# Logstash filter kv fortinet not searchable into kibana

**URL:** https://discuss.elastic.co/t/logstash-filter-kv-fortinet-not-searchable-into-kibana/187367
**Category:** Logstash
**Created:** [June 25, 2019, 2:30pm UTC](https://discuss.elastic.co/t/logstash-filter-kv-fortinet-not-searchable-into-kibana/187367 "2019-06-25T14:30:50Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![temuccio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/temuccio/32/121070_2.png) [@temuccio](https://discuss.elastic.co/u/temuccio)
#### Post date: [June 25, 2019, 2:30pm UTC](https://discuss.elastic.co/t/logstash-filter-kv-fortinet-not-searchable-into-kibana/187367/1 "2019-06-25T14:30:50Z")

</div>

Hello all,  
I have try to run stack ELK for fortinet's syslog.  
It's works and on kibana I see the log, but almost all fields are not searchable and they have a ❓ before the name... 🤔  
I have used on logstash kv filter and in this mode:

```auto
filter {
   kv {
       source => "message"
   }
}
```

It's works fine because find all key and value but in kibana it is not searchable...

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [June 25, 2019, 2:44pm UTC](https://discuss.elastic.co/t/logstash-filter-kv-fortinet-not-searchable-into-kibana/187367/2 "2019-06-25T14:44:14Z")

</div>

Sounds like you need to refresh the index pattern.

---

<div class="post-metadata">

### Author: ![temuccio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/temuccio/32/121070_2.png) [@temuccio](https://discuss.elastic.co/u/temuccio)
#### Post date: [June 25, 2019, 9:54pm UTC](https://discuss.elastic.co/t/logstash-filter-kv-fortinet-not-searchable-into-kibana/187367/3 "2019-06-25T21:54:28Z")

</div>

Hello @Badger, in **Kibana settings** , under **Index management** of elasticsearch I have select the index and select **Refresh Index** but the problem is the same...  
It is necessary drop the current index? For me this solution it isn't a problem...

---

<div class="post-metadata">

### Author: ![temuccio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/temuccio/32/121070_2.png) [@temuccio](https://discuss.elastic.co/u/temuccio)
#### Post date: [June 26, 2019, 4:08am UTC](https://discuss.elastic.co/t/logstash-filter-kv-fortinet-not-searchable-into-kibana/187367/4 "2019-06-26T04:08:57Z")

</div>

Hi @Badger, I have solved 🎉🎉  
It is necessary refresh the index of kibana, not elasticsearch.  
Thanks a lot for suggestion.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 24, 2019, 4:09am UTC](https://discuss.elastic.co/t/logstash-filter-kv-fortinet-not-searchable-into-kibana/187367/5 "2019-07-24T04:09:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
