# "no results found" in Kibana Dashboard with filebeat & elastic search

**URL:** <https://discuss.elastic.co/t/no-results-found-in-kibana-dashboard-with-filebeat-elastic-search/192714>\
**Category:** Kibana\
**Created:** [July 29, 2019, 1:49pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana-dashboard-with-filebeat-elastic-search/192714 "2019-07-29T13:49:27Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![anarchipur](https://avatars.discourse-cdn.com/v4/letter/a/94ad74/32.png) [@anarchipur](https://discuss.elastic.co/u/anarchipur)\
**Post date:** [July 29, 2019, 1:49pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana-dashboard-with-filebeat-elastic-search/192714/1 "2019-07-29T13:49:28Z")

</div>

Hi I am absolutely new to elastic stack. I just installed and configured filebeat, elastic search and Kibana for Apache logging.

I went through the steps as described in "Getting Started with Filebeat" and reached "Step 6. View the sample Kibana Dashboards" ( [https://www.elastic.co/guide/en/beats/filebeat/current/view-kibana-dashboards.html](https://www.elastic.co/guide/en/beats/filebeat/current/view-kibana-dashboards.html) ) Elastic search is running correctly and Kibana and filebeat are started as well.

In the "Discover" panel I see the raw data, then I go to "Dashboard", select the Filebeat Apache  
ECS dashboard and can see the dashboard, however in the charts I get "no results found".

Do I have to configure the metrics in order to get the visualisations (there is no hint in the help documentation...)?

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [July 29, 2019, 4:57pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana-dashboard-with-filebeat-elastic-search/192714/2 "2019-07-29T16:57:06Z")

</div>

Perhaps no data exists for the time range in the Dashboard (I think the default is the last 15 minutes)? Maybe you need to expand the time range?

---

<div class="post-metadata">

**Author:** ![anarchipur](https://avatars.discourse-cdn.com/v4/letter/a/94ad74/32.png) [@anarchipur](https://discuss.elastic.co/u/anarchipur)\
**Post date:** [July 30, 2019, 9:17am UTC](https://discuss.elastic.co/t/no-results-found-in-kibana-dashboard-with-filebeat-elastic-search/192714/3 "2019-07-30T09:17:44Z")

</div>

I have set the data range to "last 10 days".

Here the raw data:

 ![2019-07-30%2010_56_42-kibana%20raw%20data](https://us1.discourse-cdn.com/elastic/original/3X/6/e/6e03ffe012dd59fa1c1b5b65d1e2cb4864ddfa28.png)

And here the dashboard:

 ![2019-07-30%2011_15_02-Kibana%20Dashboard](https://us1.discourse-cdn.com/elastic/original/3X/6/2/62148b223293197612e79f46cdc9ef3d199f42ae.png)

So, I got stuck here in the last step of my evaluation...

Please help...

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [July 30, 2019, 5:35pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana-dashboard-with-filebeat-elastic-search/192714/4 "2019-07-30T17:35:16Z")

</div>

Hi Sergio, what are the values for `event.dataset` in your data? Does it match mine?

 ![Screenshot_2019-07-30%20Discover%20-%20Kibana](https://us1.discourse-cdn.com/elastic/original/3X/a/b/ab5f936b3843391b6de5998bd83d4e572cf0f6c9.png)

---

<div class="post-metadata">

**Author:** ![anarchipur](https://avatars.discourse-cdn.com/v4/letter/a/94ad74/32.png) [@anarchipur](https://discuss.elastic.co/u/anarchipur)\
**Post date:** [August 5, 2019, 10:52am UTC](https://discuss.elastic.co/t/no-results-found-in-kibana-dashboard-with-filebeat-elastic-search/192714/5 "2019-08-05T10:52:53Z")

</div>

Hi Nick,

thank you for asking me. Yes I have these fields.

 ![2019-08-05%2012_48_45-Available%20FIelds](https://us1.discourse-cdn.com/elastic/original/3X/2/6/2682bcfa51fc82375ef59f192422c2a25fd9493b.png)

I actually just want to display the log messages in a more readable way than they are shown in the Discover panel. I do not need special charts. Just the log lines with some red colored keywords like ERROR for better readability.

I appreciate your help.

---

<div class="post-metadata">

**Author:** ![nickpeihl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nickpeihl/32/112622_2.png) [@nickpeihl](https://discuss.elastic.co/u/nickpeihl)\
**Post date:** [August 5, 2019, 4:01pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana-dashboard-with-filebeat-elastic-search/192714/6 "2019-08-05T16:01:00Z")

</div>

Discover is useful for exploring data when creating your own visualizations. The Visual Builder (TSVB) has some useful customizations for coloring text based on data. Here's a great video showing how you can customize a TSVB visualization.

> **[Kibana's New Time Series Visual Builder - Part 2](https://www.elastic.co/blog/kibanas-new-time-series-visual-builder-part-2)**
>
> The second blog post in a series focused on utilizing Kibana's new visual builder for time series data

---

<div class="post-metadata">

**Author:** ![anarchipur](https://avatars.discourse-cdn.com/v4/letter/a/94ad74/32.png) [@anarchipur](https://discuss.elastic.co/u/anarchipur)\
**Post date:** [August 12, 2019, 1:57pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana-dashboard-with-filebeat-elastic-search/192714/7 "2019-08-12T13:57:13Z")

</div>

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 9, 2019, 1:57pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana-dashboard-with-filebeat-elastic-search/192714/8 "2019-09-09T13:57:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
