# Kibana issue - Index Patterns: Please specify a default index pattern

**URL:** <https://discuss.elastic.co/t/kibana-issue-index-patterns-please-specify-a-default-index-pattern/133712>\
**Category:** Elasticsearch\
**Created:** [May 29, 2018, 3:36pm UTC](https://discuss.elastic.co/t/kibana-issue-index-patterns-please-specify-a-default-index-pattern/133712 "2018-05-29T15:36:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhat](https://avatars.discourse-cdn.com/v4/letter/a/8e8cbc/32.png) [@abhat](https://discuss.elastic.co/u/abhat)\
**Post date:** [May 29, 2018, 3:36pm UTC](https://discuss.elastic.co/t/kibana-issue-index-patterns-please-specify-a-default-index-pattern/133712/1 "2018-05-29T15:36:05Z")

</div>

Hi Team,

I have setup an ELK Stack and when I am trying to login I am seeing below message -

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/d/edfbcf72e5b03a40444c68e882488be06edd637a.png)

Used filebeat-\* but it is not showing up the save option

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/4/947341840cece271b38d960a7fa457a4ad409c0e.png)

Any starting point I need to check.

Kind Regards,  
Asif Bhat

---

<div class="post-metadata">

**Author:** ![abhat](https://avatars.discourse-cdn.com/v4/letter/a/8e8cbc/32.png) [@abhat](https://discuss.elastic.co/u/abhat)\
**Post date:** [May 29, 2018, 3:51pm UTC](https://discuss.elastic.co/t/kibana-issue-index-patterns-please-specify-a-default-index-pattern/133712/2 "2018-05-29T15:51:36Z")

</div>

cd /etc/logstash/  
vim conf.d/filebeat-input.conf  
Input configuration: paste the configuration below.  
input {  
beats {  
port =\> 5443  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}  
Save and exit.  
Create the syslog-filter.conf file.  
vim conf.d/syslog-filter.conf  
Paste the configuration below.  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
We use a filter plugin named 'grok' to parse the syslog files.  
Save and exit.  
Create the output configuration file 'output-elasticsearch.conf'.  
vim conf.d/output-elasticsearch.conf  
Paste the configuration below.  
output {  
elasticsearch { hosts =\> ["localhost:9200"]  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
Save and exit.  
Finally add logstash to start at boot time and start the service.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2018, 3:51pm UTC](https://discuss.elastic.co/t/kibana-issue-index-patterns-please-specify-a-default-index-pattern/133712/3 "2018-06-26T15:51:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
