# Logs Not displaying in kibana while using newly created index but displaying when using default logstash-\*

**URL:** <https://discuss.elastic.co/t/logs-not-displaying-in-kibana-while-using-newly-created-index-but-displaying-when-using-default-logstash/99729>\
**Category:** Elasticsearch\
**Created:** [September 7, 2017, 1:54pm UTC](https://discuss.elastic.co/t/logs-not-displaying-in-kibana-while-using-newly-created-index-but-displaying-when-using-default-logstash/99729 "2017-09-07T13:54:13Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![fazi347](https://avatars.discourse-cdn.com/v4/letter/f/b5e925/32.png) [@fazi347](https://discuss.elastic.co/u/fazi347)\
**Post date:** [September 7, 2017, 1:54pm UTC](https://discuss.elastic.co/t/logs-not-displaying-in-kibana-while-using-newly-created-index-but-displaying-when-using-default-logstash/99729/1 "2017-09-07T13:54:13Z")

</div>

Hi,

i am configured server with fluentd, elasticsearch and kibana to ship logs to server from client node and display in kibana.  
When i am configuring kibana index using default logstash-\* index logs are displaying in kibana, but when i am using the index which i created is not displaying logs in kibana.  
Please help to troubleshoot the issue.  
elasticsearch and kibana version -- 5.x.x

screenshot of non working kibana display:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f75d61dd572e53335848b995c295112ac30091ce.png)

screenshot of working kibana display:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/4/e4f90b74cccaad63a46a81ee37b0e06cdc8029ef.png)

curl -XGET [http://localhost:9200/\_cat/indices?v](http://localhost:9200/_cat/indices?v)  
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
yellow open logstash-2017.09.07 liFB3tS4QcKLqmTGtGs8nQ 5 1 95 0 223.8kb 223.8kb  
yellow open issuepredtool 3mcGPLT7RKSeHslHlPua5w 5 1 0 0 955b 955b  
yellow open fluentd juxdqw3QRNmH0NyMp9ZNTw 5 1 105 0 81.3kb 81.3kb  
yellow open .kibana Z\_EGBqWFSn6wtdhc0mYDsg 1 1 5 0 23.8kb 23.8kb  
yellow open logstash-2017-09-07 IuC0Cn66RFiESfRgCCxCaQ 5 1 0 0 955b 955b  
yellow open test 4DzRjVhhT8KoGTuOrkpSYA 5 1 1 4 4.6kb 4.6kb

* * *

Working index - auto generated  
curl -XGET [http://localhost:9200/logstash-2017.09.07](http://localhost:9200/logstash-2017.09.07)  
{"logstash-2017.09.07":{"aliases":{},"mappings":{"fluentd":{"properties":{"@timestamp":{"type":"date"},"arguments":{"type":"text","fields":{"keyword":{"type":"keyword","ignore\_above":256}}},"issue":{"type":"text","fields":{"keyword":{"type":"keyword","ignore\_above":256}}},"issue\_category":{"type":"text","fields":{"keyword":{"type":"keyword","ignore\_above":256}}},"log\_id":{"type":"long"},"server\_name":{"type":"text","fields":{"keyword":{"type":"keyword","ignore\_above":256}}},"time\_stamp":{"type":"text","fields":{"keyword":{"type":"keyword","ignore\_above":256}}}}}},"settings":{"index":{"creation\_date":"1504778910233","number\_of\_shards":"5","number\_of\_replicas":"1","uuid":"liFB3tS4QcKLqmTGtGs8nQ","version":{"created":"5050299"},"provided\_name":"logstash-2017.09.07"}}}}

