# No Logs appearing in Kibana

**URL:** <https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208>\
**Category:** Kibana\
**Created:** [June 16, 2023, 9:54am UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208 "2023-06-16T09:54:03Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 16, 2023, 9:54am UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/1 "2023-06-16T09:54:03Z")

</div>

![kibana](https://us1.discourse-cdn.com/elastic/original/3X/1/6/16c6f11f8343ceff354c2add75ca0866e9980309.png)  
Those are my statistics. When I tcpdump port 5044 I see traffic coming from the host where I have winlogbeat running and when I tcpdump port 9200 on the server I see a lot of traffic. So I suppose Data is reaching elasticsearch. I also see the number of Documents increasing at the dashboard, but I cannot get Kibana to show me any actual event logs. What am I missing?

At the Dashboard it says I need an Index Pattern. I installed a "Custom Windows Event Logs" integration, but I am not really sure what that is.

---

<div class="post-metadata">

**Author:** ![chinmoy\_padhi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chinmoy_padhi/32/68568_2.png) [@chinmoy\_padhi](https://discuss.elastic.co/u/chinmoy_padhi)\
**Post date:** [June 16, 2023, 11:04am UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/2 "2023-06-16T11:04:14Z")

</div>

_At the Dashboard it says I need an Index Pattern. I installed a "Custom Windows Event Logs" integration, but I am not really sure what that is._

Go to your Kibana UI --\> Stack Management --\> Kibana --\> Index Pattern  
this is where you need to create Index Pattern for created index which are coming from winlogbeat

---

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 16, 2023, 11:37am UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/3 "2023-06-16T11:37:50Z")

</div>

When I do so, it says "Ready to try Kibana? First you need data." And it asks me to add an integration. Somehow the data is not recognized or I need to configure something differently. But I dont know what to look for

---

<div class="post-metadata">

**Author:** ![chinmoy\_padhi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chinmoy_padhi/32/68568_2.png) [@chinmoy\_padhi](https://discuss.elastic.co/u/chinmoy_padhi)\
**Post date:** [June 16, 2023, 12:24pm UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/4 "2023-06-16T12:24:41Z")

</div>

Usually the log integration flow is like:  
Filebeat/Logbeat --\>Logstash--\>Elasticsearch--\>Kibana  
Make sure your Logbeat should be running as an instance on every node,which will push the log to logstash collector and then to logstash indexer later towards Elasticsearch and finally to Kibana to view the logs

---

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 16, 2023, 12:25pm UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/5 "2023-06-16T12:25:23Z")

</div>

![issue](https://us1.discourse-cdn.com/elastic/original/3X/b/1/b1a9d8baea76c43af7e942ba13f625f3dca7efe5.png)  
This might be part of the issue

---

<div class="post-metadata">

**Author:** ![chinmoy\_padhi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chinmoy_padhi/32/68568_2.png) [@chinmoy\_padhi](https://discuss.elastic.co/u/chinmoy_padhi)\
**Post date:** [June 16, 2023, 12:28pm UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/6 "2023-06-16T12:28:28Z")

</div>

You can add username ,password to curl command

_For example: curl -X GET -u username:password localhost:9200/\_cat/indices?v_

---

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 16, 2023, 12:33pm UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/7 "2023-06-16T12:33:29Z")

</div>

Okay, now I see some indices. However, these look like default ones. There is nothing that seems to be related to the winlogbeat data I want to process.  
 ![indices](https://us1.discourse-cdn.com/elastic/original/3X/4/5/4506657b41d3dcf6cad33ea89eece0de36227708.png)

In /etc/logstash/conf.d/30-elasticsearch-output.conf I have defined  
index =\> "testindex"  
but in Kibana I see that the index is not created.

When doing a "tcpdump dst port 9200" I do not see any traffic anymore.

---

<div class="post-metadata">

**Author:** ![chinmoy\_padhi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chinmoy_padhi/32/68568_2.png) [@chinmoy\_padhi](https://discuss.elastic.co/u/chinmoy_padhi)\
**Post date:** [June 16, 2023, 1:01pm UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/8 "2023-06-16T13:01:26Z")

</div>

check your log beat logs and logstash logs for the bottleneck

---

<div class="post-metadata">

**Author:** ![chinmoy\_padhi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chinmoy_padhi/32/68568_2.png) [@chinmoy\_padhi](https://discuss.elastic.co/u/chinmoy_padhi)\
**Post date:** [June 16, 2023, 1:10pm UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/9 "2023-06-16T13:10:01Z")

</div>

_When doing a "tcpdump dst port 9200" I do not see any traffic anymore._

Are you sure tcp port is 9200,I think it might be 9300, I presume 9200 is the API listening port of elasticsearch. Can you check that

---

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 16, 2023, 1:19pm UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/10 "2023-06-16T13:19:54Z")

</div>

I actually wanted to check on the API Port. Anyhow, I think i got closer to the issue. A tcpdump at port 5044 shows only keepalive packets, but no log data being sent. In my winlogbeat config I have configured logstash port 5044 as my output target.

---

<div class="post-metadata">

**Author:** ![chinmoy\_padhi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chinmoy_padhi/32/68568_2.png) [@chinmoy\_padhi](https://discuss.elastic.co/u/chinmoy_padhi)\
**Post date:** [June 16, 2023, 1:22pm UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/11 "2023-06-16T13:22:17Z")

</div>

Make sure your "testindex" is reaching to elasticsearch first then later you can think of Kibana

---

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 16, 2023, 1:57pm UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/12 "2023-06-16T13:57:28Z")

</div>

In the elasticsearch config I have these settings:  
network.host: localhost  
http.port: 9200

And my logstash configs look like this:  
 ![input](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e83f45ac69911ed2d02f306d478a669dcf8ec08c.png)

There is no data arriving at elasticsearch. The logs of logstash and elasticsearch show no new messages

---

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 16, 2023, 1:59pm UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/13 "2023-06-16T13:59:29Z")

</div>

That is the output config

 ![output](https://us1.discourse-cdn.com/elastic/original/3X/8/9/899895ddaa6ef9b2f30e9a40734890fc0a0316ba.png)

---

<div class="post-metadata">

**Author:** ![chinmoy\_padhi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chinmoy_padhi/32/68568_2.png) [@chinmoy\_padhi](https://discuss.elastic.co/u/chinmoy_padhi)\
**Post date:** [June 16, 2023, 2:07pm UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/14 "2023-06-16T14:07:33Z")

</div>

please check the logs for winlogbeat and logstash and does their any kind of redis is running which will cache the logs(just for curiosity)  
Also if you felt your configurations are fine then you can restart all the nodes, just to check incase, you receive any new logs or not

---

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 19, 2023, 7:50am UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/15 "2023-06-19T07:50:12Z")

</div>

Actually, I think my configs were right, even before the weekend. I restarted all nodes as you said and now I can access the Data. Thank you very much for your support!

---

<div class="post-metadata">

**Author:** ![chinmoy\_padhi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chinmoy_padhi/32/68568_2.png) [@chinmoy\_padhi](https://discuss.elastic.co/u/chinmoy_padhi)\
**Post date:** [June 19, 2023, 8:21am UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/16 "2023-06-19T08:21:27Z")

</div>

Thanks for your confirmation, could you please thumbs up or mark that as Solution

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2023, 8:22am UTC](https://discuss.elastic.co/t/no-logs-appearing-in-kibana/336208/17 "2023-07-17T08:22:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
