# I can't create indexes patterns with ECK

**URL:** <https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194>\
**Category:** Kibana\
**Created:** [June 4, 2019, 1:21pm UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194 "2019-06-04T13:21:31Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Benjamin\_Carriou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_carriou/32/47347_2.png) [@Benjamin\_Carriou](https://discuss.elastic.co/u/Benjamin_Carriou)\
**Post date:** [June 4, 2019, 1:21pm UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/1 "2019-06-04T13:21:31Z")

</div>

Hello everyone,

I just freshly installed an Elastic stack on Kubernetes in following tutorial:  
[https://www.elastic.co/guide/en/cloud-on-k8s/current/index.html](https://www.elastic.co/guide/en/cloud-on-k8s/current/index.html)

So I have an elasticsearch cluster of two nodes (test phase;)) + an instance of Kibana that connects to it.

Everything seems to work because everything is in a "green" state:

- Elasticsearch

- Kibana

I can contact the ES API by filling in the access account (\* data has been changed for security reasons \*):

```
curl -u "elastic:pass" https://es.cloud.example.com
{
  "name" : "cloud-es-f2gqfdlsp6",
  "cluster_name" : "cloud",
  "cluster_uuid" : "rHnRmGsWSvyS14rGIyWq3w",
  "version" : {
    "number" : "7.1.0",
    "build_flavor" : "default",
    "build_type" : "docker",
    "build_hash" : "606a173",
    "build_date" : "2019-05-16T00:43:15.323135Z",
    "build_snapshot" : false,
    "lucene_version" : "8.0.0",
    "minimum_wire_compatibility_version" : "6.8.0",
    "minimum_index_compatibility_version" : "6.0.0-beta1"
  },
  "tagline" : "You Know, for Search"
}

```

I can connect to Kibana with the dedicated account and no errors appear.

I deployed filebeat and metricbeat on my k8s cluster and made sure they send their data to my elastic cluster.

This seems to be happening because I do not see any error in the logs and the indices are correctly created in ES:

```
curl -u "elastic:pass" https://es.cloud.example.com_cat/indices

green open kibana_sample_data_logs IH22ll_MSEKOMSjNKTN5Lg 1 1 14005 0 21.9mb 11mb
green open .monitoring-es-7-2019.06.03 S5B1_mBrQtCAKxM4ca98Hw 1 1 23617 28468 31.9mb 15.7mb
green open .kibana_1 2Y427ZARRG6ktI8Z6ePMBg 1 1 0 0 566b 283b
green open metricbeat-7.1.1-2019.06.03-000001 0lIhb99UQ1mf-0ryyk5XTQ 1 1 134396 0 140.3mb 70.3mb
green open .monitoring-kibana-7-2019.06.03 JdWb-TiFROCjfedvrXLN4g 1 1 1676 0 1.1mb 534.5kb
green open .kibana_task_manager idILcj5mRHOtsYoGhNWxRA 1 1 2 0 74.9kb 45.5kb
green open .kibana 0qrECl53RcqAoGG2nlLjIg 1 1 30 6 1.2mb 647.8kb
green open .security-7 5HaugK0CQOauG2CFN6B_Iw 1 1 5 0 80.4kb 40.2kb
green open .kibana_2 ert8jPjeTHGIhi0S3rb9mw 1 1 0 0 566b 283b
green open filebeat-7.1.1-2019.06.03-000001 DzD2Q4qjQUiV4kDuO4k7ig 1 1 12159278 0 12.4gb 5.5gb

```

I wish now to be able to discover these indices in kibana by creating index patterns (ex: filebeat- \*).

So I'm the classic procedure that seems to work:

 ![Capture%20d%E2%80%99%C3%A9cran%20de%202019-06-03%2015-42-31](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e7bb0710cc441b9c496e49a3b8dd7f4eddc4e075.png)

 ![Capture%20d%E2%80%99%C3%A9cran%20de%202019-06-03%2015-42-38](https://us1.discourse-cdn.com/elastic/original/3X/b/7/b7ff9d9ab5d699a7a20518f604dfe5bd88f062c2.png)

 ![Capture%20d%E2%80%99%C3%A9cran%20de%202019-06-03%2015-42-46](https://us1.discourse-cdn.com/elastic/original/3X/e/e/eed090f98a2ce9fc8e1757510417a6fb53db058c.png)

The index pattern seems created, however when I click on the tab discover, it returns me to the menu of creation of the index pattern:

 ![Capture%20d%E2%80%99%C3%A9cran%20de%202019-06-03%2015-42-58](https://us1.discourse-cdn.com/elastic/original/3X/4/0/403f69faa19e249d8df3ada89e8ccfe77728fb93.png)

It does not seem to find this index pattern previously created.

