620).aspx) was introduced in PowerShell 3.0. You may need to update your PowerShell version.

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [June 24, 2016, 12:53pm UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/7 "2016-06-24T12:53:15Z")

</div>

Hello,  
Thanks a lot for the suggestion.  
the command is running successfully after upgrading the PS.  
But the filebeat index pattern is not auto detected by Kibana.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 24, 2016, 9:37pm UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/8 "2016-06-24T21:37:51Z")

</div>

Does the index actually exist? What is the output of this query?

`curl http://elasticsearch:9200/_cat/indices?v`

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [June 27, 2016, 6:12am UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/9 "2016-06-27T06:12:39Z")

</div>

I can see the filebeat index as below,

PS C:\ELK-Stack\filebeat\> curl [http://localhost:9200/\_cat/indices?v](http://localhost:9200/_cat/indices?v) -R  
health status index pri rep docs.count docs.deleted store.size pri.store.size  
yellow open winlogbeat-2015.09.09 5 1 70 0 148kb 148kb  
yellow open winlogbeat-2016.02.26 5 1 506 0 743.5kb 743.5kb  
yellow open winlogbeat-2015.09.08 5 1 299 0 441.4kb 441.4kb  
yellow open winlogbeat-2015.12.22 5 1 592 0 869.4kb 869.4kb  
yellow open winlogbeat-2015.12.23 5 1 1024 0 842.7kb 842.7kb  
yellow open winlogbeat-2015.12.24 5 1 448 0 704.2kb 704.2kb  
yellow open winlogbeat-2015.12.25 5 1 249 0 406.2kb 406.2kb  
yellow open filebeat 5 1 0 0 795b 795b  
yellow open winlogbeat-2016.05.09 5 1 1077 0 874.4kb 874.4kb  
yellow open winlogbeat-2015.12.10 5 1 751 0 728.6kb 728.6kb

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [June 28, 2016, 1:07pm UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/10 "2016-06-28T13:07:43Z")

</div>

Hi, can you please help me out to proceed further.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 28, 2016, 3:51pm UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/11 "2016-06-28T15:51:58Z")

</div>

Can you please provide the configuration for your Filebeat and Logstash instances. It looks like there is a problem with your Filebeat setup because you do not have any daily indices present, just one called "filebeat".

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [June 29, 2016, 9:13am UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/13 "2016-06-29T09:13:34Z")

</div>

I have attached the filebeat config file.  
I don't have the logstash config file

 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/be6a9b1855111eb16b8ed222fccecdb2f8688673.jpg)

---

<div class="post-metadata">

**Author:** ![ramanamohan](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@ramanamohan](https://discuss.elastic.co/u/ramanamohan)\
**Post date:** [July 4, 2016, 5:52am UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/14 "2016-07-04T05:52:44Z")

</div>

Hi, I have attached the config file. Can you please help me out further.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2016, 12:11pm UTC](https://discuss.elastic.co/t/how-to-create-filebeat-index-pattern-in-kibana/53489/15 "2016-07-12T12:11:08Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
