I know this feels like beating a dead horse a little bit (I've searched this topic a lot in the forums but have yet to find an answer)....but this has really got me stumped.
I had ElasticSearch and Kibana running with WinlogBeat and Heartbeat sending data to Elasticsearch for about 2 days. I had the index Pattern setup and the Heartbeat dashboard working.
I then install x-pack and they no longer show data.
I decided to delete both the winLogbeat-* and the heartbeat-* indexes from Kibana hoping to recreate them and now Kibana (under Management, Index Patterns) says "Couldn't find any Elasticsearch data".
I then uninstalled x-pack and I could recreate the indexes just fine. I feel like I'm missing a critical piece of the x-pack install/config.
We should start by looking in the ES cluster to see if the indices are truly gone or if it's just Kibana that can't find them.
Can you post the answer of a _cat/indices to your ES cluster? I would say try it first from the Kibana Console (from Dev Tools) and if that shows nothing, try it from cURL as well.
OK, so here is what I have done. I removed x-pack and got the system back to what I had before. I have heartbeat running monitoring a couple things (1-icmp and 1-http) and I have one server running winlogbeat.
Here is a screen shot from the ES showing the current indexes:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.