However, when I go to the tabs "infrastucture" and "logs", the contents of the indexes are displayed:

 ![Capture%20d%E2%80%99%C3%A9cran%20de%202019-06-03%2015-49-55](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2da9b59420802897e5950453063670a7ea326003.png)

If I open the chrome admin console, I can see the following message:

 ![Capture%20d%E2%80%99%C3%A9cran%20de%202019-06-03%2015-51-34](https://us1.discourse-cdn.com/elastic/original/3X/9/8/986c00a3848de202ee0a87b37f0ef54176cb00a0.png)

Any ideas ?

Benjamin

---

<div class="post-metadata">

**Author:** ![jen-huang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jen-huang/32/74327_2.png) [@jen-huang](https://discuss.elastic.co/u/jen-huang)\
**Post date:** [June 4, 2019, 11:29pm UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/2 "2019-06-04T23:29:05Z")

</div>

Hi, I believe this is occurring because even though the index pattern is created, it has not been set as the default index pattern for some reason. If you still have the URL of the page [in this screenshot](https://discuss.elastic.co/uploads/short-url/y4EukySdqXgKdo2ib4RGJzTK2Qc.png), try clicking the **Star icon** to set it as your default index pattern.

However the concerning part to me is that in the same screenshot, there should be a list of your existing index patterns under the **Create index pattern** button, but that area is blank in your case.

I would be interested in seeing why that is. Try opening Chrome dev tools, click to **Network** tab, then navigate Management \> Index Pattern. There should be a few requests made to URLs containing **saved\_objects**. Are there any errors associated with those requests? What are the responses?

---

<div class="post-metadata">

**Author:** ![Benjamin\_Carriou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_carriou/32/47347_2.png) [@Benjamin\_Carriou](https://discuss.elastic.co/u/Benjamin_Carriou)\
**Post date:** [June 5, 2019, 6:49am UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/3 "2019-06-05T06:49:45Z")

</div>

Hi @jen-huang and thx for your answer.

When I click on Star icon, nothing is happenning, it's seem be desactivate.

Concerning the requests having in the URL saved\_objects, I do not see any error.  
Here are the queries and their responses:

> **[kibana-debug-request-response.txt](https://drive.google.com/file/d/1LFBBjpeSeiHk31pHH3tQ0Wu-mcWUGlhO/view?usp=drive_open)**
>
> Google Drive file.

Here, my k8s ressources:

```
apiVersion: elasticsearch.k8s.elastic.co/v1alpha1
kind: Elasticsearch
metadata:
  name: cloud
spec:
  version: 7.1.0
  nodes:
  - nodeCount: 2
    config:
      node.master: true
      node.data: true
      node.ingest: true
    volumeClaimTemplates:
    - metadata:
        name: data
      spec:
        accessModes:
        - ReadWriteOnce
        resources:
          requests:
            storage: 100Gi
        storageClassName: cinder-high-speed # can be any available storage class
----
apiVersion: kibana.k8s.elastic.co/v1alpha1
kind: Kibana
metadata:
  name: cloud
spec:
  version: 7.1.0
  nodeCount: 1
  elasticsearchRef:
    name: cloud

```

Thx for your help

---

<div class="post-metadata">

**Author:** ![Benjamin\_Carriou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_carriou/32/47347_2.png) [@Benjamin\_Carriou](https://discuss.elastic.co/u/Benjamin_Carriou)\
**Post date:** [June 5, 2019, 6:52am UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/4 "2019-06-05T06:52:04Z")

</div>

My problem does not seem isolated:

> [@Created Index Pattern is not visible in KIbana 7.0.1](https://discuss.elastic.co/t/created-index-pattern-is-not-visible-in-kibana-7-0-1/184098):
>
> I have created one index pattern.but the created index pattern is not visible.

---

<div class="post-metadata">

**Author:** ![Benjamin\_Carriou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_carriou/32/47347_2.png) [@Benjamin\_Carriou](https://discuss.elastic.co/u/Benjamin_Carriou)\
**Post date:** [June 6, 2019, 6:55am UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/5 "2019-06-06T06:55:03Z")

</div>

Any ideas ?

---

<div class="post-metadata">

**Author:** ![alchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alchy/32/47743_2.png) [@alchy](https://discuss.elastic.co/u/alchy)\
**Post date:** [June 7, 2019, 4:26pm UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/6 "2019-06-07T16:26:48Z")

</div>

> [@Benjamin\_Carriou](#):
>
> When I click on Star icon, nothing is happenning, it's seem be desactivate.

I can confirm the same behavior.

