# Need help with filebeat and Kibana index pattern creation

**URL:** <https://discuss.elastic.co/t/need-help-with-filebeat-and-kibana-index-pattern-creation/274243>\
**Category:** Kibana\
**Created:** [May 27, 2021, 5:16pm UTC](https://discuss.elastic.co/t/need-help-with-filebeat-and-kibana-index-pattern-creation/274243 "2021-05-27T17:16:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![byoungman](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@byoungman](https://discuss.elastic.co/u/byoungman)\
**Post date:** [May 27, 2021, 5:16pm UTC](https://discuss.elastic.co/t/need-help-with-filebeat-and-kibana-index-pattern-creation/274243/1 "2021-05-27T17:16:56Z")

</div>

I was out on vacation last week and while I was out there was an issue with one of our kibana index patterns getting corrupted (for lack of a better term).

We have a 'responseTime' stamp in our incoming payload that we set for our primary time field and up until May 14th it was working fine (see below)

 ![kibana-index-pattern-0514](https://us1.discourse-cdn.com/elastic/original/3X/a/d/adaee9e6119c74166c7289814072d05f1edd4d76.png)

Then at midnight on May 15th something happened that caused this pattern to get corrupted which I still haven't figured out but my main priority is getting this pattern working again. Below is what is showing when you try to create a new index pattern

 ![kibana-index-pattern-0515](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cd987ceda424e0410d8f39141743a28e5bffc4e1.png)

I recreated the index template in the Index Management area and it looks fine and when I do a search from within the Dev area the results are as I would expect which is showing customer payload information but trying to create a new index pattern isn't working.

Here is a copy of my mappings for the index (you can see the responseTime field about 1/2 way down --

{  
"\_doc": {  
"\_meta": {  
"beat": "filebeat",  
"version": "7.1.1"  
},  
"dynamic\_templates": ,  
"date\_detection": false,  
"properties": {  
"trustedId": {  
"ignore\_above": 1024,  
"type": "keyword"  
},  
"@timestamp": {  
"type": "date"  
},  
"payload": {  
"norms": false,  
"type": "text"  
},  
"responseTime": {  
"type": "date"  
},  
"amazonTraceId": {  
"norms": false,  
"type": "text"  
},  
"uuid": {  
"ignore\_above": 1024,  
"type": "keyword"  
},  
"podId": {  
"ignore\_above": 1024,  
"type": "keyword"  
}  
}  
}  
}

I've tried everything I can think of short of blowing everything away and starting over from scratch and am at a loss as to how or where to proceed so any and all help is appreciated.

TIA,  
Bill Youngman

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 27, 2021, 11:42pm UTC](https://discuss.elastic.co/t/need-help-with-filebeat-and-kibana-index-pattern-creation/274243/2 "2021-05-27T23:42:07Z")

</div>

It looks like maybe a Filebeat module is loading template information into Elasticsearch. Or something else is writing data into that index and creating the extra fields.

Are there other instances of Filebeat running anywhere?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2021, 11:42pm UTC](https://discuss.elastic.co/t/need-help-with-filebeat-and-kibana-index-pattern-creation/274243/3 "2021-06-24T23:42:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
