# Kibana - Failed to query events data

**URL:** <https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699>\
**Category:** Kibana\
**Created:** [August 17, 2021, 2:08pm UTC](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699 "2021-08-17T14:08:38Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![panagiss](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@panagiss](https://discuss.elastic.co/u/panagiss)\
**Post date:** [August 21, 2021, 12:22pm UTC](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699/8 "2021-08-21T12:22:01Z")

</div>

The solution wasn't obvious. I had already done the `auditbeat setup` thing. So i made the output of Auditbeat straight to ES.  
And then i noticed the error ` resource .... exists, but it is not an alias` so i solved in on that [thread](https://discuss.elastic.co/t/failed-to-connect-to-backoff-elasticsearch-http-es01-9200-connection-marked-as-failed-because-the-onconnect-callback-failed-resource-apm-7-5-2-error-exists-but-it-is-not-an-alias/236088).

So the problem was that i deleted the `auditbeat-7.13.2` index and i created another one via logstash when i had the output like this:

```auto
output { 

    elasticsearch { 
        hosts => ["https://localhost:9200"] 
        index => "%{[@metadata][beat]}-%{[@metadata][version]}"
        user => logstash_user
        password => apass
        ssl => true
        cacert => "/usr/share/logstash/config/elasticsearch-ca.pem"
        http_compression => true
	 	sniffing => false 
    } 
}

```

So i get **HOW** this happened but even after i read that [thread on github](https://github.com/elastic/apm-server/issues/3698#issuecomment-620865066), i don't fully understand **WHY** is that behavior happening. I mean i just Deleted the index and logstash created automatically...

Can someone explain it ?

---

_[View the full topic](https://discuss.elastic.co/t/kibana-failed-to-query-events-data/281699)._
