# Kibana - Failed to query events data

**URL:** <https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699>\
**Category:** Kibana\
**Created:** [August 17, 2021, 2:08pm UTC](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699 "2021-08-17T14:08:38Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 17, 2021, 2:08pm UTC](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699/1 "2021-08-17T14:08:38Z")

</div>

Here are the full errors:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/9/6997280723c8198b37c72f5e701956ab442b9917.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/8/080b03aa6864af1569bc238ae1445abc8e71f664.png)

That is the error i see in KIbana when i try to visualize auditbeat data from auditbeat index.

i cannot visualize anything in Kibana now from that index.  
The error states:

```auto
type": "illegal_argument_exception",
"reason": "Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [host.name] in order to load field data by uninverting the inverted index. Note that this can use significant memory."

```

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [August 18, 2021, 8:58am UTC](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699/2 "2021-08-18T08:58:30Z")

</div>

Hi

Which version of Auditbeat are you using and could you share the mapping of one of the indices you are trying to query events data?

Thx!  
Matthias

---

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 18, 2021, 9:07am UTC](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699/3 "2021-08-18T09:07:25Z")

</div>

I use auditbeat-7.13.2.

Should it be automated? The mapping i mean. Because it's an auditbeat index. So if i understood you correctly you want the whole json mapping index management.  
Here it is:

```auto
{
  "mappings": {
    "_doc": {
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "@version": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },
        "agent": {
          "properties": {
            "ephemeral_id": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            },
            "hostname": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            },
            "id": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            },
            "name": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            },
            "type": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            },
            "version": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            }
          }
        },
        "auditd": {
          "properties": {
            "data": {
              "properties": {
                "acct": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "audit_enabled": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "cmd": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "entries": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "family": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "hostname": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "old": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "old-ses": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "op": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "table": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "terminal": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "tty": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                },
                "unit": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  }
                }
              }
            },
            "message_type": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            },

.
.
.
.
.
.
.

```

It doesn't let me paste the whole mappings Json so i have pasted a portion and the whole Json is in [here](https://pastebin.com/98R86BWg)

The name of the index is \*\* auditbeat-7.13.2\*\* and i create it from logstash output config like this:

```auto
 elasticsearch { 
        hosts => ["https://localhost:9200"] 
        index => "%{[@metadata][beat]}-%{[@metadata][version]}"
        user => logstash_internal
        password => logstashpass
        ssl => true
        cacert => "/usr/share/logstash/config/elasticsearch-ca.pem"
        http_compression => true
	 	sniffing => false 
    } 

```

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [August 19, 2021, 6:01am UTC](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699/4 "2021-08-19T06:01:59Z")

</div>

Could you try to visualize by `host.name.keyword`?  
Also I'm not sure you're using the audit beat index template, it looks more like the default ES one, have a look here:

> **[Load the Elasticsearch index template | Auditbeat Reference \[7.14\] | Elastic](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-template.html)**

---

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 19, 2021, 8:21am UTC](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699/5 "2021-08-19T08:21:37Z")

</div>

How I'm going to do that? Whenever i go to kibana i see this

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/2/3286b5ee3c8d3b528ae027bda1960d27566ede9e.png)  
And are the same error i send you before.

How I'm going to see the mapping attached to an index? Here are the mapping templates

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/c/3c89cf5e34301ae48e962edece6d25aed1d55867.png)

and here are the Indexes

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f3d5ebc022e7bed9bcb9901bc1f103bff29704c.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dc498165ee33e9a94c4b8e6386a1822019c7561a.png)

Also to point out that i didn't make any changes to the default ones.  
Just instead of sending auditbeat straight to ES, it now goes first to Logstash, but there is no change in the fields.

---

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 20, 2021, 11:42pm UTC](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699/6 "2021-08-20T23:42:34Z")

</div>

Anyone could know why these error occur ?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 21, 2021, 5:36am UTC](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699/7 "2021-08-21T05:36:22Z")

</div>

Looks like you did not run `setup`.

setup sets up the correct mappings, ingest pipeline etc.

Hopefully your are following the steps closely in the Quick start guide

Setup see [here](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-installation-configuration.html#setup-assets)

Auditbeat Quick start guide [here](https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-installation-configuration.html)

If you do not run setup your mappings will not be correct which is what your issue looks like to me.

Also if you Architecture is

Auditbeat \> Logstash \> Elasticsearch you need to follow this process.

This example is metricbeat but same process

> [@Metricbeat to Logstash to ElasticSearch - Cannot See Any Hosts Defined, But Data Is Definitely Coming In](https://discuss.elastic.co/t/metricbeat-to-logstash-to-elasticsearch-cannot-see-any-hosts-defined-but-data-is-definitely-coming-in/275715/2):
>
> Hi @jthart Welcome to the community apologies that you're having some struggles getting this set up Perhaps we can help. Assuming you want to run an architecture like this Metricbeat (1 to Many) -\> Logstash -\> Elasticsearch Basically using Logstash as a collect and pass through Here is my recommendation try to resist the urge to make this more complex. Do not try to manually load index templates dashboards anything else follow the quick start / basic setup. Clean everything up we're star…

Also I would get

Auditbeat \> Elasticsearch working first then introduce Logstash

---

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 21, 2021, 12:22pm UTC](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699/8 "2021-08-21T12:22:01Z")

</div>

The solution wasn't obvious. I had already done the `auditbeat setup` thing. So i made the output of Auditbeat straight to ES.  
And then i noticed the error ` resource .... exists, but it is not an alias` so i solved in on that [thread](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-http-es01-9200-connection-marked-as-failed-because-the-onconnect-callback-failed-resource-apm-7-5-2-error-exists-but-it-is-not-an-alias/236088).

So the problem was that i deleted the `auditbeat-7.13.2` index and i created another one via logstash when i had the output like this:

```auto
output { 

    elasticsearch { 
        hosts => ["https://localhost:9200"] 
        index => "%{[@metadata][beat]}-%{[@metadata][version]}"
        user => logstash_user
        password => apass
        ssl => true
        cacert => "/usr/share/logstash/config/elasticsearch-ca.pem"
        http_compression => true
	 	sniffing => false 
    } 
}

```

So i get **HOW** this happened but even after i read that [thread on github](https://github.com/elastic/apm-server/issues/3698#issuecomment-620865066), i don't fully understand **WHY** is that behavior happening. I mean i just Deleted the index and logstash created automatically...

Can someone explain it ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2021, 12:23pm UTC](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699/9 "2021-09-18T12:23:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