Not working- index created by me.  
curl -XGET [http://localhost:9200/issuepredtool](http://localhost:9200/issuepredtool)  
{"issuepredtool":{"aliases":{},"mappings":{"fluentd":{"properties":{"@timestamp":{"type":"date"},"arguments":{"type":"text","fields":{"keyword":{"type":"keyword","ignore\_above":256}}},"issue":{"type":"text","fields":{"keyword":{"type":"keyword","ignore\_above":256}}},"issue\_category":{"type":"text","fields":{"keyword":{"type":"keyword","ignore\_above":256}}},"log\_id":{"type":"long"},"server\_name":{"type":"text","fields":{"keyword":{"type":"keyword","ignore\_above":256}}},"time\_stamp":{"type":"date","fields":{"keyword":{"type":"keyword","ignore\_above":256}}}}}},"settings":{"index":{"creation\_date":"1504781949934","number\_of\_shards":"5","number\_of\_replicas":"1","uuid":"3mcGPLT7RKSeHslHlPua5w","version":{"created":"5050299"},"provided\_name":"issuepredtool"}}}}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 7, 2017, 2:12pm UTC](https://discuss.elastic.co/t/logs-not-displaying-in-kibana-while-using-newly-created-index-but-displaying-when-using-default-logstash/99729/2 "2017-09-07T14:12:09Z")

</div>

> [@fazi347](#):
>
> yellow open issuepredtool 3mcGPLT7RKSeHslHlPua5w 5 1 0 0 955b 955b

It looks like the `issuepredtool` index does not have any data in it.

---

<div class="post-metadata">

**Author:** ![fazi347](https://avatars.discourse-cdn.com/v4/letter/f/b5e925/32.png) [@fazi347](https://discuss.elastic.co/u/fazi347)\
**Post date:** [September 7, 2017, 2:14pm UTC](https://discuss.elastic.co/t/logs-not-displaying-in-kibana-while-using-newly-created-index-but-displaying-when-using-default-logstash/99729/3 "2017-09-07T14:14:34Z")

</div>

I think issuepredtool have data.. please see below output.

curl -i -XHEAD [http://localhost:9200/issuepredtool](http://localhost:9200/issuepredtool)  
HTTP/1.1 200 OK  
content-type: application/json; charset=UTF-8  
content-length: 764

curl -i -XHEAD [http://localhost:9200/logstash-2017.09.07](http://localhost:9200/logstash-2017.09.07)  
HTTP/1.1 200 OK  
content-type: application/json; charset=UTF-8  
content-length: 776

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 7, 2017, 2:18pm UTC](https://discuss.elastic.co/t/logs-not-displaying-in-kibana-while-using-newly-created-index-but-displaying-when-using-default-logstash/99729/4 "2017-09-07T14:18:00Z")

</div>

According to the output from your cat indices call it does not. The index exists, but is empty. Why would running a HEAD request indicate whether the index has data or not?

---

<div class="post-metadata">

**Author:** ![fazi347](https://avatars.discourse-cdn.com/v4/letter/f/b5e925/32.png) [@fazi347](https://discuss.elastic.co/u/fazi347)\
**Post date:** [September 7, 2017, 2:25pm UTC](https://discuss.elastic.co/t/logs-not-displaying-in-kibana-while-using-newly-created-index-but-displaying-when-using-default-logstash/99729/5 "2017-09-07T14:25:06Z")

</div>

i am not sure how to check data.. got some command while searching , that is why ... thanks ..

could you please help why the logs are not loading in to new index (issuepredtool)... but the logs are loading in to default index (logstash-\*).

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 7, 2017, 2:26pm UTC](https://discuss.elastic.co/t/logs-not-displaying-in-kibana-while-using-newly-created-index-but-displaying-when-using-default-logstash/99729/6 "2017-09-07T14:26:56Z")

</div>

There is probably something wrong in your ingest pipeline. Have you checked the logs?

---

<div class="post-metadata">

**Author:** ![fazi347](https://avatars.discourse-cdn.com/v4/letter/f/b5e925/32.png) [@fazi347](https://discuss.elastic.co/u/fazi347)\
**Post date:** [September 7, 2017, 2:31pm UTC](https://discuss.elastic.co/t/logs-not-displaying-in-kibana-while-using-newly-created-index-but-displaying-when-using-default-logstash/99729/7 "2017-09-07T14:31:59Z")

</div>

couldn't see any error logs from fluentd or elasticsearch

---

<div class="post-metadata">

**Author:** ![fazi347](https://avatars.discourse-cdn.com/v4/letter/f/b5e925/32.png) [@fazi347](https://discuss.elastic.co/u/fazi347)\
**Post date:** [September 8, 2017, 4:57am UTC](https://discuss.elastic.co/t/logs-not-displaying-in-kibana-while-using-newly-created-index-but-displaying-when-using-default-logstash/99729/8 "2017-09-08T04:57:15Z")

