# Misconfigured dashboards?

**URL:** <https://discuss.elastic.co/t/misconfigured-dashboards/121875>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 28, 2018, 3:21pm UTC](https://discuss.elastic.co/t/misconfigured-dashboards/121875 "2018-02-28T15:21:50Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![QuizzyRascal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/quizzyrascal/32/27900_2.png) [@QuizzyRascal](https://discuss.elastic.co/u/QuizzyRascal)\
**Post date:** [February 28, 2018, 3:21pm UTC](https://discuss.elastic.co/t/misconfigured-dashboards/121875/1 "2018-02-28T15:21:50Z")

</div>

I have built a syslog receiver using ELK 6.2.1, which works great.

Logstash receives syslog data and pushes it into ES and then I can use discover to see the logs coming in via Kibana.

I read somewhere that there are some default dashboards in filebeat that would allow me to see more in Kibana.

So I have installed filebeat on my single ELK server and I edited the following in filebeat.yml:

In paths:

- /var/log/_.log  
was changed to /var/lib/logstash/_.log

In the Dashboards section:  
setup.dashboards.enabled: true

In the Kibana section  
I added  
setup.kibana:  
host: "localhost:5601

I then ran the filebeat setup and installed it successfully (well I got no errors)

I then when into Kibana and saw lots of new dashboards but also got the following message on the top status bar:

No matching indices found: No indices match pattern "filebeat-\*"

All my syslog data comes into Kibana with Logstash\* and @timestamp.

Can anyone tell me what else I may need to do to the filebeat.yml file to be able to use the syslog dashboard with my syslog files within logstash?

All help is appreciated,  
QR

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [February 28, 2018, 7:54pm UTC](https://discuss.elastic.co/t/misconfigured-dashboards/121875/2 "2018-02-28T19:54:45Z")

</div>

I believe the problem is that Logstash is creating an index named differently than "filebeat-\*".

Have you followed the [logstash output docs](https://www.elastic.co/guide/en/beats/filebeat/current/logstash-output.html)? It's easy to misconfigure it.

---

<div class="post-metadata">

**Author:** ![QuizzyRascal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/quizzyrascal/32/27900_2.png) [@QuizzyRascal](https://discuss.elastic.co/u/QuizzyRascal)\
**Post date:** [February 28, 2018, 8:22pm UTC](https://discuss.elastic.co/t/misconfigured-dashboards/121875/3 "2018-02-28T20:22:55Z")

</div>

Thank you for your thoughts... but I’m not using filebeats for anything other than to get to the dashboards.

I receive native syslog from network components like fw, routers, etc straight into logstash

If I’m not using filebeats can I still use the dashboards in Kibana?

I’ve no interest in filebeats for clients as they don’t suit my use cases.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [February 28, 2018, 11:23pm UTC](https://discuss.elastic.co/t/misconfigured-dashboards/121875/4 "2018-02-28T23:23:09Z")

</div>

I don't think the dashboards will work with documents that are not generated by filebeat as they won't have the required fields.

But I may be wrong, so you can try setting an index pattern in Kibana that matches the indexes created by logstash.

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [March 1, 2018, 8:38am UTC](https://discuss.elastic.co/t/misconfigured-dashboards/121875/5 "2018-03-01T08:38:40Z")

</div>

You might want to try this solution as a starting point for collecting syslog data...

> **[koiossian/synesis\_lite\_syslog](https://github.com/koiossian/synesis_lite_syslog)**
>
> synesis\_lite\_syslog - Syslog collection with Elastic Stack

---

<div class="post-metadata">

**Author:** ![QuizzyRascal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/quizzyrascal/32/27900_2.png) [@QuizzyRascal](https://discuss.elastic.co/u/QuizzyRascal)\
**Post date:** [March 1, 2018, 9:29am UTC](https://discuss.elastic.co/t/misconfigured-dashboards/121875/6 "2018-03-01T09:29:55Z")

</div>

Wow that looks just what I’m looking for 😁  
When I installed Kibaba I was asked to create an index and offered logstash\*. Can I create a syslog-\* as well?

Thanks  
QR

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [March 1, 2018, 9:54am UTC](https://discuss.elastic.co/t/misconfigured-dashboards/121875/7 "2018-03-01T09:54:27Z")

</div>

@QuizzyRascal as you dig into this more, you will realize that there are four things that have to work together...

1. Logstash Pipelines
2. Elasticsearch Index Templates
3. Kibana Index Patterns
4. Kibana Dashboards

The material in this repository walks through a more in depth example...

> **[robcowart/eslog\_tutorial](https://github.com/robcowart/eslog_tutorial)**
>
> eslog\_tutorial - From Raw Logs to Real Insights - A tutorial for getting started with log analytics using Elastic Stack.

Even more advanced deployments, will consider normalizing sources to a common data model, which allows for analytics and visualization of a heterogenous environment with a common set up tools and dashboards. Providing such solutions in a turnkey package, are what we provide for our customers.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2018, 9:54am UTC](https://discuss.elastic.co/t/misconfigured-dashboards/121875/8 "2018-03-29T09:54:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
