first: I'm sure this topic comes up frequently but all my searching has been fruitless.
I cannot seem to get Kibana to reflect what is in my indices. Forget live (15 minutes) data, I can't even get it to show the current day's worth of data. I rebuilt my whole environment over the last couple of days and finally fired it up mid-afternoon. It was never current, but it did manage to show data, right up until just after 10PM when it stopped. No new data since then.
In looking at my Elasticsearch index for today, iis-2017.05.11, I see it has over 900K documents. I'm at a complete loss for why I cannot search these in Kibana.
I'm sure it's something simple, and will be obvious to someone else. Please help and Thank you!
(all latest versions)
Filebeats -> REDIS/LOGSTASH -> ELASTICSEARCH (cluster \w 2 injest nodes) <- KIBANA (w/ non-master ES node)
configurations, screenshots, etc available upon request.