# No logstash data showing up in kibana

**URL:** <https://discuss.elastic.co/t/no-logstash-data-showing-up-in-kibana/251471>\
**Category:** Kibana\
**Created:** [October 8, 2020, 3:13pm UTC](https://discuss.elastic.co/t/no-logstash-data-showing-up-in-kibana/251471 "2020-10-08T15:13:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jimmyacuna](https://avatars.discourse-cdn.com/v4/letter/j/8491ac/32.png) [@jimmyacuna](https://discuss.elastic.co/u/jimmyacuna)\
**Post date:** [October 8, 2020, 3:13pm UTC](https://discuss.elastic.co/t/no-logstash-data-showing-up-in-kibana/251471/1 "2020-10-08T15:13:46Z")

</div>

I have just installed a new ELK stack instance but I cant figure out what I am missing. By default filebeats were being sent and that worked. I dont intend to use filebeats as since Im mainly collecting syslogs from network devices such as routers that wont have a filebeat client. I have built up logstash to accept UDP from the source with an output to Elasticsearch as well as to a file to verify the logstash piece is working. Data seems be getting indexed for logstash on elasticsearch but nothing shows up in the discover tab.

here is mylogstash config

> Blockquote

# Sample Logstash configuration for creating a simple

# Beats -\> Logstash -\> Elasticsearch pipeline.

input {  
tcp {  
port =\> 5002  
type =\> "cradlepoint"  
}  
udp {  
port =\> 5002  
type =\> "cradlepoint"  
}

# beats {

# port =\> 5044

# }

file {  
path =\> "/var/log/syslog-ng"  
start\_position =\> "beginning"  
type =\> "syslog"  
}

}

filter {

if [type] == "syslog-ng"{  
grok {  
match =\> { "message" =\> "%{SYSLOGLINE}"}  
}  
date {  
match =\> ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

# else if [type] == "syslog" {

# grok {

# match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }

# add\_field =\> ["received\_at", "%{@timestamp}"]

# add\_field =\> ["received\_from", "%{host}"]

# }

# date {

# match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]

# }

# }

#}

output {

#stdout { codec =\> rubydebug}

elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false

# index =\> "syslog-ng%{+YYY.MM.dd}"

```
index => "logstash-%{+YYYY.MM.dd}"

```

# index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"

# index =\> "%{[@metadata][index]}"

# document\_type =\> "system\_logs"

}

file { path =\> "/tmp/logstash.log"}

}

> Blockquote

 ![Screen Shot 2020-10-08 at 9.06.00 AM](https://us1.discourse-cdn.com/elastic/original/3X/d/d/dd1d0ec9af0116d767ca4aea2c4d985cb2db4b98.png)

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [October 9, 2020, 7:03am UTC](https://discuss.elastic.co/t/no-logstash-data-showing-up-in-kibana/251471/2 "2020-10-09T07:03:14Z")

</div>

Hi,

Are you able to see the data with a `GET logstash-*/_search` (you can use the [Dev Tools](https://www.elastic.co/guide/en/kibana/current/console-kibana.html) for this).

Did you create an [index pattern](https://www.elastic.co/guide/en/kibana/current/index-patterns.html) in Kibana for the logstash-\* indexes?

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![jimmyacuna](https://avatars.discourse-cdn.com/v4/letter/j/8491ac/32.png) [@jimmyacuna](https://discuss.elastic.co/u/jimmyacuna)\
**Post date:** [October 9, 2020, 1:02pm UTC](https://discuss.elastic.co/t/no-logstash-data-showing-up-in-kibana/251471/3 "2020-10-09T13:02:19Z")

</div>

When running the GET logstash-_/\_search I do see a few logs there but only like 4. And yes I have created the logstash-_ index and have attached a screenshot.

 ![Screen Shot 2020-10-09 at 7.01.03 AM](https://us1.discourse-cdn.com/elastic/original/3X/1/6/161947cbee5d94316520de4f875be9be217f81f4.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2020, 1:02pm UTC](https://discuss.elastic.co/t/no-logstash-data-showing-up-in-kibana/251471/4 "2020-11-06T13:02:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
