# Kibana4 not working with documents send via python into ElasticSearch

**URL:** <https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918>\
**Category:** Kibana\
**Created:** [January 11, 2016, 8:47pm UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918 "2016-01-11T20:47:16Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![nicolas\_merle](https://avatars.discourse-cdn.com/v4/letter/n/87869e/32.png) [@nicolas\_merle](https://discuss.elastic.co/u/nicolas_merle)\
**Post date:** [January 11, 2016, 8:47pm UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/1 "2016-01-11T20:47:16Z")

</div>

Hello,

I am trying to implement an ElasticSearch server to store and display analysis of https answer.  
What I'm doing is that I send all the documents via python with the following code :

```
i = 0
for answer in answers:
  query = json.dumps(answer)
  url = "http://localhost:9200/piccolo-" + str(answer["campaign"]) + "/answer/" + str(i)
  response = requests.post(url, data=query)
  i += 1
return redirect("/", code=302)

```

which send a packet like this to the ElasticSearch server :

```
`#@l#FdnV+

U
UPOST /piccolo-0/answer/1023 HTTP/1.1 
Host: localhost:9200 
Content-Length: 584 
User-Agent: python-requests/2.9.1 
Connection: keep-alive 
Accept: */* 
Accept-Encoding: gzip, deflate 
 
{"trust_flag": "trusted", "alert_type": "", "ordered": 0, "campaign": 0, "grade": "D", "ip": "104.20.77.29", "type_str": "TLS 1.2 Handshake (49195)", "complete": 1, "chain_hash": "174bb3c4415d932d291569cd123a9f9f58ec16d9", "version": 771, "answer_type": 21, "type": "TLS 1.2 Handshake (49195)", "ciphersuite": 49195, "timestamp_str": "2015-12-16 10:01:36", "timestamp": 1450260096, "alert_level": "", "date": "2015-12-16 10:01:36", "_timestamp": 1450260096, "name": "txxx.com", "n_transvalid": 2, "rfc": 1, "cipherphrase": "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256", "chain_length": 6}

```

And when I try to get the document with the rest API, I get something like this :

```
{
  "_index": "piccolo-0",
  "_type": "answer",
  "_id": "1",
  "_version": 1,
  "_timestamp": 1450260096,
  "found": true,
  "_source": {
    "trust_flag": "trusted",
    "alert_type": "",
    "ordered": 1,
    "campaign": 0,
    "grade": "B",
    "ip": "23.3.13.42",
    "type_str": "TLS 1.2 Handshake (49199)",
    "complete": 1,
    "chain_hash": "5e66cc799c18d0c05e339f9314e904527cf1e8f7",
    "version": 771,
    "answer_type": 21,
    "type": "TLS 1.2 Handshake (49199)",
    "ciphersuite": 49199,
    "timestamp_str": "2015-12-16 10:01:36",
    "timestamp": 1450260096,
    "alert_level": "",
    "date": "2015-12-16 10:01:36",
    "_timestamp": 1450260096,
    "name": "target.com",
    "n_transvalid": 0,
    "rfc": 0,
    "cipherphrase": "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256",
    "chain_length": 3
  }
} 

```

Which is what I want, but I didn't find the way to visualize all those documents into Kibana4.

Thanks in advance for all the help you will provide me 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 12, 2016, 2:59am UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/2 "2016-01-12T02:59:25Z")

</div>

> [@nicolas\_merle](#):
>
> Which is what I want, but I didn't find the way to visualize all those documents into Kibana4.

What do you mean here, how do you want to visualise them?

---

<div class="post-metadata">

**Author:** ![nicolas\_merle](https://avatars.discourse-cdn.com/v4/letter/n/87869e/32.png) [@nicolas\_merle](https://discuss.elastic.co/u/nicolas_merle)\
**Post date:** [January 12, 2016, 4:12am UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/3 "2016-01-12T04:12:00Z")

</div>

Sorry, what I meant is that I just want to visualize them. When I go to kibana, I can choose the default index but I don't get any timestamp choice, and even when I add \_timestamp in the metafields, kibana doesn't found any doc.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 12, 2016, 8:45am UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/4 "2016-01-12T08:45:05Z")

</div>

Can you see the timestamp field in the mapping?

