# Kibana, missing fields

**URL:** <https://discuss.elastic.co/t/kibana-missing-fields/274989>\
**Category:** Kibana\
**Created:** [June 4, 2021, 1:53pm UTC](https://discuss.elastic.co/t/kibana-missing-fields/274989 "2021-06-04T13:53:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Weathmious](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weathmious/32/70916_2.png) [@Weathmious](https://discuss.elastic.co/u/Weathmious)\
**Post date:** [June 4, 2021, 1:53pm UTC](https://discuss.elastic.co/t/kibana-missing-fields/274989/1 "2021-06-04T13:53:01Z")

</div>

Hello,  
I currently use graylog as SIEM. I kibana to install on the same server in order to better visualize the data. I created different extractors on graylog to have several fields extracted from the message:

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/e/3e23234da7bdc80dbf28842dea3a68bdc76ef4af.png)

The problem is that on kibana, these fields do not necessarily appear and are not the same, I need them to create my dashboards

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/5/a572e557f99ce4d32af07fb5e782f3548c7172a7.png)

For example, the field ip\_src, backend, frontend is missing here

I try to find the solution but for the moment I can’t understand why the fields are not the same (for the haproxy logs in this case), knowing that for some messages (which come from something other than the haproxy) they are

Thank you

---

<div class="post-metadata">

**Author:** ![Weathmious](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weathmious/32/70916_2.png) [@Weathmious](https://discuss.elastic.co/u/Weathmious)\
**Post date:** [June 8, 2021, 8:20am UTC](https://discuss.elastic.co/t/kibana-missing-fields/274989/2 "2021-06-08T08:20:35Z")

</div>

I specify that in addition to that Kibana knows these extractors:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/a/ea5d670759cc00cdd294f1d0cc8281941ed22e4e.png)

Thank you

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [June 8, 2021, 9:37pm UTC](https://discuss.elastic.co/t/kibana-missing-fields/274989/3 "2021-06-08T21:37:10Z")

</div>

Hi, can you explain your data pipeline? Is the data going into Graylog and then copied into Elasticsearch? Or is data being sent to Grayload and Elasticsearch?

Have you looked into using ingest pipelines? [Ingest pipelines | Elasticsearch Guide [7.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html#ingest)

Did you create an index template for this data? [Index templates | Elasticsearch Guide [7.13] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-templates.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2021, 9:37pm UTC](https://discuss.elastic.co/t/kibana-missing-fields/274989/4 "2021-07-06T21:37:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
