# Kibana cannot create index pattern

**URL:** <https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001>\
**Category:** Kibana\
**Created:** [December 11, 2017, 4:39am UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001 "2017-12-11T04:39:59Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Terry](https://avatars.discourse-cdn.com/v4/letter/t/b9e5f3/32.png) [@Terry](https://discuss.elastic.co/u/Terry)\
**Post date:** [December 11, 2017, 4:39am UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001/1 "2017-12-11T04:39:59Z")

</div>

After deleting all indexes using curl -XDELETE [http://localhost:9200/\_all](http://localhost:9200/_all)  
I tried to create index pattern again but when I clicked the create button, it didn't response and no index was created. How to fix this problem?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 11, 2017, 4:41am UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001/2 "2017-12-11T04:41:40Z")

</div>

Index patterns do not create indices, you need to do that in Elasticsearch before Kibana can read them.

---

<div class="post-metadata">

**Author:** ![Terry](https://avatars.discourse-cdn.com/v4/letter/t/b9e5f3/32.png) [@Terry](https://discuss.elastic.co/u/Terry)\
**Post date:** [December 11, 2017, 7:00am UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001/3 "2017-12-11T07:00:41Z")

</div>

![indexpattern](https://us1.discourse-cdn.com/elastic/original/3X/5/0/50622c3d936da4f09bc529a9ff298d5b41bc94e0.PNG)

I found that there are still indices in elasticsearch. Are these indices constantly generated by elasticsearch from the logs sent from the beat agents?

However, when I clicked the create button, it stay the same with no index pattern created.

Also I found that there are many .hprof files taking a lot of disk space.  
C:\Program Files\Elasticsearch\bin\java\_pidXXXX.hprof  
What are the files for? Can I delete them?

Where are the indices stored?  
If I turn on all the beat agents on the logging machines to send logs to the ELK server, the log received will grow continuously. What the house keeping work to do?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 11, 2017, 7:16am UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001/4 "2017-12-11T07:16:18Z")

</div>

> [@Terry](#):
>
> Are these indices constantly generated by elasticsearch from the logs sent from the beat agents?

Yes.

> [@Terry](#):
>
> However, when I clicked the create button, it stay the same with no index pattern created.

Check with `_cat/indices` please 🙂

> [@Terry](#):
>
> Also I found that there are many .hprof files taking a lot of disk space.
> 
> C:\Program Files\Elasticsearch\bin\java\_pidXXXX.hprof
> 
> What are the files for? Can I delete them?

They are JVM heap dumps, which are not good. You may want to check your logs.

> [@Terry](#):
>
> Where are the indices stored?

On the local disk.

Check out [Elasticsearch Curator](https://www.elastic.co/guide/en/elasticsearch/client/curator/current/index.html).

---

<div class="post-metadata">

**Author:** ![Terry](https://avatars.discourse-cdn.com/v4/letter/t/b9e5f3/32.png) [@Terry](https://discuss.elastic.co/u/Terry)\
**Post date:** [December 11, 2017, 7:45am UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001/5 "2017-12-11T07:45:47Z")

</div>

![indexerror](https://us1.discourse-cdn.com/elastic/original/3X/0/6/068f69091ba476ff3d63165237fa18f69991d1fd.PNG)

Can you see any thing wrong?

I can't find the index files? Are they .json files inside the logstash or elasticsearch folder? What is the exact path?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 11, 2017, 8:12am UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001/6 "2017-12-11T08:12:43Z")

</div>

I'm a little lost, what problem are you trying to solve here?

---

<div class="post-metadata">

**Author:** ![Terry](https://avatars.discourse-cdn.com/v4/letter/t/b9e5f3/32.png) [@Terry](https://discuss.elastic.co/u/Terry)\
**Post date:** [December 13, 2017, 2:35am UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001/7 "2017-12-13T02:35:33Z")

</div>

I tried to add index pattern by command with the following errors. How to fix it?

C:\Script\>curl -XPUT [http://127.0.0.1:9200/.kibana/index-pattern/filebeat-\*](http://127.0.0.1:9200/.kibana/index-pattern/filebeat-*) -d '  
{"title" : "filebeat-_", "timeFieldName": "@timestamp"}'  
{"error":"Content-Type header [application/x-www-form-urlencoded] is not support  
ed","status":406}curl: (7) Failed to connect to port 80: Connection refused  
curl: (6) Could not resolve host: filebeat-_,  
curl: (6) Could not resolve host: timeFieldName  
curl: (3) [globbing] unmatched close brace/bracket in column 11

---

<div class="post-metadata">

**Author:** ![Terry](https://avatars.discourse-cdn.com/v4/letter/t/b9e5f3/32.png) [@Terry](https://discuss.elastic.co/u/Terry)\
**Post date:** [December 13, 2017, 4:15am UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001/8 "2017-12-13T04:15:39Z")

</div>

I would like to know what is serving the web page? Why port 80 cannot be connected in this case?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 13, 2017, 9:41pm UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001/9 "2017-12-13T21:41:35Z")

</div>

It's probably easier if you do it via the Kibana UI.

---

<div class="post-metadata">

**Author:** ![Terry](https://avatars.discourse-cdn.com/v4/letter/t/b9e5f3/32.png) [@Terry](https://discuss.elastic.co/u/Terry)\
**Post date:** [December 14, 2017, 2:25am UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001/10 "2017-12-14T02:25:15Z")

</div>

But Kibana UI does not response. What wrong with it?

---

<div class="post-metadata">

**Author:** ![Terry](https://avatars.discourse-cdn.com/v4/letter/t/b9e5f3/32.png) [@Terry](https://discuss.elastic.co/u/Terry)\
**Post date:** [December 18, 2017, 4:36am UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001/11 "2017-12-18T04:36:47Z")

</div>

> <https://github.com/elastic/kibana/issues/15110>

I am not sure how to do the following. Can provide a more detailed guide of how to execute the command?

1.Create a .kibana-6.1 index based on your existing mappings, but make sure type looks like:  
"type": {  
"type": "keyword"  
},

2.Reindex from .kibana-6 into .kibana-6.1:  
POST \_reindex  
{  
"source": {  
"index": ".kibana-6"  
},  
"dest": {  
"index": ".kibana-6.1"  
}  
}

3.Realias  
POST /\_aliases  
{  
"actions" : [  
{ "add": { "index": ".kibana-6.1", "alias": ".kibana" } },  
]  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2018, 4:36am UTC](https://discuss.elastic.co/t/kibana-cannot-create-index-pattern/111001/12 "2018-01-15T04:36:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
