# Kibana Discover - No results found :|

**URL:** <https://discuss.elastic.co/t/kibana-discover-no-results-found/33146>\
**Category:** Kibana\
**Created:** [October 28, 2015, 12:33pm UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146 "2015-10-28T12:33:27Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![jsps](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsps/32/5411_2.png) [@jsps](https://discuss.elastic.co/u/jsps)\
**Post date:** [October 28, 2015, 12:33pm UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/1 "2015-10-28T12:33:27Z")

</div>

Im doing something wrong but cant work it out, any help is appreciated.

I have a bunch of documents in elasticsearch, this is the search and result from Marvel:

```
GET /my_index/my_type/_search
{"query" :
{
    "bool" : {
        "must" : [
          {
            "term" : { "channel" : "request" }
        },
        {
          "term":{"level" : "200"}},
             {
          "term":{"userid" : 84}}
        ]
    }
}
}

### result

{
   "took": 10,
   "timed_out": false,
   "_shards": {
      "total": 5,
      "successful": 5,
      "failed": 0
   },
   "hits": {
      "total": 1,
      "max_score": 2.970658,
      "hits": [
         {
            "_index": "my_index",
            "_type": "my_type",
            "_id": "AVCuTdURjAmnSWnnkp4Z",
            "_score": 2.970658,
            "_source": {
               "id": "29155",
               "channel": "request",
               "level": "200",
               "source": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx)",
               "message": "yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy",
               "userid": "84",
               "time": "1405813801"
            }
         }
      ]
   }
}

```

The time field represents Sat, 19 Jul 2014 23:50:01 GMT

I've managed to find the index in Kibana settings, but I cannot get a single result from any search. I have set the time range to "last 5 years" and search as \* , I just get "No Results found 😑 "

I've also tried recreating my index with a new mapping where "store" is true in all fields. No difference.  
Can anyone suggest what I might be doing wrong?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 28, 2015, 11:57pm UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/2 "2015-10-28T23:57:26Z")

</div>

Did KB accept the time field in the index settings?

---

<div class="post-metadata">

**Author:** ![jsps](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsps/32/5411_2.png) [@jsps](https://discuss.elastic.co/u/jsps)\
**Post date:** [October 29, 2015, 4:39pm UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/3 "2015-10-29T16:39:13Z")

</div>

I've now tried several different ways and cannot get any data to show in kibana. Time-field name does not provide anything in the drop down at kibana-\>settings-\>"configure an index" .

In ES I have a sync.json in config/mappings/\_default ( i have also tried to add this mapping in a PUT but same end result )

```
{

```

"sync" :{  
"\_timestamp" : {  
"enabled" : true,  
"path" : "time",  
"ignore\_missing" : true,  
"store":true  
},  
"properties": {  
"channel": {  
"type": "string",  
"store" : true  
},  
"id": {  
"type": "integer"  
},  
"level": {  
"type": "integer",  
"store" : true  
},  
"message": {  
"type": "string"  
},  
"source": {  
"type": "string"  
},  
"time": {  
"type": "date"  
},  
"userid": {  
"type": "integer",  
"store" : true  
}  
}

}  
}

I create an index in sense.  
I load documents into index\_name/sync using the php api ( the "time" field values are unix timestamp \* 1000 for epoch\_millis )

The mapping do not appear to get used, when I then:

```
GET index_name/sync/_mapping

```

I get

```
{

```

"index\_name": {  
"mappings": {  
"sync": {  
"properties": {  
"channel": {  
"type": "string"  
},  
"id": {  
"type": "long"  
},  
"level": {  
"type": "long"  
},  
"message": {  
"type": "string"  
},  
"source": {  
"type": "string"  
},  
"time": {  
"type": "long"  
},  
"userid": {  
"type": "long"  
}  
}  
}  
}  
}  
}

In Kibana I can see the index but it does not recognize any date fields. So it looks like the mappings in \_default just doesn't get used, or I'm adding the data in the wrong way or adding the mapping in the wrong way. If I make a deliberate syntax error in the sync.json file I get an error when trying to create an index, so the file is being parsed.  
Also I can search my documents using sense or curl and I get the results I expect with the time field in milliseconds.

