Kibana not showning data from ES


(John) #1

Hi,

I've used Fscrawler to index some files from the file system to ES and hoped to hook up ES to Kibana to get a visual representation but after defining an index pattern for Kibana it doesn't display anything under the discover tab...

I've have used the same index name for all inputs and they all have date modified and i can see the _source is full in ES but under discover i can't find any results on _source and * (i've even tried setting it to past 7 days etc).
Any ideas?


(Chris Cowan) #2

When you go to the index pattern under settings are there any fields listed?


(John) #3

Yes i do, i will even add a picture :slight_smile:
Fields I have


(John) #4

Anyone?


(Joe Fleming) #5

Are you sure you have records in the last 7 days? I'm guessing you are...

Are you sure that Elasticsearch is correctly parsing the date you are giving it? Can you see the data if you query Elasticsearch directly, without using Kibana?


(John) #6

Actually double checking based on what you have said, apparently if i go back more than a year i can see data, this is kind of stupid isn't there a way to make it show all data from all time?


(Joe Fleming) #7

Currently, no. Im not sure there's an API in Elasticsearch to find out where your data starts and ends, and if there's not, there's no way for Kibana to get that time range.

The more common use case is to use Kibana to view current data, so that's why the last 15 minutes is the default. You can change the default in advanced settings if you need to though.


(John) #8

Thanks! no further questions so far.


(system) #9