# Index not taken - Timelion

**URL:** <https://discuss.elastic.co/t/index-not-taken-timelion/80849>\
**Category:** Kibana\
**Tags:** timelion\
**Created:** [March 31, 2017, 4:50pm UTC](https://discuss.elastic.co/t/index-not-taken-timelion/80849 "2017-03-31T16:50:48Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![pavithrakc](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pavithrakc](https://discuss.elastic.co/u/pavithrakc)\
**Post date:** [March 31, 2017, 4:50pm UTC](https://discuss.elastic.co/t/index-not-taken-timelion/80849/1 "2017-03-31T16:50:48Z")

</div>

Hello All,

I have ingested some data inside elastic search and trying to visualize using Kibana Timelion.

.es(index="fx\_twofour\_outbound",q='\*')

But it is not reflecting any output in my graph.

I crossed verified my index name in Elastic search by querying like this:

GET /fx\_twofour\_outbound/\_search

All my data are available inside elastic search.

Other visualization tools are working fine. But I am facing issue with no output in timelion.

Let me know what could be the issue here.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [March 31, 2017, 7:12pm UTC](https://discuss.elastic.co/t/index-not-taken-timelion/80849/2 "2017-03-31T19:12:30Z")

</div>

A common reason for data not showing up in timelion is because of the name of your timefield. By default timelion uses @timestamp, but you can change that by specifing the `timefield` argument.

[timelion functions doc](https://github.com/elastic/timelion/blob/master/FUNCTIONS.md#es)

---

<div class="post-metadata">

**Author:** ![pavithrakc](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pavithrakc](https://discuss.elastic.co/u/pavithrakc)\
**Post date:** [April 3, 2017, 5:18pm UTC](https://discuss.elastic.co/t/index-not-taken-timelion/80849/3 "2017-04-03T17:18:43Z")

</div>

If that is the case, I tried giving like this:

.es(index="fx\_twofour\_outbound,timefield ="TransactTime\_Tag\_60")

It shows a syntax error.

Can't we specify both the index and timefield together?

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [April 10, 2017, 8:13pm UTC](https://discuss.elastic.co/t/index-not-taken-timelion/80849/4 "2017-04-10T20:13:06Z")

</div>

```auto
.es(index="fx_twofour_outbound", timefield="TransactTime_Tag_60")

```

---

<div class="post-metadata">

**Author:** ![pavithrakc](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pavithrakc](https://discuss.elastic.co/u/pavithrakc)\
**Post date:** [April 12, 2017, 3:14pm UTC](https://discuss.elastic.co/t/index-not-taken-timelion/80849/5 "2017-04-12T15:14:17Z")

</div>

A space after ',' is the reason for failing so far?

Strange behaviour.

I actually changed the fields and retrieved data like this

.es(timefield="TransactTime\_Tag\_60",index="fx\_twofour\_outbound")

It worked.

Just cross verified. Both the query results in same output.

Thanks a lot.

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [April 12, 2017, 3:30pm UTC](https://discuss.elastic.co/t/index-not-taken-timelion/80849/6 "2017-04-12T15:30:26Z")

</div>

> [@pavithrakc](#):
>
> .es(index="fx\_twofour\_outbound,timefield ="TransactTime\_Tag\_60")

If you look closely at the code you posted, you weren't properly enclosing your index name within double quotes. So the parser thought your index name was '`fx_twofour_outbound,timefield =`' and then didn't know what to do with '`TransactTime_Tag_60"`'. 😉

---

<div class="post-metadata">

**Author:** ![pavithrakc](https://avatars.discourse-cdn.com/v4/letter/p/a6a055/32.png) [@pavithrakc](https://discuss.elastic.co/u/pavithrakc)\
**Post date:** [April 12, 2017, 5:02pm UTC](https://discuss.elastic.co/t/index-not-taken-timelion/80849/7 "2017-04-12T17:02:57Z")

</div>

That's really bad.

Unexpected and not noticed at all till you mentioned it now.

Bad code and silly mistake.

Thanks for pointing it out.

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [April 12, 2017, 6:54pm UTC](https://discuss.elastic.co/t/index-not-taken-timelion/80849/8 "2017-04-12T18:54:23Z")

</div>

Happy to help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2017, 7:08pm UTC](https://discuss.elastic.co/t/index-not-taken-timelion/80849/9 "2017-05-10T19:08:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
