# I have ran filebeat but not showing up anything on kibana

**URL:** https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046
**Category:** Beats
**Tags:** filebeat
**Created:** [April 21, 2016, 1:08pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046 "2016-04-21T13:08:59Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![GSL10019](https://avatars.discourse-cdn.com/v4/letter/g/ecb155/32.png) [@GSL10019](https://discuss.elastic.co/u/GSL10019)
#### Post date: [April 21, 2016, 1:08pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/1 "2016-04-21T13:08:59Z")

</div>

Hi, I just ran filebeat with the typical commands of filebeat start within the directory of filebeat.

But when i open Kibana with my configured yml, i dont see anything too it but I see my previous defaulted filebeat outputs within kibana which makes not a ton of sense.

I am running 1.1.1 filebeat

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [April 21, 2016, 4:05pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/2 "2016-04-21T16:05:32Z")

</div>

Can you share some more details. What is your config file? Which LS, ES, Kibana version are you using? Did you check the log files from filebeat?

---

<div class="post-metadata">

### Author: ![GSL10019](https://avatars.discourse-cdn.com/v4/letter/g/ecb155/32.png) [@GSL10019](https://discuss.elastic.co/u/GSL10019)
#### Post date: [April 21, 2016, 4:23pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/3 "2016-04-21T16:23:31Z")

</div>

LS 2.2.2  
ES 2.2.0  
Kibana 4.4.1

and my configuration document had a very simple setup so far

```auto
filebeat: 
 prospectors: 
-
paths:
- "/var/log/*.log"
- C:\Users\qa1\Desktop\*.logs

input_type:logs 
document_type:logs

paths: 
-C:\Users\qa1\Desktop\logs

registry_files: "C:/ProgramData/filebeat/registry"

output:

logstash: 
hosts:["localhost:5044"]

shipper:

logging:
files:
rotateeverybytes:10485760

```

---

<div class="post-metadata">

### Author: ![GSL10019](https://avatars.discourse-cdn.com/v4/letter/g/ecb155/32.png) [@GSL10019](https://discuss.elastic.co/u/GSL10019)
#### Post date: [April 21, 2016, 6:06pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/4 "2016-04-21T18:06:14Z")

</div>

Also Ruflin, quick question. is there a shell cmd that is available that I could explicitly just write out and force any of the stack or beat to read?

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [April 25, 2016, 7:37am UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/5 "2016-04-25T07:37:59Z")

</div>

I tried to format your config, but it seems like no indentation exists?

Not sure what you mean by your last question. You mean just print out the output for debugging? Then you can use `-e -d "*"` flags and all output is printed to stdout.

---

<div class="post-metadata">

### Author: ![GSL10019](https://avatars.discourse-cdn.com/v4/letter/g/ecb155/32.png) [@GSL10019](https://discuss.elastic.co/u/GSL10019)
#### Post date: [April 25, 2016, 12:18pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/6 "2016-04-25T12:18:15Z")

</div>

Ahh okay, ill use that command more frequently as I did not know it existed.

And Yeah I will update you within a couple of hours as I will just redownload the .yml confg from git and c&p the stuff over and try to maintain the consistent indentation and see if that was the main culprit of my problems. And much thanks =]

---

<div class="post-metadata">

### Author: ![GSL10019](https://avatars.discourse-cdn.com/v4/letter/g/ecb155/32.png) [@GSL10019](https://discuss.elastic.co/u/GSL10019)
#### Post date: [April 25, 2016, 5:13pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/7 "2016-04-25T17:13:05Z")

</div>

Hmm I just reused the default configuration document and it seems to be stuck after the start command. I also ran the -e - d "8" command and got these results

 ![](https://us1.discourse-cdn.com/elastic/original/2X/7/7bbc977f294fcc3ad5243946ffd1673807bc19dd.png)

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [April 26, 2016, 6:59am UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/8 "2016-04-26T06:59:56Z")

</div>

Based on the above output it looks like your log file does not get any updates in the 2m you posted the output. Were there any updates to logs in this time?

Please don't use screenshots but paste the code itself which is much easier to read.

---

<div class="post-metadata">

### Author: ![GSL10019](https://avatars.discourse-cdn.com/v4/letter/g/ecb155/32.png) [@GSL10019](https://discuss.elastic.co/u/GSL10019)
#### Post date: [April 26, 2016, 12:45pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/9 "2016-04-26T12:45:35Z")

</div>

Oh okay and sorry about the pasted img.

But in terms of updated logs, there wasn't any updates but I may have to reset the path as it looks like it may have looked into a place that may not have had the files it should have been looking for. I will run it and see what occurs, when I change the path to another directory.

