# Kibana, Logstash - Couldn't find any Elasticsearch data

**URL:** <https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913>\
**Category:** Kibana\
**Created:** [March 28, 2018, 10:57am UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913 "2018-03-28T10:57:12Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chips](https://avatars.discourse-cdn.com/v4/letter/c/3ab097/32.png) [@Chips](https://discuss.elastic.co/u/Chips)\
**Post date:** [March 28, 2018, 10:57am UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913/1 "2018-03-28T10:57:12Z")

</div>

Kibana on the control tab appears an inscription "Couldn't find any Elasticsearch data".

 ![%D0%A1%D0%BD%D0%B8%D0%BC%D0%BE%D0%BA%20%D1%8D%D0%BA%D1%80%D0%B0%D0%BD%D0%B0%20%D0%BE%D1%82%202018-03-28%2015-40-14](https://us1.discourse-cdn.com/elastic/original/3X/7/8/785a43ca49284cb8d706ed208053e1373d7af2f1.png)

I decided to see if I have any templates at all on what to give out to me the following:  
`health status index uuid pri rep docs.count docs.deleted store.size pri.store.size`

Although it should be like this:

```
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size
green open logstash-0 4fOMSVMoQ3S0ZNpb73WjDA 1 0 14005 0 56mb 56mb
green open .kibana Zd2muayFR7SlPBGq1f6ShQ 1 0 3 1 26.2kb 26.2kb
yellow open shakespeare LmuYM18vTN6SOJU8mw20Pg 5 1 111396 0 21.2mb 21.2mb

```

The installation of Logstash, Kibana, Elasticsearch was performed on Ubuntu 16.04.

Installation performed as it was said [here](https://www.elastic.co/guide/en/logstash/current/installing-logstash.html#package-repositories), [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/zip-targz.html) and [there](https://www.elastic.co/guide/en/kibana/current/targz.html).

What could be the problem and how to set the template index logstash-0?

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 28, 2018, 1:19pm UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913/2 "2018-03-28T13:19:08Z")

</div>

Can you do a "GET \_cat/indices" in the Dev Tools console inside Kibana?

---

<div class="post-metadata">

**Author:** ![Chips](https://avatars.discourse-cdn.com/v4/letter/c/3ab097/32.png) [@Chips](https://discuss.elastic.co/u/Chips)\
**Post date:** [March 29, 2018, 3:02am UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913/3 "2018-03-29T03:02:24Z")

</div>

Gives an error message

```
{
  "error": "Incorrect HTTP method for uri [/_cat] and method [POST], allowed: [GET]",
  "status": 405
}
```

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [March 29, 2018, 11:39am UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913/4 "2018-03-29T11:39:29Z")

</div>

You need to a GET request, not a POST request, like this:  
`curl -XGET "http://localhost:9200/_cat/indices"`  
where `localhost:9200` is the address and port for your Elasticsearch instance.

---

<div class="post-metadata">

**Author:** ![Blisk](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@Blisk](https://discuss.elastic.co/u/Blisk)\
**Post date:** [April 16, 2018, 2:03pm UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913/5 "2018-04-16T14:03:21Z")

</div>

Hi  
I have the same problem and when I get indices I get this.

yellow open logstash-2015.05.20 5hrI0PMvS3qh6RZUqg7Yng 5 1 0 0 1.2kb 1.2kb  
yellow open logstash-2015.05.19 70ADDXtcQouCgsaK73EN-g 5 1 0 0 1.2kb 1.2kb  
yellow open shakespeare -sZuMTVeRiSoCRIKSb-n2g 5 1 0 0 1.2kb 1.2kb  
yellow open logstash-2015.05.18 Iel3IM17T7-bQqvOVe9ERw 5 1 0 0 1.2kb 1.2kb

---

<div class="post-metadata">

**Author:** ![Blisk](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@Blisk](https://discuss.elastic.co/u/Blisk)\
**Post date:** [April 17, 2018, 8:56am UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913/6 "2018-04-17T08:56:45Z")

</div>

Can anyone suggest what to do?

---

<div class="post-metadata">

**Author:** ![ruzzetto](https://avatars.discourse-cdn.com/v4/letter/r/d9b06d/32.png) [@ruzzetto](https://discuss.elastic.co/u/ruzzetto)\
**Post date:** [April 17, 2018, 9:21am UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913/7 "2018-04-17T09:21:01Z")

</div>

Hi,  
I have the same problem too. Reading some guides over internet it seems we're unable to create any indexes until any kind of data will arrive. Is that true?

I'm going to configure logstash for syslog incoming (some network devices)

Thanks,

---

<div class="post-metadata">

**Author:** ![Blisk](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@Blisk](https://discuss.elastic.co/u/Blisk)\
**Post date:** [April 17, 2018, 9:35am UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913/8 "2018-04-17T09:35:50Z")

</div>

Yes that is true, but I have data and don't know where is problem. There is so much to setup before this starts to work and coding isn't my field. This should be more plugin solved not coding.

---

<div class="post-metadata">

**Author:** ![ruzzetto](https://avatars.discourse-cdn.com/v4/letter/r/d9b06d/32.png) [@ruzzetto](https://discuss.elastic.co/u/ruzzetto)\
**Post date:** [April 17, 2018, 9:37am UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913/9 "2018-04-17T09:37:33Z")

</div>

Ok, thanks. Have you ever experience with syslog? It seems logstash won't open UDP socket 514 on my machine

---

<div class="post-metadata">

**Author:** ![Blisk](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@Blisk](https://discuss.elastic.co/u/Blisk)\
**Post date:** [April 18, 2018, 10:16am UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913/10 "2018-04-18T10:16:50Z")

</div>

I give up on this crap, it is way to hard to setup anything to work even on basic logs. I will delete kibana and elasticsearch and install splunk which is more intiutive and much easier to setup.  
You have some samples about version 5 how to install and setup but on 6 almost nothing, and all what it is you can use it only if you have alot of previous knowledge of kibana, elasticsearch...

---

<div class="post-metadata">

**Author:** ![tamersalama](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tamersalama/32/30786_2.png) [@tamersalama](https://discuss.elastic.co/u/tamersalama)\
**Post date:** [May 3, 2018, 10:06pm UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913/11 "2018-05-03T22:06:37Z")

</div>

It appears the issue might have had something to do with the number of hidden system indexes in Elasticsearch (.monitoring-_, .watch-_). Or a combination of those hidden system and query Kibana issues to get those indexes (perhaps it pagination limit).

What I did was remove some/all older indexes - which resulted in the Kibana query to get the indexes actually returning non-system indexes in the first page (and properly displaying them).

HTH

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2018, 10:06pm UTC](https://discuss.elastic.co/t/kibana-logstash-couldnt-find-any-elasticsearch-data/125913/12 "2018-05-31T22:06:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