A bit stumped, any help appreciated

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 30, 2015, 4:45am UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/4 "2015-10-30T04:45:40Z")

</div>

> [@jsps](#):
>
> "time": { "type": "long"

That looks like why. Your mapping isn't being done correctly.

What does the date actually look like.

---

<div class="post-metadata">

**Author:** ![jsps](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsps/32/5411_2.png) [@jsps](https://discuss.elastic.co/u/jsps)\
**Post date:** [October 30, 2015, 9:13am UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/5 "2015-10-30T09:13:40Z")

</div>

> [@jsps](#):
>
> "time": "1405813801"

"time": "1405813801"

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 30, 2015, 10:40am UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/6 "2015-10-30T10:40:52Z")

</div>

Ok, so it's a epoch timestamp that just isn't being mapped correctly as I mentioned.

Can you gist/pastebin/etc your entire mapping file and link it here?

---

<div class="post-metadata">

**Author:** ![jsps](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsps/32/5411_2.png) [@jsps](https://discuss.elastic.co/u/jsps)\
**Post date:** [October 30, 2015, 11:07am UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/7 "2015-10-30T11:07:47Z")

</div>

Now resolved. Since upgrading to ES 2.0 ( which no longer supports mapping in config files ( thanks erikstephens) ) I now see docs in kibana. Thanks for your help.

---

<div class="post-metadata">

**Author:** ![GregMeadows](https://avatars.discourse-cdn.com/v4/letter/g/b5e925/32.png) [@GregMeadows](https://discuss.elastic.co/u/GregMeadows)\
**Post date:** [November 1, 2015, 2:47pm UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/8 "2015-11-01T14:47:06Z")

</div>

wait...how did ES 2.0 solve this issue? I am getting the same error after installing ELK (latest versions for each). Where do you now do your mappings?

---

<div class="post-metadata">

**Author:** ![jsps](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsps/32/5411_2.png) [@jsps](https://discuss.elastic.co/u/jsps)\
**Post date:** [November 2, 2015, 12:33pm UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/9 "2015-11-02T12:33:39Z")

</div>

Well it was solved because ES2.0 no longer supports mapping in config files so I created a new index, added the mapping via the PUT api and then added the documents ( you have to add the mapping before the documents ) . The mapping persisted and now Kibana can read the date fields and display the data.

---

<div class="post-metadata">

**Author:** ![r.ganeshbabu](https://avatars.discourse-cdn.com/v4/letter/r/4da419/32.png) [@r.ganeshbabu](https://discuss.elastic.co/u/r.ganeshbabu)\
**Post date:** [December 23, 2015, 12:30pm UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/10 "2015-12-23T12:30:18Z")

</div>

Hi All

I have the same problem in ES 1.7.3 with kibana 4.1.3. Discover tab is not displaying data and showing as "No results found". I configured index pattern as "test\_item" in settings indices tab and selected "CRT\_DTTM" in time field name dropdown. CRT\_DTTM has type "date". Please find below mappings of "test\_item.

{

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/ce0a93f629e0687468503ad89fb1251b90512083.PNG)