---

<div class="post-metadata">

### Author: ![GSL10019](https://avatars.discourse-cdn.com/v4/letter/g/ecb155/32.png) [@GSL10019](https://discuss.elastic.co/u/GSL10019)
#### Post date: [April 26, 2016, 6:39pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/10 "2016-04-26T18:39:18Z")

</div>

Hi, I just adjusted the pathing for the logs and it does seem like I may have to change the duration in which it starts to ignore the log. Where within the yml can I do this? and it seems like it was defaulted to 24hrs as the result does say

INFO set ignore-older duration to 24h0m0s and my file is currently at 526h11m17s

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [April 27, 2016, 6:26am UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/11 "2016-04-27T06:26:44Z")

</div>

ignore\_older can be configured here: [https://www.elastic.co/guide/en/beats/filebeat/1.2/configuration-filebeat-options.html#ignore-older](https://www.elastic.co/guide/en/beats/filebeat/1.2/configuration-filebeat-options.html#ignore-older)

Be aware that the behaviour changed between 1.1 and 1.2. Per default in 1.2, ignore\_older is set to infinity, also to prevent similar cases you have above. I strong recommend you to update to filebeat 1.2.2.

The ignore\_older would also explain why the files were not shipped to elasticsearch.

---

<div class="post-metadata">

### Author: ![GSL10019](https://avatars.discourse-cdn.com/v4/letter/g/ecb155/32.png) [@GSL10019](https://discuss.elastic.co/u/GSL10019)
#### Post date: [April 27, 2016, 12:58pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/12 "2016-04-27T12:58:09Z")

</div>

Oh okay, and thank you for that link and I think I got my beat to work as it read the logs =].

So in order to get the messages to get indexed, I would then have to change the json format? And upgrading to 1.2.2 would it change anything else? and is it compatible with my ELK stack?

And much thanks =]

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [April 28, 2016, 12:57pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/13 "2016-04-28T12:57:52Z")

</div>

If 1.1 worked with your ELK stack, 1.2 should be compatible to.

What do you mean by changing JSON format?

---

<div class="post-metadata">

### Author: ![GSL10019](https://avatars.discourse-cdn.com/v4/letter/g/ecb155/32.png) [@GSL10019](https://discuss.elastic.co/u/GSL10019)
#### Post date: [April 28, 2016, 1:19pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/14 "2016-04-28T13:19:55Z")

</div>

the filebeat.template.json as my current filebeat is currently storing everything within properties -\> message so what I will attempt currently would be to add more fields in message such as program version. And I was wondering if that would be the current path to take.

i.e: "message":{  
"programversion": {  
"version": 1.234,  
"program" : "string"  
} ,  
etc  
}

---

<div class="post-metadata">

### Author: ![GSL10019](https://avatars.discourse-cdn.com/v4/letter/g/ecb155/32.png) [@GSL10019](https://discuss.elastic.co/u/GSL10019)
#### Post date: [May 2, 2016, 5:30pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/15 "2016-05-02T17:30:03Z")

</div>

Hey ruflin, I was also wondering, as I did change some of the message inputs. But does filebeat basically parse the entire text document depending on what I put into quotations on the left side of the argument?  
Such as---\> "3DENGINE": "string"

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [May 3, 2016, 2:50pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/16 "2016-05-03T14:50:55Z")

</div>

Filebeat does not process the log messages. It just takes line by line and forwards it to Logstash or Elasticsearch. If you need log line processing and extraction, that is what Logstash is for.

The filebeat template has no affect on what filebeat itself does. It is for elasticsearch to know the types of the fields.

---

<div class="post-metadata">

### Author: ![GSL10019](https://avatars.discourse-cdn.com/v4/letter/g/ecb155/32.png) [@GSL10019](https://discuss.elastic.co/u/GSL10019)
#### Post date: [May 9, 2016, 6:59pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/17 "2016-05-09T18:59:41Z")

</div>

Oh okay, and sorry for the delayed reply.

And I did get everything to work and show up on kibana and much thanks for your help ruflin =].

But a minor question would be, my work around was to play around with the includes and I was wondering if I can include \* within the includes

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [May 10, 2016, 9:50am UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/18 "2016-05-10T09:50:16Z")

</div>

What exactly are you referring to with `include`? Which config option? paths?

---

<div class="post-metadata">

### Author: ![GSL10019](https://avatars.discourse-cdn.com/v4/letter/g/ecb155/32.png) [@GSL10019](https://discuss.elastic.co/u/GSL10019)
#### Post date: [May 10, 2016, 1:00pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/19 "2016-05-10T13:00:19Z")

</div>

the particular include is within filebeat.yml and it was for the  
include\_lines: ["^ERR", "^WARN"]  
And the paths where the same as the one stated earlier which was just the typical -C:\pwd\*.log

And for my question I could have phrased it better, I would wondering within the include\_lines: is there a option that I could do something that would automatically read past all the basic information of dates and times like these  
Fri Dec 04 10:51:24 EST 2015:  
Mon Dec 07 12:16:37 EST 2015:  
May 01 17:15:16 EDT 2016:

And the include\_lines would read the three dates and look for a word such as ERROR right afterwards like this and punch it out into kibana or logstash

May 01 17:15:16 EDT 2016: ERROR

And thank you for your support

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 9:52pm UTC](https://discuss.elastic.co/t/i-have-ran-filebeat-but-not-showing-up-anything-on-kibana/48046/20 "2017-07-05T21:52:09Z")

</div>


