# Kibana unable to query index data from ES

**URL:** <https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134>\
**Category:** Kibana\
**Created:** [April 14, 2021, 5:02pm UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134 "2021-04-14T17:02:56Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![GregoryBrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregorybrown/32/53934_2.png) [@GregoryBrown](https://discuss.elastic.co/u/GregoryBrown)\
**Post date:** [April 14, 2021, 5:02pm UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134/1 "2021-04-14T17:02:56Z")

</div>

I am able to upload the following data into my ES Cluster, and have an index template apply to it. However the default search of kibana (using an index pattern) doesn't query the data.

Index Template that gets applied to the indices:

```
{
  "properties": {
    "@timestamp": {
      "format": "epoch_millis||strict_date_optional_time",
      "index": true,
      "ignore_malformed": false,
      "store": false,
      "type": "date",
      "doc_values": true
    }
  }
}

```

I see the data in ES:

```
curl --location --request POST 'http://es-node-2:9200/*grpc*/_search' \
--header 'Content-Type: application/json' \
--data-raw '{
  "size": 500,
  "sort": [
    {
      "@timestamp": {
        "order": "desc",
        "unmapped_type": "boolean"
      }
    }
  ],
  "version": true,
  "fields": [
    {
      "field": "*",
      "include_unmapped": "true"
    },
    {
      "field": "@timestamp",
      "format": "strict_date_optional_time"
    }
  ],
  "aggs": {
    "2": {
      "date_histogram": {
        "field": "@timestamp",
        "fixed_interval": "10m",
        "time_zone": "America/New_York",
        "min_doc_count": 1
      }
    }
  },
"script_fields": {},
  "stored_fields": [
    "*"
  ],
  "runtime_mappings": {},
  "_source": false
}'

"hits": {
        "total": {
            "value": 3,
            "relation": "eq"
        },
        "max_score": null,
        "hits": [
            {
                "_index": "cisco-ios-xr-ip-rib-ipv4-oper-rib-vrfs-vrf-afs-af-safs-saf-ip-rib-route-table-names-ip-rib-grpc-2021.04.14",
                "_type": "_doc",
                "_id": "wNxF0XgBgKJ8dEf0YYZq",
                "_version": 1,
                "_score": null,
                "fields": {
                    "keys.vrf-name.keyword": [
                        "default"
                    ],
                    "keys.vrf-name": [
                        "default"
                    ],
                    "keys.saf-name": [
                        "Unicast"
                    ],
                    "content.entry.keyword": [
                        "0.0.0.0"
                    ],
                    "keys.af-name": [
                        "IPv4"
                    ],
                    "keys.route-table-name": [
                        "default"
                    ],

```

But when Kibana tries to query it, I don't see any results:

```
{
  "size": 500,
  "sort": [
    {
      "@timestamp": {
        "order": "desc",
        "unmapped_type": "boolean"
      }
    }
  ],
  "version": true,
  "fields": [
    {
      "field": "*",
      "include_unmapped": "true"
    },
    {
      "field": "@timestamp",
      "format": "strict_date_optional_time"
    }
  ],
  "aggs": {
    "2": {
      "date_histogram": {
        "field": "@timestamp",
        "fixed_interval": "10m",
        "time_zone": "America/New_York",
        "min_doc_count": 1
      }
    }
  },
  "script_fields": {},
  "stored_fields": [
    "*"
  ],
  "runtime_mappings": {},
  "_source": false,
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "match_all": {}
        },
        {
          "range": {
            "@timestamp": {
              "gte": "2021-04-14T02:01:38.062Z",
              "lte": "2021-04-14T17:01:38.062Z",
              "format": "strict_date_optional_time"
            }
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  },
  "highlight": {
    "pre_tags": [
      "@kibana-highlighted-field@"
    ],
    "post_tags": [
      "@/kibana-highlighted-field@"
    ],
    "fields": {
      "*": {}
    },
    "fragment_size": 2147483647
  }
} 

```

How can I make Kibana search similar to what I am searching for?

I use _grpc_ index pattern and have @timestamp set.

Thanks,

Greg

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [April 14, 2021, 11:56pm UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134/2 "2021-04-14T23:56:57Z")

</div>

> [@GregoryBrown](#):
>
> ` "_index": "cisco-ios-xr-ip-rib-ipv4-oper-rib-vrfs-vrf-afs-af-safs-saf-ip-rib-route-table-names-ip-rib-grpc-2021.04.14`

Do you have an index pattern like below or similar?

```auto
cisco-ios-xr-ip-rib-ipv4-oper-rib-vrfs-vrf-afs-af-safs-saf-ip-rib-route-table-names-ip-rib-grpc*

```

Can you screenshot the discovery tab when the relevant index pattern?

