# No results found in Kibana

**URL:** <https://discuss.elastic.co/t/no-results-found-in-kibana/47360>\
**Category:** Logstash\
**Created:** [April 14, 2016, 8:51am UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360 "2016-04-14T08:51:49Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Karl\_Trasschaert](https://avatars.discourse-cdn.com/v4/letter/k/f9ae1b/32.png) [@Karl\_Trasschaert](https://discuss.elastic.co/u/Karl_Trasschaert)\
**Post date:** [April 14, 2016, 8:51am UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/1 "2016-04-14T08:51:49Z")

</div>

Hi,

I just install all the latest kibana 4.5 / elasticsearch and logstash on a ubuntu server.

I'm sending logs from syslog to the server but kibana still say that it can't find results.

here is the conf file 🙂

`input {  
lumberjack {  
port =\> 514  
type =\> "logs"  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGLINE}" }  
}

```
date {

```

match =\> ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}

}

output {  
elasticsearch { hosts=\> localhost index =\> "logstash-%{+YYYY.MM.dd}" }  
stdout { codec =\> rubydebug }  
}output {  
elasticsearch { hosts =\> localhost index =\> "logstash-%{+YYYY.MM.dd}" }  
stdout { codec =\> rubydebug }'

Could you help me to troubleshoot this?

How can i first check if logs arrive to the server, if logstash receive it and if it does somthing with it.

Thx

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 15, 2016, 2:49pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/2 "2016-04-15T14:49:50Z")

</div>

For starters, you could take Kibana out of the equation and test if the data is in Elasticsearch. To do this check if the `logstash-` indices you expect are even there in Elasticsearch by running:

`curl http://localhost:9200/_cat/indices`

If the indices you expect to see show up, then do a search on them to see if there's the expected data in them:

`curl http://localhost:9200/logstash-*/_search`

---

<div class="post-metadata">

**Author:** ![Karl\_Trasschaert](https://avatars.discourse-cdn.com/v4/letter/k/f9ae1b/32.png) [@Karl\_Trasschaert](https://discuss.elastic.co/u/Karl_Trasschaert)\
**Post date:** [April 18, 2016, 2:27pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/3 "2016-04-18T14:27:24Z")

</div>

apparently the indices, i'm waiting for is not there 🙂  
`administrator@ELKibana4:~$ curl http://localhost:9200/_cat/indices yellow open .kibana 1 1 104 1 101kb 101kb yellow open blog 5 1 1 0 3.6kb 3.6kb`

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 19, 2016, 8:41am UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/4 "2016-04-19T08:41:09Z")

</div>

Okay, so then something's not correct on the shipping side as the documents don't even seem to be getting to Elasticsearch. I'm moving this to the Logstash category as that is more appropriate at this point.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 19, 2016, 9:02am UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/5 "2016-04-19T09:02:56Z")

</div>

Multiple problems:

- You can't use the lumberjack input to receive data over the syslog protocol. Use a syslog, udp, or tcp input (depending on how the sender sends the data).
- Unless you run Logstash as root or take other special measures you won't be able to listen on a port below 1024.

---

<div class="post-metadata">

**Author:** ![Karl\_Trasschaert](https://avatars.discourse-cdn.com/v4/letter/k/f9ae1b/32.png) [@Karl\_Trasschaert](https://discuss.elastic.co/u/Karl_Trasschaert)\
**Post date:** [April 19, 2016, 2:58pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/6 "2016-04-19T14:58:26Z")

</div>

> [@magnusbaeck](#):
>
> Unless you run Logstash as root or take other special measures you won't be able to listen on a port below 1024.

Could you explain me how to be able to receive log on a port bellow 1024, without runing logstash as root ?

---

<div class="post-metadata">

**Author:** ![Karl\_Trasschaert](https://avatars.discourse-cdn.com/v4/letter/k/f9ae1b/32.png) [@Karl\_Trasschaert](https://discuss.elastic.co/u/Karl_Trasschaert)\
**Post date:** [April 19, 2016, 3:30pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/7 "2016-04-19T15:30:44Z")

</div>

I've set this up but i didn't have any indice too:

> input{  
> tcp {  
> port =\> 1514  
> tags =\> [IPO]  
> type =\> cdr  
> }  
> }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 19, 2016, 6:10pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/8 "2016-04-19T18:10:50Z")

</div>

> Could you explain me how to be able to receive log on a port bellow 1024, without runing logstash as root ?

You can use iptables to reroute the port and you should be able to adjust the process's capabilities (but I recall that being problematic with the JVM). I don't have any details as I've never done it myself.

> I've set this up but i didn't have any indice too:

Be systematic. Forget about Kibana and ES for now. Comment out the elasticsearch output and focus on the stdout output. Does that make a difference? Does anything happen if you send stuff to the listening port with telnet or netcat?

