# No Output shown on kibana

**URL:** <https://discuss.elastic.co/t/no-output-shown-on-kibana/297443>\
**Category:** Kibana\
**Created:** [February 17, 2022, 7:11am UTC](https://discuss.elastic.co/t/no-output-shown-on-kibana/297443 "2022-02-17T07:11:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [February 17, 2022, 7:11am UTC](https://discuss.elastic.co/t/no-output-shown-on-kibana/297443/1 "2022-02-17T07:11:43Z")

</div>

Hi, I have parsed a few sample syslog messages through logstash. I am receiving the right output on the logstash cmd but nothing is displayed on the kibana dashboard.  
I need help in figuring out how to get the same.  
This is my conf file-

```auto
input { 
  file {
      path => "C:/elk stack/samples.log"
      start_position => "beginning"
      type => "syslog"
  }
}

filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    syslog_pri {}
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}

output {
  elasticsearch { # output to ES
    hosts => ["localhost:9200"]
    index => "indexforsyslog17"
  }
  stdout { codec => "rubydebug" }
}

```

These are the sample syslog messages-

```auto
Dec 23 12:11:46 louis postfix/smtpd[31499]: connect from unknown[95.75.93.154]
Dec 23 14:42:59 louis named[16000]: client 199.48.164.7#64817: query (cache) 'amsterdamboothuren.com/MX/IN' denied

```

The output on my logstash powershell is -

```auto
{
              "@timestamp" => 2022-12-23T06:41:46.000Z,
                 "message" => "Dec 23 12:11:46 louis postfix/smtpd[31499]: connect from unknown[95.75.93.154]\r",
              "syslog_pid" => "31499",
          "syslog_message" => "connect from unknown[95.75.93.154]\r",
                    "path" => "C:/elk stack/samples.log",
                    "type" => "syslog",
                "@version" => "1",
         "syslog_hostname" => "louis",
          "syslog_program" => "postfix/smtpd",
        "syslog_timestamp" => "Dec 23 12:11:46",
    "syslog_severity_code" => 5,
             "received_at" => "2022-02-17T06:38:15.329Z",
           "received_from" => "IE3BLTGPCZXD3",
    "syslog_facility_code" => 1,
         "syslog_facility" => "user-level",
                    "host" => "IE3BLTGPCZXD3",
         "syslog_severity" => "notice"
}
{
              "@timestamp" => 2022-12-23T09:12:59.000Z,
                 "message" => "Dec 23 14:42:59 louis named[16000]: client 199.48.164.7#64817: query (cache) 'amsterdamboothuren.com/MX/IN' denied\r",
              "syslog_pid" => "16000",
          "syslog_message" => "client 199.48.164.7#64817: query (cache) 'amsterdamboothuren.com/MX/IN' denied\r",
                    "path" => "C:/elk stack/samples.log",
                    "type" => "syslog",
                "@version" => "1",
         "syslog_hostname" => "louis",
          "syslog_program" => "named",
        "syslog_timestamp" => "Dec 23 14:42:59",
    "syslog_severity_code" => 5,
             "received_at" => "2022-02-17T06:38:15.347Z",
           "received_from" => "IE3BLTGPCZXD3",
    "syslog_facility_code" => 1,
         "syslog_facility" => "user-level",
                    "host" => "IE3BLTGPCZXD3",
         "syslog_severity" => "notice"
}

```

However, kibana shows no output at the time

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/a/daafaa192bb8daa2ad829bde8af8cd5e580de768.png)

Help would be appreciated  
Thank you

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [February 17, 2022, 9:08am UTC](https://discuss.elastic.co/t/no-output-shown-on-kibana/297443/2 "2022-02-17T09:08:51Z")

</div>

From the screenshot, it looks like your selected date range is for a couple of hours only on Feb 17th, when in fact you are interested in data from Dec 23th 2022. Could you select a wider date-range and let us know if the problem persists?

---

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [February 21, 2022, 7:48am UTC](https://discuss.elastic.co/t/no-output-shown-on-kibana/297443/3 "2022-02-21T07:48:49Z")

</div>

Yes that's where I was going wrong. It's working perfectly! thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2022, 7:48am UTC](https://discuss.elastic.co/t/no-output-shown-on-kibana/297443/4 "2022-03-21T07:48:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