---

<div class="post-metadata">

**Author:** ![GregoryBrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregorybrown/32/53934_2.png) [@GregoryBrown](https://discuss.elastic.co/u/GregoryBrown)\
**Post date:** [April 15, 2021, 12:52am UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134/3 "2021-04-15T00:52:31Z")

</div>

My index pattern is _grpc_. so it gets all cisco-_grpc_. I can query it via REST API.

---

<div class="post-metadata">

**Author:** ![GregoryBrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregorybrown/32/53934_2.png) [@GregoryBrown](https://discuss.elastic.co/u/GregoryBrown)\
**Post date:** [April 15, 2021, 12:52am UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134/4 "2021-04-15T00:52:58Z")

</div>

`*grpc*` sorry for the confusions

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [April 15, 2021, 12:59am UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134/5 "2021-04-15T00:59:26Z")

</div>

Screenshot of discovery?

---

<div class="post-metadata">

**Author:** ![GregoryBrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregorybrown/32/53934_2.png) [@GregoryBrown](https://discuss.elastic.co/u/GregoryBrown)\
**Post date:** [April 15, 2021, 1:17am UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134/6 "2021-04-15T01:17:57Z")

</div>

![Screen Shot 2021-04-14 at 9.16.44 PM](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b9c3de4e3ff47c3474a428cc501ccd11772c1f28.png) ![Screen Shot 2021-04-14 at 9.16.30 PM](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f7c158e3bc2534fe1da7f96aa15aab76d60e9d06.png)

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [April 15, 2021, 1:39am UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134/7 "2021-04-15T01:39:12Z")

</div>

I see that your data is from yesterday?  
Can you change the time range? e.g. for 24 hours or 48 hours?

Also, you have 0 hits in your query. So not sure what you are after.

---

<div class="post-metadata">

**Author:** ![GregoryBrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregorybrown/32/53934_2.png) [@GregoryBrown](https://discuss.elastic.co/u/GregoryBrown)\
**Post date:** [April 15, 2021, 2:05am UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134/8 "2021-04-15T02:05:59Z")

</div>

Thats the problem I have data in there but I am not seeing the hits with Kibana's standard query. I can manually query using REST API, but with Kibana the request doesn't find the data. The time range doesn't matter as if I set it to last 15 mins/days/weeks Kibana still can't find the data.

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [April 15, 2021, 2:10am UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134/9 "2021-04-15T02:10:06Z")

</div>

so can you show a document for example?

---

<div class="post-metadata">

**Author:** ![GregoryBrown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gregorybrown/32/53934_2.png) [@GregoryBrown](https://discuss.elastic.co/u/GregoryBrown)\
**Post date:** [April 15, 2021, 2:37am UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134/10 "2021-04-15T02:37:43Z")

</div>

```
 "hits": [
            {
                "_index": "cisco-ios-xr-bundlemgr-oper-lacp-bundles-bundles-bundle-members-member-counters-grpc-2021.04.14",
                "_type": "_doc",
                "_id": "Xnqi0XgBngwOqGl4_Mbo",
                "_score": 1.0,
                "_source": {
                    "hostname": "DX",
                    "version": "7.1.2-rev2",
                    "yang_path": "Cisco-IOS-XR-bundlemgr-oper:lacp-bundles/bundles/bundle/members/member/counters",
                    "@timestamp": 1618424758698000000,
                    "keys": {
                        "bundle-interface": "Bundle-Ether10",
                        "member-interface": "HundredGigE0/0/0/0"
                    },
                    "content": {
                        "lacpd-us-received": 330,
                        "lacpd-us-transmitted": 329,
                        "marker-packets-received": 0,
                        "marker-responses-transmitted": 0,
                        "illegal-packets-received": 0,
                        "excess-lacpd-us-received": 0,
                        "excess-marker-packets-received": 0,
                        "defaulted": 2,
                        "expired": 1,
                        "last-cleared-sec": 1967793,
                        "last-cleared-nsec": 448111494
                    }
                }
            }...

```

This is one hit, the index pattern of `*grpc*` should find this

---

<div class="post-metadata">

**Author:** ![AClerk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aclerk/32/55297_2.png) [@AClerk](https://discuss.elastic.co/u/AClerk)\
**Post date:** [April 16, 2021, 1:14am UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134/11 "2021-04-16T01:14:36Z")

</div>

> [@GregoryBrown](#):
>
> `1618424758698000000`

Looks like your timestamp is **nanoseconds (1 billionth of a second)**  
[The supported formats](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-date-format.html#built-in-date-formats)  
Convert to milliseconds will be 1618424758698. i.e. you need to remove the trailing 0 (zero).

Cheers!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2021, 1:14am UTC](https://discuss.elastic.co/t/kibana-unable-to-query-index-data-from-es/270134/12 "2021-05-14T01:14:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
