# Index pattern search returns empty results

**URL:** <https://discuss.elastic.co/t/index-pattern-search-returns-empty-results/233407>\
**Category:** Kibana\
**Created:** [May 19, 2020, 8:43pm UTC](https://discuss.elastic.co/t/index-pattern-search-returns-empty-results/233407 "2020-05-19T20:43:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gustavosoares](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavosoares/32/68598_2.png) [@gustavosoares](https://discuss.elastic.co/u/gustavosoares)\
**Post date:** [May 19, 2020, 8:43pm UTC](https://discuss.elastic.co/t/index-pattern-search-returns-empty-results/233407/1 "2020-05-19T20:43:43Z")

</div>

Hi All,

I'm using kibana 7.5.0.

I've recently created a new time based index pattern and the discover view is not returning any results. However, when I search directly on the index using the console, it does return results. I'm not using x-pack security. I'm a bit lost of what might be causing this...

# checking index exists (logmux-2020.05.19.20)

 ![Screen Shot 2020-05-19 at 4.25.06 PM](https://us1.discourse-cdn.com/elastic/original/3X/4/5/4581b124a584ea55bab27d25558d933e43edb4a7.png)

# searching directly in the index

 ![Screen Shot 2020-05-20 at 8.38.13 AM](https://us1.discourse-cdn.com/elastic/original/3X/f/8/f88f052e9de35e9d7eccc343a1744f1a064c0a5c.png)

Here is the request that hits Kibana

```auto
  kibana_1 | {"type":"response","@timestamp":"2020-05-19T20:40:26Z","tags":[],"pid":6,"method":"post","statusCode":200,"req":{"url":"/elasticsearch/logmux-*/_search?rest_total_hits_as_int=true&ignore_unavailable=true&ignore_throttled=true&preference=1589919114934&timeout=30000ms","method":"post","headers":{"host":"127.0.0.1:5601","connection":"keep-alive","content-length":"844","accept":"application/json, text/plain, */*","kbn-version":"7.5.0","user-agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36","content-type":"application/json","origin":"http://127.0.0.1:5601","sec-fetch-site":"same-origin","sec-fetch-mode":"cors","sec-fetch-dest":"empty","referer":"http://127.0.0.1:5601/app/kibana","accept-encoding":"gzip, deflate, br","accept-language":"en-US,en;q=0.9"},"remoteAddress":"172.19.0.1","userAgent":"172.19.0.1","referer":"http://127.0.0.1:5601/app/kibana"},"res":{"statusCode":200,"responseTime":69,"contentLength":9},"message":"POST /elasticsearch/logmux-*/_search?rest_total_hits_as_int=true&ignore_unavailable=true&ignore_throttled=true&preference=1589919114934&timeout=30000ms 200 69ms - 9.0B"}

```

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [May 19, 2020, 9:11pm UTC](https://discuss.elastic.co/t/index-pattern-search-returns-empty-results/233407/2 "2020-05-19T21:11:32Z")

</div>

The primary difference is that in Discover it's filtering the results based on the time filter.

You also want to be sure that you have the correct field selected. On the index pattern, what field did you select as the "Time Filter field name"? On the index pattern view, this should have a clock next to it on the field list. Based on the screenshot you probably want the `time` field.

Then, just verify there are indeed documents that match that field for the time span selected on Discover. I would expect that document to show up if you selected last 24 hours.

---

<div class="post-metadata">

**Author:** ![gustavosoares](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavosoares/32/68598_2.png) [@gustavosoares](https://discuss.elastic.co/u/gustavosoares)\
**Post date:** [May 20, 2020, 1:15am UTC](https://discuss.elastic.co/t/index-pattern-search-returns-empty-results/233407/3 "2020-05-20T01:15:06Z")

</div>

> [@tylersmalley](#):
>
> ify there are indeed documents that match that field for the time span selected on Discover. I would expect that document to show up if you selected last 24 hours.

thanks. there are documents, however I just discovered that the timestamp field was not in the right format.

cheers

---

<div class="post-metadata">

**Author:** ![gustavosoares](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavosoares/32/68598_2.png) [@gustavosoares](https://discuss.elastic.co/u/gustavosoares)\
**Post date:** [May 25, 2020, 11:13pm UTC](https://discuss.elastic.co/t/index-pattern-search-returns-empty-results/233407/4 "2020-05-25T23:13:49Z")

</div>

@tylersmalley sorry, I'm reopening this post as I thought I had solved, but I didn't. ☹

Turns out I have two different log sources writing to the @timestamp field (the one with the clock). One logsource writes data in the format `2020-05-19T20:40:26Z` whereas the other logsource uses something like `1589857569.340`.

You're right, if I use the time field instead of timestamp I can search data from the second logsource.. but the first logsource stops working. ☹

Can't I have the @timestamp field with two different formats and Kibana does the conversion behind the scenes?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2020, 11:13pm UTC](https://discuss.elastic.co/t/index-pattern-search-returns-empty-results/233407/5 "2020-06-22T23:13:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
