# Index not visble in Kibana

**URL:** <https://discuss.elastic.co/t/index-not-visble-in-kibana/136989>\
**Category:** Kibana\
**Created:** [June 22, 2018, 8:34am UTC](https://discuss.elastic.co/t/index-not-visble-in-kibana/136989 "2018-06-22T08:34:15Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [June 22, 2018, 8:34am UTC](https://discuss.elastic.co/t/index-not-visble-in-kibana/136989/1 "2018-06-22T08:34:15Z")

</div>

Hi there,

I've noticed that mu Indexes aren't being added to Kibana anymore. I do have changed my Logstash conf files in the meantime. But still then I would only expect GROK parse failures and not my index to dissapear..  
This is the config:

input {  
udp {  
port =\> 5514  
type =\> syslog  
}

tcp {  
port =\> 5514  
type =\> syslog  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"] index =\> "logstash-syslog" }  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)\
**Post date:** [June 22, 2018, 1:33pm UTC](https://discuss.elastic.co/t/index-not-visble-in-kibana/136989/2 "2018-06-22T13:33:31Z")

</div>

Hi @heskez,

Can you verify the indices exist in Elasticsearch? Do you have appropriate index patterns setup within Kibana that match those Elasticsearch indices? If the data is in Elasticsearch, Kibana should be able to see it, but if the data is not in Elasticsearch, you might have issues on the Logstash side

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [June 22, 2018, 1:38pm UTC](https://discuss.elastic.co/t/index-not-visble-in-kibana/136989/3 "2018-06-22T13:38:22Z")

</div>

Hi @chrisronline how can I verify the indices exist in Elasticsearch?

---

<div class="post-metadata">

**Author:** ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)\
**Post date:** [June 22, 2018, 1:39pm UTC](https://discuss.elastic.co/t/index-not-visble-in-kibana/136989/4 "2018-06-22T13:39:07Z")

</div>

In Kibana, go to the Dev Tools page and run this query:

```auto
GET _cat/indices

```

You should see the indices there if they exist in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [June 22, 2018, 1:40pm UTC](https://discuss.elastic.co/t/index-not-visble-in-kibana/136989/5 "2018-06-22T13:40:56Z")

</div>

Great thx, I think they're not there:

green open .monitoring-es-6-2018.04.11 GWH5uCuOQjGjdSkf22ZoUw 1 0 1839 12 1mb 1mb  
yellow open syslog-2018.12.22 ULJz3m2jSxS7kFrcJPsQXQ 5 1 1 0 13.9kb 13.9kb  
yellow open logstash-2018.12.22 glSsUzStTrOcL3u8U0TxtA 5 1 1 0 12.2kb 12.2kb  
green open .watches n0HQZ2pKT4GTvfMHrOeo2g 1 0 6 0 32.9kb 32.9kb  
green open .monitoring-alerts-6 whBL9bysR7au2\_1bBSMtPQ 1 0 1 0 6.1kb 6.1kb  
yellow open logstash-2018.12.23 gJgTS6i5SSeYa8mlK7eO7g 5 1 3 0 36.3kb 36.3kb  
green open .security-6 ZXbp\_DODSouFZamobe3Wdg 1 0 3 0 9.8kb 9.8kb  
green open .kibana FtIuYpWUSV-pZ78VskTTnw 1 0 1 0 3.7kb 3.7kb  
yellow open syslog-2018.04.11 OyXhG8wjT9i3kPjGCU24Lw 5 1 5 0 25.4kb 25.4kb  
close .watcher-history-7-2018.04.11 01Z34Tk8SoCWrrQj\_oFlYA  
green open .triggered\_watches dm4mpxy\_Q4GTwLJPVjQ7ng 1 0 0 0 15.5kb 15.5kb  
yellow open syslog-2018.12.23 PtgRZgsQTC-z3BIBYPTPqg 5 1 3 0 28.8kb 28.8kb  
yellow open logstash-2018.04.11 yXMKHnulSHOimPlNwsgUXw 5 1 5 0 22.7kb 22.7kb

---

<div class="post-metadata">

**Author:** ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)\
**Post date:** [June 22, 2018, 1:41pm UTC](https://discuss.elastic.co/t/index-not-visble-in-kibana/136989/6 "2018-06-22T13:41:42Z")

</div>

Ah yea. It sounds like an issue elsewhere. Verify the data is coming into Logstash and then verify it's properly going to your Elasticsearch cluster.

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [June 22, 2018, 1:42pm UTC](https://discuss.elastic.co/t/index-not-visble-in-kibana/136989/7 "2018-06-22T13:42:10Z")

</div>

Yes how? 🙂

[TCPDUMP shows incoming data on correct port]  
[Logstash/Elasticsearch/Kibana instances are running]  
[output debug logs look also good]

---

<div class="post-metadata">

**Author:** ![chrisronline](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisronline/32/28230_2.png) [@chrisronline](https://discuss.elastic.co/u/chrisronline)\
**Post date:** [June 22, 2018, 4:16pm UTC](https://discuss.elastic.co/t/index-not-visble-in-kibana/136989/8 "2018-06-22T16:16:36Z")

</div>

Try posting in [https://discuss.elastic.co/c/logstash](https://discuss.elastic.co/c/logstash) as they'll be able to help more.

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [June 25, 2018, 9:37am UTC](https://discuss.elastic.co/t/index-not-visble-in-kibana/136989/9 "2018-06-25T09:37:37Z")

</div>

This one has been solved, it was a local firewall issue

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2018, 9:37am UTC](https://discuss.elastic.co/t/index-not-visble-in-kibana/136989/10 "2018-07-23T09:37:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
