# How to index the logstash filter and filter not showing up in Kibana

**URL:** https://discuss.elastic.co/t/how-to-index-the-logstash-filter-and-filter-not-showing-up-in-kibana/55277
**Category:** Logstash
**Created:** [July 12, 2016, 9:50am UTC](https://discuss.elastic.co/t/how-to-index-the-logstash-filter-and-filter-not-showing-up-in-kibana/55277 "2016-07-12T09:50:08Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Preeti\_Sharma](https://avatars.discourse-cdn.com/v4/letter/p/f4b2a3/32.png) [@Preeti\_Sharma](https://discuss.elastic.co/u/Preeti_Sharma)
#### Post date: [July 12, 2016, 9:50am UTC](https://discuss.elastic.co/t/how-to-index-the-logstash-filter-and-filter-not-showing-up-in-kibana/55277/1 "2016-07-12T09:50:08Z")

</div>

```
Here is my logstash conf

```

input {  
file {  
path =\> '/home/logs/corporate\_access.log'  
}  
}

filter {  
grok {

match =\> {  
"message" =\> "User id: %{NUMBER:UserId}, Client id:%{NUMBER:ClientId}"  
}

}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}

Here is my log data :

`{ "_index": "filebeat-2016.07.12", "_type": "corporate-access", "_id": "AVXdvwm4Om7vxCUl3Ywh", "_score": null, "_source": { "message": "12 Jul 2016 11:45:25,218 http-bio-9080-exec-10 [INFO] corporate_access - Request details - Uri: /corporate/analytics/report/1278829, Ip: x.x.x.x, **User id:** 12315, **Client id:** 10905", "@version": "1", "@timestamp": "2016-07-12T06:15:26.308Z", "fields": null, "beat": { "hostname": "abc.xyz.df", "name": "abc.xyz.df" }, "source": "/home/logs/corporate_access.log", "offset": 6962908, "type": "corporate-access", "input_type": "log", "count": 1, "host": "abc.xyz.df", "tags": ["beats_input_codec_plain_applied"] }, "fields": { "@timestamp": [1468304126308] }, "sort": [1468304126308] }`

My problem is these filters are not creating fields and neither showing up in kibana

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [July 13, 2016, 5:36am UTC](https://discuss.elastic.co/t/how-to-index-the-logstash-filter-and-filter-not-showing-up-in-kibana/55277/2 "2016-07-13T05:36:13Z")

</div>

Attack one problem at a time. Let's start with the grok problem. Shouldn't you have a space after "Client id:" in your grok expression?

If that doesn't help, forget about Kibana and Elasticsearch for now and replace the elasticsearch output with a `stdout { codec => rubydebug }` output that dumps messages to Logstash's stdout. What do you get? Please don't destroy the evidence by inserting `**` markers.

---

<div class="post-metadata">

### Author: ![Preeti\_Sharma](https://avatars.discourse-cdn.com/v4/letter/p/f4b2a3/32.png) [@Preeti\_Sharma](https://discuss.elastic.co/u/Preeti_Sharma)
#### Post date: [July 13, 2016, 5:50am UTC](https://discuss.elastic.co/t/how-to-index-the-logstash-filter-and-filter-not-showing-up-in-kibana/55277/3 "2016-07-13T05:50:04Z")

</div>

Hi Magnus , I am able to grok now . I have added tags as well. Problem is  
solved. I have to unistall logstash and reinstall it as it was throwing  
Manticore::SocketException: Connection refused.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:48am UTC](https://discuss.elastic.co/t/how-to-index-the-logstash-filter-and-filter-not-showing-up-in-kibana/55277/4 "2017-07-06T04:48:20Z")

</div>