---

<div class="post-metadata">

**Author:** ![Karl\_Trasschaert](https://avatars.discourse-cdn.com/v4/letter/k/f9ae1b/32.png) [@Karl\_Trasschaert](https://discuss.elastic.co/u/Karl_Trasschaert)\
**Post date:** [April 26, 2016, 12:58pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/9 "2016-04-26T12:58:52Z")

</div>

> [@magnusbaeck](#):
>
> Does anything happen if you send stuff to the listening port with telnet or netcat?

I just try to connect with telnet on port 5514 ( port i've set up in the conf file) i can't connect with telnet.

Do i have just to telnet to the server ip on this port ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 26, 2016, 4:45pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/10 "2016-04-26T16:45:32Z")

</div>

> Do i have just to telnet to the server ip on this port ?

Yes. That should work. Make sure Logstash starts up correctly and that there's no firewall blocking the access.

---

<div class="post-metadata">

**Author:** ![Karl\_Trasschaert](https://avatars.discourse-cdn.com/v4/letter/k/f9ae1b/32.png) [@Karl\_Trasschaert](https://discuss.elastic.co/u/Karl_Trasschaert)\
**Post date:** [April 28, 2016, 12:54pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/11 "2016-04-28T12:54:26Z")

</div>

ok, it looks to receive logs now, i'v recreate the conf file.

Now when i add the filter type =cdr, i didn't get any logs any more, but configtest give ok.

here is the file:

> input {  
> tcp {  
> port =\> 1514  
> type =\> cdr  
> }  
> udp {  
> port =\> 1514  
> type =\> syslog  
> }  
> }

> filter {  
> if [type] == "syslog" {  
> grok {  
> match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
> add\_field =\> ["received\_at", "%{@timestamp}"]  
> add\_field =\> ["received\_from", "%{host}"]  
> }  
> date {  
> match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
> }  
> }  
> if [type] == "cdr" {  
> csv {

> separator =\> ","  
> columns =\> [  
> "Call\_Start", "Connected\_Time", "Ring\_Time", "Caller", "Direction", "Called\_Number", "Dialed\_Number", "Account", "Is\_Internal", "Call\_ID", "Continuation", "Party1device", "Party1Name", "Party2Device", "Party2Name", "Hold\_Time", "Park\_Time", "AuthValid", "AuthCode", "User\_Charged", "Call\_Charge", "Currency", "Amount\_at\_last\_User\_Change", "Call\_Units", "Units\_at\_Last\_User \_hange", "Cost\_per\_Units", "Mark\_up", "External\_Targeting\_Cause", "External\_targeter\_ID", "External\_Targeted\_Number"  
> ]

> }  
> ruby  
> {  
> code =\> "event['Duration'] = event['Connected\_Time'] ? event['Connected\_Time'].split(':').inject(0){|a, m| a = a \* 60 + m.to\_i} : 0"  
> }  
> ruby  
> {  
> code =\> "event['Sonnerie'] = event['Ring\_Time']"  
> }

> mutate  
> {  
> convert =\> {"Sonnerie" =\> "integer"}  
> convert =\> {"Duration" =\> "integer"}  
> }  
> }  
> }  
> output {  
> elasticsearch { hosts =\> ["localhost:9200"] }  
> stdout { codec =\> rubydebug }  
> }

---

<div class="post-metadata">

**Author:** ![Karl\_Trasschaert](https://avatars.discourse-cdn.com/v4/letter/k/f9ae1b/32.png) [@Karl\_Trasschaert](https://discuss.elastic.co/u/Karl_Trasschaert)\
**Post date:** [April 28, 2016, 1:16pm UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/12 "2016-04-28T13:16:22Z")

</div>

don't take care of my previus message, it looks to works 🙂

I think i'm not waiting enough

---

<div class="post-metadata">

**Author:** ![Karl\_Trasschaert](https://avatars.discourse-cdn.com/v4/letter/k/f9ae1b/32.png) [@Karl\_Trasschaert](https://discuss.elastic.co/u/Karl_Trasschaert)\
**Post date:** [April 29, 2016, 10:32am UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/13 "2016-04-29T10:32:22Z")

</div>

yesterday i was receiving log but today since 00:12:33, i didn't receive any logs anymore from TCP port 1514.

logs from TCP 1514 are SMDR, the same device can send logs UDP on port 1514 :s

I need to be able to receive the 2.

I didn't change anything in the config since yesterday .

Any idea why i can receive logs from UDP and not from TCP ?

is it something in ubuntu which can block traffic from a source if it's sending too many data ?

---

<div class="post-metadata">

**Author:** ![Karl\_Trasschaert](https://avatars.discourse-cdn.com/v4/letter/k/f9ae1b/32.png) [@Karl\_Trasschaert](https://discuss.elastic.co/u/Karl_Trasschaert)\
**Post date:** [April 29, 2016, 10:52am UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/14 "2016-04-29T10:52:24Z")

</div>

looks to be a issue with the device 🙂  
i've chaneg te port - Save reset the port - save and now i receive the smdr again ...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:00am UTC](https://discuss.elastic.co/t/no-results-found-in-kibana/47360/15 "2017-07-06T05:00:00Z")

</div>