---

<div class="post-metadata">

**Author:** ![nicolas\_merle](https://avatars.discourse-cdn.com/v4/letter/n/87869e/32.png) [@nicolas\_merle](https://discuss.elastic.co/u/nicolas_merle)\
**Post date:** [January 12, 2016, 10:08am UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/5 "2016-01-12T10:08:09Z")

</div>

Here is the mapping that I get in Kibana4 if it is the one you are speaking about.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1c7b864fc96c323f789bb0156870eb69b050fa53.png)

Here is the result of this command:

`curl -XGET 'http://localhost:9200/piccolo-0/_mapping/answer`

and I get

```
{
  "piccolo-0": {
    "mappings": {
      "answer": {
        "properties": {
          "_timestamp": {
            "type": "date",
            "store": true,
            "format": "strict_date_optional_time||epoch_millis"
          },
          "alert_level": {
            "type": "string"
          },
          "alert_type": {
            "type": "string"
          },
          "answer_type": {
            "type": "long"
          },
          "campaign": {
            "type": "long"
          },
          "chain_hash": {
            "type": "string"
          },
          "chain_length": {
            "type": "long"
          },
          "cipherphrase": {
            "type": "string"
          },
          "ciphersuite": {
            "type": "long"
          },
          "complete": {
            "type": "long"
          },
          "date": {
            "type": "string"
          },
          "grade": {
            "type": "string"
          },
          "ip": {
            "type": "string"
          },
          "n_transvalid": {
            "type": "long"
          },
          "name": {
            "type": "string"
          },
          "ordered": {
            "type": "long"
          },
          "rfc": {
            "type": "long"
          },
          "timestamp": {
            "type": "long"
          },
          "timestamp_str": {
            "type": "string"
          },
          "trust_flag": {
            "type": "string"
          },
          "type": {
            "type": "string"
          },
          "type_str": {
            "type": "string"
          },
          "version": {
            "type": "long"
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 12, 2016, 9:40pm UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/6 "2016-01-12T21:40:04Z")

</div>

You can see the KB has picked the `_timestamp` field automatically (as evidenced by the little clock icon beside the field name).

When you go into discover, did you set the time range correctly?

---

<div class="post-metadata">

**Author:** ![nicolas\_merle](https://avatars.discourse-cdn.com/v4/letter/n/87869e/32.png) [@nicolas\_merle](https://discuss.elastic.co/u/nicolas_merle)\
**Post date:** [January 12, 2016, 11:42pm UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/7 "2016-01-12T23:42:07Z")

</div>

I tried to put the largest range possible. But even with 5 years it doesn't work.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 13, 2016, 12:39am UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/8 "2016-01-13T00:39:12Z")

</div>

And you changed the index pattern, on the left near the top.

---

<div class="post-metadata">

**Author:** ![nicolas\_merle](https://avatars.discourse-cdn.com/v4/letter/n/87869e/32.png) [@nicolas\_merle](https://discuss.elastic.co/u/nicolas_merle)\
**Post date:** [January 13, 2016, 12:48am UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/9 "2016-01-13T00:48:46Z")

</div>

I have only one index pattern....

Here is a screenshot I took, I took a very big time range but still nothing

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/c78a07380c24963bf4d79a42bbfacc7223bdb386.png)

and all the piccolo-\* index are selected

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 13, 2016, 10:24am UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/10 "2016-01-13T10:24:13Z")

</div>

What's the output from `_cat/indices` show?

---

<div class="post-metadata">

**Author:** ![nicolas\_merle](https://avatars.discourse-cdn.com/v4/letter/n/87869e/32.png) [@nicolas\_merle](https://discuss.elastic.co/u/nicolas_merle)\
**Post date:** [January 13, 2016, 11:00am UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/11 "2016-01-13T11:00:44Z")

</div>

Here is the output :

```
"yellow open piccolo-13012016 5 1 2242 0 1.1mb 1.1mb 
yellow open .kibana 1 1 2 0 5kb 5kb 
" 

```

It's not piccolo-0 anymore but it is the same structure.

---

<div class="post-metadata">

**Author:** ![nicolas\_merle](https://avatars.discourse-cdn.com/v4/letter/n/87869e/32.png) [@nicolas\_merle](https://discuss.elastic.co/u/nicolas_merle)\
**Post date:** [January 13, 2016, 3:12pm UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/12 "2016-01-13T15:12:25Z")

</div>

I think I will give up and go with logstash instead. Thanks again for all the help you gave me 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:05pm UTC](https://discuss.elastic.co/t/kibana4-not-working-with-documents-send-via-python-into-elasticsearch/38918/13 "2017-07-06T14:05:09Z")

</div>


