# I get error type "Could not locate thatindex-pattern-field" then Dashboard not loading

**URL:** <https://discuss.elastic.co/t/i-get-error-type-could-not-locate-thatindex-pattern-field-then-dashboard-not-loading/169143>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 20, 2019, 6:52am UTC](https://discuss.elastic.co/t/i-get-error-type-could-not-locate-thatindex-pattern-field-then-dashboard-not-loading/169143 "2019-02-20T06:52:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![khergner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khergner/32/130758_2.png) [@khergner](https://discuss.elastic.co/u/khergner)\
**Post date:** [February 20, 2019, 6:52am UTC](https://discuss.elastic.co/t/i-get-error-type-could-not-locate-thatindex-pattern-field-then-dashboard-not-loading/169143/1 "2019-02-20T06:52:43Z")

</div>

Hi everyone  
**I am using new**  
I want to use nginx module to filebeat, I made settings for logstash to nginx modules then filebeat start service. I installed plugin geoip & user-agent for elasticsearch. Nginx modules is active but dashboard no t loading and could not locate that index-pattern-filed(id:traefik.access.remote.ip) or get similar error. in the meantime Picture 2 filebeat is load 110 fields. **Why less space is loading?**  
I upload 3 pictures about my mistakes

 ![1](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e75d9af7a36c726ee4c18e1363ad58f9dc354cd6.png) ![2](https://us1.discourse-cdn.com/elastic/original/3X/7/7/77f7369bd07bf1b5a995476080c92b656640f081.png) ![3](https://us1.discourse-cdn.com/elastic/original/3X/0/b/0b3dadada9e73a49a213799734a05b77eb5eb879.png)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [February 20, 2019, 3:59pm UTC](https://discuss.elastic.co/t/i-get-error-type-could-not-locate-thatindex-pattern-field-then-dashboard-not-loading/169143/2 "2019-02-20T15:59:06Z")

</div>

Can you share your configs and logs (please use the `</>` button to format those)?

Have you checked filebeat/logstash logs?

When starting with filebeat modules better not use Logstash.

---

<div class="post-metadata">

**Author:** ![khergner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khergner/32/130758_2.png) [@khergner](https://discuss.elastic.co/u/khergner)\
**Post date:** [February 25, 2019, 6:56am UTC](https://discuss.elastic.co/t/i-get-error-type-could-not-locate-thatindex-pattern-field-then-dashboard-not-loading/169143/3 "2019-02-25T06:56:33Z")

</div>

Logstash using the reason with filebeat; I want to parsing Nginx log therefore I use logstash filter method . Below filter for Nginx

```
filter {
  if [fileset][module] == "nginx" {
    if [fileset][name] == "access" {
      grok {
        match => { "message" => ["%{IPORHOST:[nginx][access][remote_ip]} - %{DATA:[nginx][access][user_name]} \[%{HTTPDATE:[nginx][access][time]}\] \"%{WORD:[nginx][access][method]} %{DATA:[nginx][access][url]} HTTP/%{NUMBER:[nginx][access][http_version]}\" %{NUMBER:[nginx][access][response_code]} %{NUMBER:[nginx][access][body_sent][bytes]} \"%{DATA:[nginx][access][referrer]}\" \"%{DATA:[nginx][access][agent]}\""] }
        remove_field => "message"
      }
      mutate {
        add_field => { "read_timestamp" => "%{@timestamp}" }
      }
      date {
        match => ["[nginx][access][time]", "dd/MMM/YYYY:H:m:s Z" ]
        remove_field => "[nginx][access][time]"
      }
      useragent {
        source => "[nginx][access][agent]"
        target => "[nginx][access][user_agent]"
        remove_field => "[nginx][access][agent]"
      }
      geoip {
        source => "[nginx][access][remote_ip]"
        target => "[nginx][access][geoip]"
      }
    }
    else if [fileset][name] == "error" {
      grok {
        match => { "message" => ["%{DATA:[nginx][error][time]} \[%{DATA:[nginx][error][level]}\] %{NUMBER:[nginx][error][pid]}#%{NUMBER:[nginx][error][tid]}: (\*%{NUMBER:[nginx][error][connection_id]} )?%{GREEDYDATA:[nginx][error][message]}"] }
        remove_field => "message"
      }
      mutate {
        rename => { "@timestamp" => "read_timestamp" }
      }
      date {
        match => ["[nginx][error][time]", "YYYY/MM/dd H:m:s" ]
        remove_field => "[nginx][error][time]"
      }
    }
  }
}

```

**filebeat.yml**  
#================================ Outputs =====================================  
output.logstash:

# The Logstash hosts

hosts: ["172.28.14.238:5044"]

**nginx.yml**

- module: nginx
# Access logs
access:  
enabled:  
var.paths: ["C:\nginx\logs\access.log"]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2019, 6:56am UTC](https://discuss.elastic.co/t/i-get-error-type-could-not-locate-thatindex-pattern-field-then-dashboard-not-loading/169143/4 "2019-03-25T06:56:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