</div>

i searched the error logs in elasticsearch , fluentd and message logs. i could see only the below error in message log file.

kibana: {"type":"log","@timestamp":"2017-09-07T10:09:58Z","tags":["error","elasticsearch","admin"],"pid":14699,"message":"Request error, retrying\nHEAD [http://localhost:9200/](http://localhost:9200/) =\> connect ECONNREFUSED 127.0.0.1:9200"}  
kibana: {"type":"log","@timestamp":"2017-09-07T10:09:58Z","tags":["status","plugin:elasticsearch@5.5.2","error"],"pid":14699,"state":"red","message":"Status changed from green to red - Unable to connect to Elasticsearch at [http://localhost:9200](http://localhost:9200).","prevState":"green","prevMsg":"Kibana index ready"}  
Sep 7 10:09:58  
kibana: {"type":"log","@timestamp":"2017-09-07T10:09:58Z","tags":["status","ui settings","error"],"pid":14699,"state":"red","message":"Status changed from green to red - Elasticsearch plugin is red","prevState":"green","prevMsg":"Ready"}  
kibana: {"type":"log","@timestamp":"2017-09-07T10:10:08Z","tags":["warning","config"],"pid":31736,"message":"Settings for "network" were not applied, check for spelling errors and ensure the plugin is loaded."}  
{"type":"log","@timestamp":"2017-09-07T10:10:09Z","tags":["error","elasticsearch","admin"],"pid":31736,"message":"Request error, retrying\nHEAD [http://localhost:9200/](http://localhost:9200/) =\> connect ECONNREFUSED 127.0.0.1:9200"}  
kibana: {"type":"log","@timestamp":"2017-09-07T10:10:09Z","tags":["status","plugin:elasticsearch@5.5.2","error"],"pid":31736,"state":"red","message":"Status changed from yellow to red - Unable to connect to Elasticsearch at [http://localhost:9200](http://localhost:9200).","prevState":"yellow","prevMsg":"Waiting for Elasticsearch"}  
kibana: {"type":"log","@timestamp":"2017-09-07T10:10:09Z","tags":["status","ui settings","error"],"pid":31736,"state":"red","message":"Status changed from uninitialized to red - Elasticsearch plugin is red","prevState":"uninitialized","prevMsg":"uninitialized"}  
kibana: {"type":"log","@timestamp":"2017-09-07T13:14:09Z","tags":["error","elasticsearch","admin"],"pid":31736,"message":"Request error, retrying\nHEAD [http://localhost:9200/](http://localhost:9200/) =\> connect ECONNREFUSED 127.0.0.1:9200"}  
kibana: {"type":"log","@timestamp":"2017-09-07T13:14:09Z","tags":["status","plugin:elasticsearch@5.5.2","error"],"pid":31736,"state":"red","message":"Status changed from green to red - Unable to connect to Elasticsearch at [http://localhost:9200](http://localhost:9200).","prevState":"green","prevMsg":"Kibana index ready"}  
elasticsearch: Caused by: com.fasterxml.jackson.dataformat.yaml.snakeyaml.error.MarkedYAMLException: while parsing a block mapping  
elasticsearch: at com.fasterxml.jackson.dataformat.yaml.snakeyaml.error.MarkedYAMLException.from(MarkedYAMLException.java:27)

---

<div class="post-metadata">

**Author:** ![fazi347](https://avatars.discourse-cdn.com/v4/letter/f/b5e925/32.png) [@fazi347](https://discuss.elastic.co/u/fazi347)\
**Post date:** [September 8, 2017, 5:35am UTC](https://discuss.elastic.co/t/logs-not-displaying-in-kibana-while-using-newly-created-index-but-displaying-when-using-default-logstash/99729/9 "2017-09-08T05:35:33Z")

</div>

can we mention some where which index need to use for storing data..

Why the newly created index not loading data and only the auto created logstash-\* only loading data.

can anyone please help on this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 6, 2017, 5:36am UTC](https://discuss.elastic.co/t/logs-not-displaying-in-kibana-while-using-newly-created-index-but-displaying-when-using-default-logstash/99729/10 "2017-10-06T05:36:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
