# Kibana index does not contain a timestamp aka why does kibana search the kibana-int index?

**URL:** <https://discuss.elastic.co/t/kibana-index-does-not-contain-a-timestamp-aka-why-does-kibana-search-the-kibana-int-index/17372>\
**Category:** Elasticsearch\
**Created:** [May 6, 2014, 1:33pm UTC](https://discuss.elastic.co/t/kibana-index-does-not-contain-a-timestamp-aka-why-does-kibana-search-the-kibana-int-index/17372 "2014-05-06T13:33:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jorn\_Eilander](https://avatars.discourse-cdn.com/v4/letter/j/b5a626/32.png) [@Jorn\_Eilander](https://discuss.elastic.co/u/Jorn_Eilander)\
**Post date:** [May 6, 2014, 1:33pm UTC](https://discuss.elastic.co/t/kibana-index-does-not-contain-a-timestamp-aka-why-does-kibana-search-the-kibana-int-index/17372/1 "2014-05-06T13:33:04Z")

</div>

LS,

I've been using an ELK-stack for development purposes for a few weeks now,  
and my logs were filled with errors.

The errors it seemed were traceable to the fact that Kibana was(/is)  
querying all the shards on the node for the @timestamp fields, which isn't  
present in the kibana-int index (where Kibana stores it reports).

So when my users generate a report, Kibana searches in \_all for the data,  
which contains shards/indices not related to logstash... Is there any way I  
can limit them to the indices/shards related to Logstash? I dislike errors  
in my logging 😉

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/17438280-2a12-4aac-aa39-4349d4f8d996%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/17438280-2a12-4aac-aa39-4349d4f8d996%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Bharvi\_Dixit\_2](https://avatars.discourse-cdn.com/v4/letter/b/9d8465/32.png) [@Bharvi\_Dixit\_2](https://discuss.elastic.co/u/Bharvi_Dixit_2)\
**Post date:** [May 7, 2014, 4:17am UTC](https://discuss.elastic.co/t/kibana-index-does-not-contain-a-timestamp-aka-why-does-kibana-search-the-kibana-int-index/17372/2 "2014-05-07T04:17:49Z")

</div>

Hi,  
In the configuration setting of kibana which appears on top-right corner,  
you can provide name of specific index instead of \_all under index tab. And  
under Timepicker tab, you can provide any date field of the logstash index  
instaead of default @timestamp value. Note that date fields name should  
not contain @ symbol, it must be like tweetCreatedAt not @tweetCreatedAt.

Regards,  
Bharvi Dixit

On Tuesday, 6 May 2014 19:03:04 UTC+5:30, Jorn Eilander wrote:

> LS,
> 
> I've been using an ELK-stack for development purposes for a few weeks now,  
> and my logs were filled with errors.
> 
> The errors it seemed were traceable to the fact that Kibana was(/is)  
> querying all the shards on the node for the @timestamp fields, which isn't  
> present in the kibana-int index (where Kibana stores it reports).
> 
> So when my users generate a report, Kibana searches in \_all for the data,  
> which contains shards/indices not related to logstash... Is there any way I  
> can limit them to the indices/shards related to Logstash? I dislike errors  
> in my logging 😉

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/56462433-c6ab-4f76-955b-7b1925b7edcf%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/56462433-c6ab-4f76-955b-7b1925b7edcf%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:31am UTC](https://discuss.elastic.co/t/kibana-index-does-not-contain-a-timestamp-aka-why-does-kibana-search-the-kibana-int-index/17372/3 "2017-07-06T01:31:11Z")

</div>


