# Kibana index pattern matching error

**URL:** <https://discuss.elastic.co/t/kibana-index-pattern-matching-error/109540>\
**Category:** Kibana\
**Created:** [November 29, 2017, 9:02am UTC](https://discuss.elastic.co/t/kibana-index-pattern-matching-error/109540 "2017-11-29T09:02:45Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![nivedita\_singh](https://avatars.discourse-cdn.com/v4/letter/n/7c8e57/32.png) [@nivedita\_singh](https://discuss.elastic.co/u/nivedita_singh)\
**Post date:** [November 29, 2017, 9:02am UTC](https://discuss.elastic.co/t/kibana-index-pattern-matching-error/109540/1 "2017-11-29T09:02:45Z")

</div>

In kibana pattern index not matching.

When I am trying to connect to Kibana through port:5601 , it is showing kibana web page but non of the index is matching . As I am using logstash so index pattern I am giving is logstash-\* .  
it is throwing index pattern not matching.

How do I proceed further?

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [November 29, 2017, 8:49pm UTC](https://discuss.elastic.co/t/kibana-index-pattern-matching-error/109540/2 "2017-11-29T20:49:36Z")

</div>

I'd start by checking elasticsearch directly to confirm that the indices exist.

Can you try requesting `localhost:9200/_cat/indices` from elasticsearch and looking for the expected names?

---

<div class="post-metadata">

**Author:** ![nivedita\_singh](https://avatars.discourse-cdn.com/v4/letter/n/7c8e57/32.png) [@nivedita\_singh](https://discuss.elastic.co/u/nivedita_singh)\
**Post date:** [November 30, 2017, 11:26am UTC](https://discuss.elastic.co/t/kibana-index-pattern-matching-error/109540/3 "2017-11-30T11:26:47Z")

</div>

Hi ,

Thanks for replying.  
so after running localhost:9200/\_cat/indices I got the following response :  
yellow open .kibana W9UCeb4WQsm7Vx3tkBH4AQ 1 1 1 0 3.2kb 3.2kb

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [November 30, 2017, 6:58pm UTC](https://discuss.elastic.co/t/kibana-index-pattern-matching-error/109540/4 "2017-11-30T18:58:24Z")

</div>

Okay, elasticsearch is telling us that no logstash indices exist. Next steps would be to check the logstash logs for any configuration errors, and to verify the service is running properly. Logs will be stored in either /var/log/logstash or the logs folder in the logstash extraction.

---

<div class="post-metadata">

**Author:** ![nivedita\_singh](https://avatars.discourse-cdn.com/v4/letter/n/7c8e57/32.png) [@nivedita\_singh](https://discuss.elastic.co/u/nivedita_singh)\
**Post date:** [December 1, 2017, 7:57am UTC](https://discuss.elastic.co/t/kibana-index-pattern-matching-error/109540/5 "2017-12-01T07:57:07Z")

</div>

Thanks for helping.

these are the log files I have got under logstash- logs

 ![log1](https://us1.discourse-cdn.com/elastic/original/3X/7/2/72b6215f12b6d3096343a71df9b41e9c23af0aa8.PNG)

 ![log2](https://us1.discourse-cdn.com/elastic/original/3X/a/c/ace2b65b0988f1237654cf89b3be48016324373c.PNG)

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [December 5, 2017, 4:19pm UTC](https://discuss.elastic.co/t/kibana-index-pattern-matching-error/109540/6 "2017-12-05T16:19:49Z")

</div>

The first log looks fine, it was able to connect to elasticsearch and add a template. The second log looks like an intentional stoppage of logstash, which is also fine.

Can you verify that logstash is getting events? One option is to log events to stdout as they come in:

```auto
output {
  stdout { codec => rubydebug }
}

```

If nothing shows up I would try manually sending an event using netcat or similar.

---

<div class="post-metadata">

**Author:** ![nivedita\_singh](https://avatars.discourse-cdn.com/v4/letter/n/7c8e57/32.png) [@nivedita\_singh](https://discuss.elastic.co/u/nivedita_singh)\
**Post date:** [December 11, 2017, 4:15am UTC](https://discuss.elastic.co/t/kibana-index-pattern-matching-error/109540/7 "2017-12-11T04:15:17Z")

</div>

Hi ,  
tried doing this,  
still nothing progressed .  
Attaching the snippets of logs newly generated after doing changes following in logstash conf file.

Kindly help me about the next steps .

Thanks

 ![Untitled](https://us1.discourse-cdn.com/elastic/original/3X/0/3/037f155d533b1a734e8d8520f826205bcba60746.png) ![Untitled1](https://us1.discourse-cdn.com/elastic/original/3X/f/4/f4cc4b21f6d1e77249ae27f96c115f7d7fdd29c1.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2018, 4:15am UTC](https://discuss.elastic.co/t/kibana-index-pattern-matching-error/109540/8 "2018-01-08T04:15:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