---

<div class="post-metadata">

**Author:** ![alchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alchy/32/47743_2.png) [@alchy](https://discuss.elastic.co/u/alchy)\
**Post date:** [June 7, 2019, 4:47pm UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/7 "2019-06-07T16:47:13Z")

</div>

Console screenshot from Firefox I do use. The message says the script-src was blocked due to the security policy.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d27ec1f883badf41ad90653df57d221b1a33354a.png)

---

<div class="post-metadata">

**Author:** ![Benjamin\_Carriou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_carriou/32/47347_2.png) [@Benjamin\_Carriou](https://discuss.elastic.co/u/Benjamin_Carriou)\
**Post date:** [June 7, 2019, 4:48pm UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/8 "2019-06-07T16:48:57Z")

</div>

I have tried to disable security policy and the problem persist for me

---

<div class="post-metadata">

**Author:** ![alchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alchy/32/47743_2.png) [@alchy](https://discuss.elastic.co/u/alchy)\
**Post date:** [June 7, 2019, 5:21pm UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/9 "2019-06-07T17:21:16Z")

</div>

...slowly getting into this...

Is this the request for saved objects please?

[http://10.128.2.18:9997/api/saved\_objects/\_find?type=index-pattern&fields=title&fields=type&per\_page=10000](http://10.128.2.18:9997/api/saved_objects/_find?type=index-pattern&fields=title&fields=type&per_page=10000)

Should this be a response? I would say the empty array is the reason the page says "No default index pattern. You must select or create one to continue.".

{"page":1,"per\_page":10000,"total":0,"saved\_objects":}

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e5435de304aeba9983958ea6cf9302002eb38dc2.png)

How the request to save an "index pattern object" should look like (the POST URL), which data is expected in json (example pls.) and when it is expected to happen in GUI? It seems this the problem part as I would say the POST did not happen, probably.

Could eventually someone please send me a curl (still learnig ELK) with the packetbeat-\* kibana's "index pattern" so I could manually inject to test?

thanks

---

<div class="post-metadata">

**Author:** ![alchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alchy/32/47743_2.png) [@alchy](https://discuss.elastic.co/u/alchy)\
**Post date:** [June 11, 2019, 10:55am UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/10 "2019-06-11T10:55:19Z")

</div>

I've found possible fix:

Wojciech\_Kuligowski]([https://discuss.elastic.co/u/Wojciech\_Kuligowski](https://discuss.elastic.co/u/Wojciech_Kuligowski))

[12d](https://discuss.elastic.co/t/kibana-7-cant-load-index-pattern/180167/15)

I have finally found solution in another discussion - set kibana.index in kibana.yml to some new name, which causes creating new index for kibana. After restart index patterns work fine.

---

<div class="post-metadata">

**Author:** ![Benjamin\_Carriou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_carriou/32/47347_2.png) [@Benjamin\_Carriou](https://discuss.elastic.co/u/Benjamin_Carriou)\
**Post date:** [June 11, 2019, 2:43pm UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/11 "2019-06-11T14:43:39Z")

</div>

@alchy Thanks for your message.  
Did you use ECK ?  
If yes, how did you do that with CRD ressources ?

---

<div class="post-metadata">

**Author:** ![j-klemm](https://avatars.discourse-cdn.com/v4/letter/j/958977/32.png) [@j-klemm](https://discuss.elastic.co/u/j-klemm)\
**Post date:** [June 11, 2019, 3:21pm UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/12 "2019-06-11T15:21:53Z")

</div>

I am having the same issue using 3 instances of Elasticsearch 7.1.1 and 3 instances of Kibana 7.1.1 in a Docker Stack over 3 remote machines (EC2s).

I create the index pattern and check that it is saved as default in Advanced Settings.

Then I navigate to Dashboard and it says

> In order to visualize and explore data in Kibana, you'll need to create an index pattern to retrieve data from Elasticsearch

Then I check again in Advanced Settings and I've lost the Default Index that was saved.

---

<div class="post-metadata">

**Author:** ![alchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alchy/32/47743_2.png) [@alchy](https://discuss.elastic.co/u/alchy)\
**Post date:** [June 12, 2019, 7:12am UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/13 "2019-06-12T07:12:57Z")

</div>

> [@Benjamin\_Carriou](#):
>
> do that with CRD ressourc

can't help with this, but the fix proven to work on locally installed kibana  
maybe I put this as issue to kibana bugtracker as this is a bug

---

<div class="post-metadata">

**Author:** ![Benjamin\_Carriou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_carriou/32/47347_2.png) [@Benjamin\_Carriou](https://discuss.elastic.co/u/Benjamin_Carriou)\
**Post date:** [July 9, 2019, 6:18am UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/14 "2019-07-09T06:18:27Z")

</div>

For me, upgrade to 7.2.0 fix the problem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2019, 6:18am UTC](https://discuss.elastic.co/t/i-cant-create-indexes-patterns-with-eck/184194/15 "2019-08-06T06:18:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
