# Logs are not reflecting in Kibana

**URL:** <https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684>\
**Category:** Elasticsearch\
**Created:** [February 27, 2021, 9:24am UTC](https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684 "2021-02-27T09:24:25Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![roh689](https://avatars.discourse-cdn.com/v4/letter/r/439d5e/32.png) [@roh689](https://discuss.elastic.co/u/roh689)\
**Post date:** [February 27, 2021, 9:24am UTC](https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684/1 "2021-02-27T09:24:25Z")

</div>

In our ELK environment, we are not seeing any issues on elasticsearch and Logstash server. We can also see logs are receiving on Logstash side, but it is not reflecting in index on Kibana side.

Can anyone suggest what would be the possible reasons for that ? How we can check logs are receiving on Elasticsearch database ?

---

<div class="post-metadata">

**Author:** ![roh689](https://avatars.discourse-cdn.com/v4/letter/r/439d5e/32.png) [@roh689](https://discuss.elastic.co/u/roh689)\
**Post date:** [February 28, 2021, 6:53am UTC](https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684/2 "2021-02-28T06:53:32Z")

</div>

can anyone suggest on this issue ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 28, 2021, 7:54am UTC](https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684/3 "2021-02-28T07:54:42Z")

</div>

You have not provided any details about your cluster or overall configuration so it is very hard for anyone to help. What does the full ingest flow look like? What is the full output of the [cluster stats API](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/cluster-stats.html)? Which version of Elasticsearch are you using?

---

<div class="post-metadata">

**Author:** ![roh689](https://avatars.discourse-cdn.com/v4/letter/r/439d5e/32.png) [@roh689](https://discuss.elastic.co/u/roh689)\
**Post date:** [February 28, 2021, 5:46pm UTC](https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684/4 "2021-02-28T17:46:29Z")

</div>

Can you suggest how to search 'syslog' logs through search query from dev tools in Kibana ? we can able to see winlogbeat related logs in indexes but syslog logs are not reflecting.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 28, 2021, 11:29pm UTC](https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684/5 "2021-02-28T23:29:20Z")

</div>

Unless you can provide more information as Christian indicated, we are just guessing.

---

<div class="post-metadata">

**Author:** ![roh689](https://avatars.discourse-cdn.com/v4/letter/r/439d5e/32.png) [@roh689](https://discuss.elastic.co/u/roh689)\
**Post date:** [March 2, 2021, 7:48am UTC](https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684/6 "2021-03-02T07:48:13Z")

</div>

We are getting below error in Logstash

Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"azure\_event\_hub-2021.03.02", :routing  
=\>nil, :\_type=\>"\_doc"}, #LogStash::Event:0x7d41709f], :response=\>{"index"=\>{"\_index"=\>"azure\_event\_hub-2021.03.02", "\_type"=\>"\_doc",  
"\_id"=\>"hn7k8XcBxp4QSwaxyn21", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"object mapping for [host] tried  
to parse field [host] as object, but found a concrete value"}}}}

Kindly suggest.

---

<div class="post-metadata">

**Author:** ![roh689](https://avatars.discourse-cdn.com/v4/letter/r/439d5e/32.png) [@roh689](https://discuss.elastic.co/u/roh689)\
**Post date:** [March 3, 2021, 6:11am UTC](https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684/7 "2021-03-03T06:11:19Z")

</div>

Can anyone suggest for the above Warning error that we are getting on Logstash ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 3, 2021, 7:04am UTC](https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684/8 "2021-03-03T07:04:39Z")

</div>

It's telling you that the value that it is trying to insert doesn't match the mapping.  
So what's the mapping for that index?

---

<div class="post-metadata">

**Author:** ![roh689](https://avatars.discourse-cdn.com/v4/letter/r/439d5e/32.png) [@roh689](https://discuss.elastic.co/u/roh689)\
**Post date:** [March 3, 2021, 12:17pm UTC](https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684/9 "2021-03-03T12:17:20Z")

</div>

can you guide how I can check the mapping ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 3, 2021, 10:25pm UTC](https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684/10 "2021-03-03T22:25:33Z")

</div>

`GET azure_event_hub-2021.03.02/_mapping`.

Please format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2021, 10:25pm UTC](https://discuss.elastic.co/t/logs-are-not-reflecting-in-kibana/265684/11 "2021-03-31T22:25:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
