# No results in Kibana search

**URL:** <https://discuss.elastic.co/t/no-results-in-kibana-search/318378>\
**Category:** Kibana\
**Created:** [November 8, 2022, 2:08am UTC](https://discuss.elastic.co/t/no-results-in-kibana-search/318378 "2022-11-08T02:08:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![azamf](https://avatars.discourse-cdn.com/v4/letter/a/958977/32.png) [@azamf](https://discuss.elastic.co/u/azamf)\
**Post date:** [November 8, 2022, 2:08am UTC](https://discuss.elastic.co/t/no-results-in-kibana-search/318378/1 "2022-11-08T02:08:33Z")

</div>

I'm trying to search against an existing index but the request yields no results. I know there is data since other users can see the index and view data in the same time frame.

I am able to view data in most indices in Kibana instance, but a few indices seem to be 'unsearchable' and give no results.

I'm new to Kibana so I may be missing something obvious. Any help would be hugely appreciated.  
Some useful info:

- The index does have a `@timestamp` field and is searchable
- Other users can run the same request and can view the data in the index
- I have the kibana\_system built-in user role.

The request:

```auto
{
  "track_total_hits": false,
  "sort": [
    {
      "@timestamp": {
        "order": "desc",
        "unmapped_type": "boolean"
      }
    }
  ],
  "fields": [
    {
      "field": "*",
      "include_unmapped": "true"
    },
    {
      "field": "@timestamp",
      "format": "strict_date_optional_time"
    }
  ],
  "size": 500,
  "version": true,
  "script_fields": {},
  "stored_fields": [
    "*"
  ],
  "runtime_mappings": {},
  "_source": false,
  "query": {
    "bool": {
      "must": [],
      "filter": [
        {
          "range": {
            "@timestamp": {
              "format": "strict_date_optional_time",
              "gte": "2022-08-09T14:00:00.000Z",
              "lte": "2022-11-08T02:06:04.033Z"
            }
          }
        }
      ],
      "should": [],
      "must_not": []
    }
  },
  "highlight": {
    "pre_tags": [
      "@kibana-highlighted-field@"
    ],
    "post_tags": [
      "@/kibana-highlighted-field@"
    ],
    "fields": {
      "*": {}
    },
    "fragment_size": 2147483647
  }
}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 8, 2022, 2:24am UTC](https://discuss.elastic.co/t/no-results-in-kibana-search/318378/2 "2022-11-08T02:24:58Z")

</div>

Welcome to our community! 😃

> [@azamf](#):
>
> ```auto
> "@timestamp": {
> "format": "strict_date_optional_time",
> "gte": "2022-08-09T14:00:00.000Z",
> "lte": "2022-11-08T02:06:04.033Z"
> 
> ```

So you're looking for all data in this range? Where are you doing this, in Discover or in a Dashboard?

---

<div class="post-metadata">

**Author:** ![azamf](https://avatars.discourse-cdn.com/v4/letter/a/958977/32.png) [@azamf](https://discuss.elastic.co/u/azamf)\
**Post date:** [November 8, 2022, 2:27am UTC](https://discuss.elastic.co/t/no-results-in-kibana-search/318378/3 "2022-11-08T02:27:13Z")

</div>

Yes, Looking for data of September through October. I'm searching it in Discover.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 8, 2022, 2:40am UTC](https://discuss.elastic.co/t/no-results-in-kibana-search/318378/4 "2022-11-08T02:40:10Z")

</div>

Can you run that query in [Run API requests | Kibana Guide [8.5] | Elastic](https://www.elastic.co/guide/en/kibana/current/console-kibana.html) and see what it outputs?

---

<div class="post-metadata">

**Author:** ![azamf](https://avatars.discourse-cdn.com/v4/letter/a/958977/32.png) [@azamf](https://discuss.elastic.co/u/azamf)\
**Post date:** [November 8, 2022, 2:54am UTC](https://discuss.elastic.co/t/no-results-in-kibana-search/318378/5 "2022-11-08T02:54:48Z")

</div>

This is the result when running it against e.g. (`my-index-*`)

```auto
{
  "took": 1,
  "timed_out": false,
  "_shards": {
    "total": 0,
    "successful": 0,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "max_score": 0,
    "hits": []
  }
}

```

But interestingly, running it against a single index, e.g (`my-index-dev`) gave this error

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "security_exception",
        "reason" : "action [indices:data/read/search] is unauthorized for user [my-username] with roles [Dev,QA,kibana_system,Support] on indices [my-index-dev], this action is granted by the index privileges [read,all]"
      }
    ],
    "type" : "security_exception",
    "reason" : "action [indices:data/read/search] is unauthorized for user [my-username] with roles [Dev,QA,kibana_system,Support] on indices [my-index-dev], this action is granted by the index privileges [read,all]"
  },
  "status" : 403
}

```

I think I've found the issue. Thank you! 😃

---

<div class="post-metadata">

**Author:** ![azamf](https://avatars.discourse-cdn.com/v4/letter/a/958977/32.png) [@azamf](https://discuss.elastic.co/u/azamf)\
**Post date:** [November 8, 2022, 3:09am UTC](https://discuss.elastic.co/t/no-results-in-kibana-search/318378/6 "2022-11-08T03:09:24Z")

</div>

After adding myself in the relevant group with permissions to read the indices in `my-index-*`, I was able to view the data in the index.

Thank you @warkolm!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 6, 2022, 3:09am UTC](https://discuss.elastic.co/t/no-results-in-kibana-search/318378/7 "2022-12-06T03:09:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