PUT test\_item/item/\_mapping  
{  
"item": {  
"\_all" : {"enabled" : false},  
"properties": {  
"ITEM\_ID": {  
"type": "long",  
"index": "not\_analyzed",  
"doc\_values": "true",  
"norms":{  
"enabled": false  
}  
},  
"CRT\_DTTM": {  
"type": "date",  
"format": "yyyy-MM-dd HH:mm:ss",  
"index": "not\_analyzed",  
"doc\_values": "true",  
"norms":{  
"enabled": false  
}  
},  
"UPD\_DTTM": {  
"type": "date",  
"format": "yyyy-MM-dd HH:mm:ss",  
"index": "not\_analyzed",  
"doc\_values": "true",  
"norms":{  
"enabled": false  
}  
},  
"ITEM\_TYPE": {  
"type": "string",  
"index": "not\_analyzed",  
"doc\_values": "true",  
"norms":{  
"enabled": false  
}  
},  
"SG\_CHR\_VAL\_ID": {  
"type": "long",  
"index": "not\_analyzed",  
"doc\_values": "true",  
"norms":{  
"enabled": false  
}  
},  
"PG\_CHR\_VAL\_ID": {  
"type": "long",  
"index": "not\_analyzed",  
"doc\_values": "true",  
"norms":{  
"enabled": false  
}  
},  
"XCD": {  
"type":"nested",  
"properties": {  
"XCD\_ID": {  
"type": "long",  
"index": "not\_analyzed",  
"doc\_values": "true",  
"norms":{  
"enabled": false  
}  
},  
"EXTRN\_CODE\_GRP\_ID": {  
"properties": {  
"ID": {  
"type": "long",  
"index": "not\_analyzed",  
"doc\_values": "true",  
"norms":{  
"enabled": false  
}  
}  
}  
},  
"HAS\_IMAGE\_IND": {  
"type": "string",  
"index": "not\_analyzed",  
"doc\_values": "true",  
"norms":{  
"enabled": false  
}  
}  
}  
}  
}  
}  
}

Please kindly in this and it would be very helpful.

Thanks,  
Ganeshbabu R

---

<div class="post-metadata">

**Author:** ![GregMeadows](https://avatars.discourse-cdn.com/v4/letter/g/b5e925/32.png) [@GregMeadows](https://discuss.elastic.co/u/GregMeadows)\
**Post date:** [February 11, 2016, 4:20pm UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/11 "2016-02-11T16:20:15Z")

</div>

upper right corner change the default time from "Today" to something longer

---

<div class="post-metadata">

**Author:** ![Inbeo\_Beo](https://avatars.discourse-cdn.com/v4/letter/i/d78d45/32.png) [@Inbeo\_Beo](https://discuss.elastic.co/u/Inbeo_Beo)\
**Post date:** [April 5, 2016, 3:54am UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/12 "2016-04-05T03:54:42Z")

</div>

Hi all

I have same trouble. I have configured to get log in iis ( example: logstash\_getlog\_iis.conf ). When i have used command line --configtest for test --\> result is ok

However, when using kibana to show this log, It's notice that no results found 😥

It's true that, i don't understand why and don't know where is my mistake in there? 😥

Could you help me?

Regds

p/s: i'm using kibana 4.1.2 on Centos 6.7

---

<div class="post-metadata">

**Author:** ![mangolzy](https://avatars.discourse-cdn.com/v4/letter/m/3ec8ea/32.png) [@mangolzy](https://discuss.elastic.co/u/mangolzy)\
**Post date:** [November 24, 2016, 7:14am UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/13 "2016-11-24T07:14:46Z")

</div>

Hi, all.. I've come across almost the same problem.  
Elasticsearch 2.3.5  
Kibana 4.5.3  
on the same ubuntu machine  
I could use curl to confirm that data are inserted into the index,  
and also in kibana, it can automatically match the index name when I create in visualize.

So I imply from this post that it may be probably caused by the time format.

But, since for the index, I've give it a mapping, and when I check it, for the time field, it shows  
"time":{  
"type" :"date",  
"format": "strict\_date\_optional\_time || epoch\_millis"  
}  
and when i do a search, a record instance contains:  
"time":1356998940000

and in kibana, I did a search from 2013-01-01 to 2013-01-06.

Could anybody tell me how to config it right, to make this search work to return result??

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![mangolzy](https://avatars.discourse-cdn.com/v4/letter/m/3ec8ea/32.png) [@mangolzy](https://discuss.elastic.co/u/mangolzy)\
**Post date:** [November 24, 2016, 7:23am UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/14 "2016-11-24T07:23:16Z")

</div>

how can I check whether KB accept it or not ? thx~!!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 24, 2016, 8:48am UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/15 "2016-11-24T08:48:05Z")

</div>

Please start a new thread, this one is really old and may not be relevant to your issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:34pm UTC](https://discuss.elastic.co/t/kibana-discover-no-results-found/33146/16 "2017-07-06T13:34:01Z")

</div>


