# Logstash Index not in Kibana

**URL:** <https://discuss.elastic.co/t/logstash-index-not-in-kibana/136999>\
**Category:** Logstash\
**Created:** [June 22, 2018, 9:21am UTC](https://discuss.elastic.co/t/logstash-index-not-in-kibana/136999 "2018-06-22T09:21:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [June 22, 2018, 9:21am UTC](https://discuss.elastic.co/t/logstash-index-not-in-kibana/136999/1 "2018-06-22T09:21:30Z")

</div>

Hi there,

I've noticed that mu Indexes aren't being added to Kibana anymore. I do have changed my Logstash conf files in the meantime. But still then I would only expect GROK parse failures and not my index to dissapear..  
This is the config:

input {  
udp {  
port =\> 5514  
type =\> syslog  
}

tcp {  
port =\> 5514  
type =\> syslog  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"] index =\> "logstash-syslog" }  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [June 23, 2018, 12:49pm UTC](https://discuss.elastic.co/t/logstash-index-not-in-kibana/136999/2 "2018-06-23T12:49:41Z")

</div>

All seems alright, no more ideas?

[TCPDUMP shows incoming data on correct port]  
[Logstash/Elasticsearch/Kibana instances are running]  
[output debug logs look also good]

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 24, 2018, 9:11pm UTC](https://discuss.elastic.co/t/logstash-index-not-in-kibana/136999/3 "2018-06-24T21:11:34Z")

</div>

So you've verified that the ES instance on localhost:9200 doesn't have a logstash-syslog index with the current data? How did you reach that conclusion?

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [June 25, 2018, 9:36am UTC](https://discuss.elastic.co/t/logstash-index-not-in-kibana/136999/4 "2018-06-25T09:36:56Z")

</div>

This one has been solved, it was a local firewall issue 😊

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2018, 9:37am UTC](https://discuss.elastic.co/t/logstash-index-not-in-kibana/136999/5 "2018-07-23T09:37:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
