# Kibana doesn't show logs

**URL:** <https://discuss.elastic.co/t/kibana-doesnt-show-logs/70935>\
**Category:** Kibana\
**Created:** [January 9, 2017, 10:32am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-logs/70935 "2017-01-09T10:32:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![wrkilu](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wrkilu](https://discuss.elastic.co/u/wrkilu)\
**Post date:** [January 9, 2017, 10:32am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-logs/70935/1 "2017-01-09T10:32:41Z")

</div>

Hi,  
I think this is some problem with timestamp of logs but I don't know how to solve this. Generally when I create index without 'contains time-based events ' (this checkbox during creating), then I see logs but of course without ability to choose according to date. In the other hand when I create index with this option (like on screenshot

 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/4df11369386ded912eeedd89107c434e68534a63.png)) Kibana says 'no results found :(' . Application responsible for logs delivering is Filebeat.

The result of  
curl -XGET '[http://localhost:9200/filebeat-\*/\_search?pretty](http://localhost:9200/filebeat-*/_search?pretty)' is :

> }, {  
> "\_index" : "filebeat-2017.01.05",  
> "\_type" : "syslog",  
> "\_id" : "AVlu0pLnQQBiZCJUK7eL",  
> "\_score" : 1.0,  
> "\_source" : {  
> "message" : "10.172.81.39 - - [05/Jan/2017:04:51:10 +0100] "GET /.lvs.php HTTP/1.1" 200 8 "-" "check\_http/v1.4.16 (nagios-plugins 1.4.16)"",  
> "@version" : "1",  
> "@timestamp" : "2017-01-05T13:30:07.131Z",  
> "count" : 1,  
> "fields" : null,  
> "beat" : {  
> "hostname" : "f1.smaker.rc.htp.iadm",  
> "name" : "f1.smaker.rc.htp.iadm"  
> },  
> "source" : "/var/log/httpd/smaker.pl.rc.htp-custom\_log",  
> "type" : "syslog",  
> "input\_type" : "log",  
> "offset" : 21294,  
> "host" : "f1.smaker.rc.htp.iadm",  
> "tags" : ["beats\_input\_codec\_plain\_applied"]  
> }  
> }, {  
> "\_index" : "filebeat-2017.01.05",  
> "\_type" : "syslog",  
> "\_id" : "AVlu0pLnQQBiZCJUK7eQ",  
> "\_score" : 1.0,  
> "\_source" : {  
> "message" : "10.172.81.39 - - [05/Jan/2017:04:56:10 +0100] "GET /.lvs.php HTTP/1.1" 200 8 "-" "check\_http/v1.4.16 (nagios-plugins 1.4.16)"",  
> "@version" : "1",  
> "@timestamp" : "2017-01-05T13:30:07.131Z",  
> "type" : "syslog",  
> "input\_type" : "log",  
> "fields" : null,  
> "beat" : {  
> "hostname" : "f1.smaker.rc.htp.iadm",  
> "name" : "f1.smaker.rc.htp.iadm"  
> },  
> "source" : "/var/log/httpd/smaker.pl.rc.htp-custom\_log",  
> "offset" : 21924,  
> "count" : 1,  
> "host" : "f1.smaker.rc.htp.iadm",  
> "tags" : ["beats\_input\_codec\_plain\_applied"]  
> }  
> } ]

What is going on ? Please help.

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [January 9, 2017, 3:32pm UTC](https://discuss.elastic.co/t/kibana-doesnt-show-logs/70935/2 "2017-01-09T15:32:20Z")

</div>

If you increase the time range of the timepicker in the top right corner are you able to see any results?

---

<div class="post-metadata">

**Author:** ![wrkilu](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wrkilu](https://discuss.elastic.co/u/wrkilu)\
**Post date:** [January 9, 2017, 5:22pm UTC](https://discuss.elastic.co/t/kibana-doesnt-show-logs/70935/3 "2017-01-09T17:22:46Z")

</div>

I did that but nothing. Still no results.

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [January 9, 2017, 7:38pm UTC](https://discuss.elastic.co/t/kibana-doesnt-show-logs/70935/4 "2017-01-09T19:38:13Z")

</div>

Can you share your mappings for the @timestamp field? In the UI, if you select "Use event times to create index names" do things work?

---

<div class="post-metadata">

**Author:** ![wrkilu](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wrkilu](https://discuss.elastic.co/u/wrkilu)\
**Post date:** [January 10, 2017, 11:50am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-logs/70935/5 "2017-01-10T11:50:45Z")

</div>

> [@jbudz](#):
>
> Can you share your mappings for the @timestamp field?

Hmm.. where its defined ? In Kibana I didn't change anything related with timestamp.

My output in Logstash looks like this:

> output {  
> elasticsearch {  
> hosts =\> ["10.209.3.134:9200"]  
> sniffing =\> true  
> manage\_template =\> false  
> index =\> "%{[@metadata][beat]}-%{+yyyy-MM-dd HH:mm:ss:SSSZ}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }

However I see in logstash.log now:

> "error"=\>{"type"=\>"invalid\_index\_name\_exception", "reason"=\>"Invalid index name [filebeat-2017-01-10 11:48:13:775+0000], must not contain the following characters [\, /, \*, ?, ", \<, \>, |, , ,]", "index"=\>"filebeat-2017-01-10 11:48:13:775+0000"}}}, :level=\>:warn}

> [@jbudz](#):
>
> In the UI, if you select "Use event times to create index names" do things work?

No, also nothing.

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [January 10, 2017, 5:25pm UTC](https://discuss.elastic.co/t/kibana-doesnt-show-logs/70935/6 "2017-01-10T17:25:09Z")

</div>

Mappings can be found by requesting `/filebeat-*/_mapping` from your elasticsearch node.

Regarding the logstash output, I'm guessing you don't want a new index every millisecond. Daily and monthly indices are common ({+YYYY.MM.dd}, {+[YYYY.MM](http://YYYY.MM)}). The invalid character is the space.

---

<div class="post-metadata">

**Author:** ![wrkilu](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wrkilu](https://discuss.elastic.co/u/wrkilu)\
**Post date:** [January 11, 2017, 9:51am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-logs/70935/7 "2017-01-11T09:51:44Z")

</div>

Ok, I've solved the problem. I've changed only output.conf in Logstash from above to minimalistic:

> output {  
> elasticsearch {  
> hosts =\> ["10.209.3.135:9200"]  
> }  
> }

...and it started work 🙂. What is interesting in logs (in Kibana) I have now index named (from default of course) " logstash-2017.01.11". Earlier I created filebeat-\* so it couldn't work of course. On the other hand I created earlier also index "\*" but it didn't show anyting either so this is strange.

Anyway... my first settings in output.conf were somehow exaggerated and thats why it didn't work.

I'm closing the case and many thanks to you Jon for enagagement in this post 🙂  
wrkilu

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2017, 9:51am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-logs/70935/8 "2017-02-08T09:51:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
