# I am not getting the logs in Kibana

**URL:** <https://discuss.elastic.co/t/i-am-not-getting-the-logs-in-kibana/129079>\
**Category:** Elasticsearch\
**Created:** [April 23, 2018, 10:29am UTC](https://discuss.elastic.co/t/i-am-not-getting-the-logs-in-kibana/129079 "2018-04-23T10:29:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![siva1](https://avatars.discourse-cdn.com/v4/letter/s/91b2a8/32.png) [@siva1](https://discuss.elastic.co/u/siva1)\
**Post date:** [April 23, 2018, 10:29am UTC](https://discuss.elastic.co/t/i-am-not-getting-the-logs-in-kibana/129079/1 "2018-04-23T10:29:51Z")

</div>

Hi..Guys..

==\> /var/log/logstash/logstash-plain.log \<==  
elk\_1 | [2018-04-23T10:04:15,350][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"/opt/logstash/modules/fb\_apache/configuration"}  
elk\_1 | [2018-04-23T10:04:15,357][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"/opt/logstash/modules/netflow/configuration"}  
elk\_1 | [2018-04-23T10:04:15,362][INFO][logstash.setting.writabledirectory] Creating directory {:setting=\>"path.queue", :path=\>"/opt/logstash/data/queue"}  
elk\_1 | [2018-04-23T10:04:15,363][INFO][logstash.setting.writabledirectory] Creating directory {:setting=\>"path.dead\_letter\_queue", :path=\>"/opt/logstash/data/dead\_letter\_queue"}  
elk\_1 | [2018-04-23T10:04:15,398][INFO][logstash.agent] No persistent UUID file found. Generating new UUID {:uuid=\>"2bcb9d7e-6c80-42ae-b635-9a306043e2bc", :path=\>"/opt/logstash/data/uuid"}  
elk\_1 | [2018-04-23T10:04:16,390][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
elk\_1 | [2018-04-23T10:04:16,393][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
elk\_1 | [2018-04-23T10:04:16,573][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
elk\_1 | [2018-04-23T10:04:16,574][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
elk\_1 | [2018-04-23T10:04:16,781][INFO][logstash.pipeline] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>500}  
elk\_1 | [2018-04-23T10:04:17,328][INFO][logstash.inputs.beats] Beats inputs: Starting input listener {:address=\>"0.0.0.0:5044"}  
elk\_1 | [2018-04-23T10:04:17,413][INFO][logstash.pipeline] Pipeline main started  
elk\_1 | [2018-04-23T10:04:17,517][INFO][logstash.inputs.udp] Starting UDP listener {:address=\>"0.0.0.0:5000"}  
elk\_1 | [2018-04-23T10:04:17,525][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
elk\_1 | [2018-04-23T10:04:17,553][INFO][logstash.inputs.udp] UDP listener started {:address=\>"0.0.0.0:5000", :receive\_buffer\_bytes=\>"106496", :queue\_size=\>"2000"}  
elk\_1 | [2018-04-23T10:04:17,562][INFO][org.logstash.beats.Server] Starting server on port: 5044

**Logstash config file** :--  
input {  
udp {  
type =\> "json-docker"  
port =\> 5000  
codec =\> json  
}  
}

filter {  
if [docker][name] =~ "goofy\_wing" or [docker][image] =~ "twitterapp" {  
grok {  
break\_on\_match =\> false  
match =\> ["message", "(?(?\<=\s\sMS:\s)([\S]\*))" ]  
tag\_on\_failure =\> []  
}  
}  
}

filter {  
if [docker][name] =~ "goofy\_wing" or [docker][image] =~ "twitterapp" {  
grok {  
break\_on\_match =\> false  
match =\> ["message", "(?(?\<=\s|\sAPI:\s)([\S]\*))" ]  
tag\_on\_failure =\> []  
}  
}  
}  
**Output :--**  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
manage\_template =\> false  
index =\> "logstash-%{+YYYY.MM.dd}"  
}  
}

Please help me

---

<div class="post-metadata">

**Author:** ![MariumHassan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mariumhassan/32/30321_2.png) [@MariumHassan](https://discuss.elastic.co/u/MariumHassan)\
**Post date:** [April 23, 2018, 11:00am UTC](https://discuss.elastic.co/t/i-am-not-getting-the-logs-in-kibana/129079/2 "2018-04-23T11:00:08Z")

</div>

Hi,

Does hitting [http://localhost:9200/\_cat/indices?v](http://localhost:9200/_cat/indices?v) give you an index with name "logstash-2018-04-23"? If yes, then it will have docs.count field against it. Make sure that you have some documents inside that index. If everything is fine there then you can check Kibana. It might be an issue of the index pattern that you have created in kibana.

Also, you don't need to add multiple filters in your configuration file.

---

<div class="post-metadata">

**Author:** ![siva1](https://avatars.discourse-cdn.com/v4/letter/s/91b2a8/32.png) [@siva1](https://discuss.elastic.co/u/siva1)\
**Post date:** [April 23, 2018, 11:22am UTC](https://discuss.elastic.co/t/i-am-not-getting-the-logs-in-kibana/129079/3 "2018-04-23T11:22:48Z")

</div>

Hi,  
@MariumHassan thanks for the reply  
when i am hitting the link [http://localhost:9200/\_cat/indices?v](http://localhost:9200/_cat/indices?v) getting like this

health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
yellow open .kibana XzSeONyKTZuJFM3tSISlsA 1 1 1 0 3.2kb 3.2kb

my output file i am mention index is index =\> "logstash-%{+YYYY.MM.dd}", then why it is show's .kibana?  
i think .kibana index is the default one, can u tell me how to set my kibana index.

---

<div class="post-metadata">

**Author:** ![MariumHassan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mariumhassan/32/30321_2.png) [@MariumHassan](https://discuss.elastic.co/u/MariumHassan)\
**Post date:** [April 23, 2018, 11:44am UTC](https://discuss.elastic.co/t/i-am-not-getting-the-logs-in-kibana/129079/4 "2018-04-23T11:44:36Z")

</div>

.kibana is the index used by kibana. It stores visualizations etc in it and doesn't have the logs you send. You should have an index "logstash" with date in elasticsearch that should be created by:

```auto
output {
elasticsearch {
hosts => ["localhost:9200"]
manage_template => false
index => "logstash-%{+YYYY.MM.dd}"
}
}

```

If it does not exist, that means that your elasticsearch is not receiving data, and you need to check your configuration file. If the index is there with the data then it might be kibana issue.

Also, make sure that your grok pattern is right using grok debugger.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2018, 11:44am UTC](https://discuss.elastic.co/t/i-am-not-getting-the-logs-in-kibana/129079/5 "2018-05-21T11:44:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
