# Kibana not seeing ES logs insterted via HTTP POST

**URL:** <https://discuss.elastic.co/t/kibana-not-seeing-es-logs-insterted-via-http-post/210398>\
**Category:** Kibana\
**Created:** [December 3, 2019, 4:25pm UTC](https://discuss.elastic.co/t/kibana-not-seeing-es-logs-insterted-via-http-post/210398 "2019-12-03T16:25:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![maxstone9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maxstone9/32/58719_2.png) [@maxstone9](https://discuss.elastic.co/u/maxstone9)\
**Post date:** [December 3, 2019, 4:25pm UTC](https://discuss.elastic.co/t/kibana-not-seeing-es-logs-insterted-via-http-post/210398/1 "2019-12-03T16:25:16Z")

</div>

Hey all,

I got Kibana and ES working together and data flowing from Winston without any issues. I have a mobile app that I am trying to hook up to ES and wanted to do it via an HTTP POST call.

```
POST /logs-2019.12.03/_doc

```

I see the new fields in the index in ES and I refreshed the Index Pattern in Kibana, but when I try to search for the data in those new fields nothing is showing up. I was able to query ES API directly to retrieve this data, so it seems there is an issue between Kibana and ES.

Any ideas?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [December 10, 2019, 9:49am UTC](https://discuss.elastic.co/t/kibana-not-seeing-es-logs-insterted-via-http-post/210398/2 "2019-12-10T09:49:56Z")

</div>

Hi @maxstone9,

thanks for reaching out. In the top menu there should be an `Inspect` button. It can show you the ES request made by Kibana. Could you copy and paste the one that's not working for you together with the mapping of your index (`GET /logs-*/_mapping`) and the request you are sending to ES directly that's working fine?

---

<div class="post-metadata">

**Author:** ![maxstone9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maxstone9/32/58719_2.png) [@maxstone9](https://discuss.elastic.co/u/maxstone9)\
**Post date:** [December 19, 2019, 7:37pm UTC](https://discuss.elastic.co/t/kibana-not-seeing-es-logs-insterted-via-http-post/210398/3 "2019-12-19T19:37:43Z")

</div>

hey @flash1293

Thank you for your response. I don't see the inspect button in my options. I am using Kibana 7.4.2.

**Mapping for 12.19.2019 ES Index**

> <https://gist.github.com/lzychowski/79b5a1215b5138ad589ab966ecf4f1eb>

**[Not Showing Up In Discover] Request from Postman to the index with `message` field**

 ![post_request](https://us1.discourse-cdn.com/elastic/original/3X/9/e/9e6553cc840abcacfcb07d7c2278048ff0590264.png)

**Get request for the above data posted with postman**

 ![get_request](https://us1.discourse-cdn.com/elastic/original/3X/4/2/4254427f6f10ebeaf59615e3d0ed896c5fc2152d.png)

**Discover search**

 ![discover](https://us1.discourse-cdn.com/elastic/original/3X/2/c/2c862d7fb80ad9fc71710d42af219a21bc04beac.jpeg)

**Index Patterns**

 ![index_pattern](https://us1.discourse-cdn.com/elastic/original/3X/1/4/140596299c7edce80b757e2339b34dad83dfe463.jpeg)

The successful requests are coming from node.js, so if you could please guide me how to get those out of Kibana UI, I can attach them as well.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [December 20, 2019, 9:12am UTC](https://discuss.elastic.co/t/kibana-not-seeing-es-logs-insterted-via-http-post/210398/4 "2019-12-20T09:12:16Z")

</div>

Sorry that was a bit vague - I meant the "Inspect" button in the Discover view. It's also visible in your screenshot, the last of the menu items above the search bar. Could you copy/paste the request from there?

At least for your example document the problem is that your time range is set to "30 Minutes" which adds a filter based on the time field of the index pattern to the request. As your `this is a test for les` document doesn't even have a time field (just a message field) it will get filtered out and isn't shown at all. Maybe that's also the problem with your actual data? Could you attach a real-world document out of your index that should show up but doesn't (with personal data blacked out)? If you want to use discover without a time field that's also possible - you just have to create the index pattern without a time field, then the time filter won't get added behind the scenes.

---

<div class="post-metadata">

**Author:** ![maxstone9](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/maxstone9/32/58719_2.png) [@maxstone9](https://discuss.elastic.co/u/maxstone9)\
**Post date:** [December 31, 2019, 8:39pm UTC](https://discuss.elastic.co/t/kibana-not-seeing-es-logs-insterted-via-http-post/210398/5 "2019-12-31T20:39:28Z")

</div>

@flash1293 the lack of timestamp was totally the problem. Thanks for all the help and happy new year!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 28, 2020, 8:39pm UTC](https://discuss.elastic.co/t/kibana-not-seeing-es-logs-insterted-via-http-post/210398/6 "2020-01-28T20:39:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
