# Not getting logs entries on the kibana - after Xpack Configuration | ELK v7.1

**URL:** <https://discuss.elastic.co/t/not-getting-logs-entries-on-the-kibana-after-xpack-configuration-elk-v7-1/188485>\
**Category:** Logstash\
**Tags:** elastic-stack-security\
**Created:** [July 2, 2019, 11:00am UTC](https://discuss.elastic.co/t/not-getting-logs-entries-on-the-kibana-after-xpack-configuration-elk-v7-1/188485 "2019-07-02T11:00:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ranjith\_SG1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ranjith_sg1/32/49258_2.png) [@Ranjith\_SG1](https://discuss.elastic.co/u/Ranjith_SG1)\
**Post date:** [July 2, 2019, 11:00am UTC](https://discuss.elastic.co/t/not-getting-logs-entries-on-the-kibana-after-xpack-configuration-elk-v7-1/188485/1 "2019-07-02T11:00:44Z")

</div>

We are not getting log entries in the - kibana after configuring xpack in version 7.1 . below is the logsatsh conf file . Let me know is anything wrong in the configuration . - User -elastic( role - super user)

logstash.yml: - Added below lines in the yml file  
xpack.monitoring.enabled: true  
xpack.monitoring.elasticsearch.username: elastic  
xpack.monitoring.elasticsearch.password: xxxxxxxxxxxxxxxx

logstash.conf:  
input {  
file {  
path =\> "/gsa/bldgsa/projects/a/logEvent\_2019\*"  
type =\> "IVT\_syslog"  
start\_position =\> "beginning"  
sincedb\_path =\> "/tmp/sincedb/ivt\_syslogs"  
close\_older =\> 0  
exclude =\> "\*.gz"  
elasticsearch { user =\> elastic  
password =\> xxxxxxxxxxxxxxxxxxx  
}  
}  
}

filter {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program})?: logEvent [%{WORD:logevent}][%{DATA:protocol}][%{DATA:messagetype}]%{GREEDYDATA:syslog\_message}" }  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
timezone =\> "UTC"  
}  
elasticsearch { user =\> elastic  
password =\> xxxxxxxxxxxxxxxx  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"]  
user =\> elastic  
password =\> xxxxxxxxxxxxx  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [July 2, 2019, 11:06am UTC](https://discuss.elastic.co/t/not-getting-logs-entries-on-the-kibana-after-xpack-configuration-elk-v7-1/188485/2 "2019-07-02T11:06:17Z")

</div>

Hello,

Please user the `</>` button or backticks (```) when adding configuration snippets in your posts as it is really hard to read through them if you don't do it. You can use the preview panel on the right to see how your post looks like before submitting it.

Also, please go through our documentation [here](https://www.elastic.co/guide/en/logstash/7.1/ls-security.html), it should have all the information you are looking for. When you perform the necessary actions, if you still have issues or questions, we'll be happy to help out

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2019, 11:06am UTC](https://discuss.elastic.co/t/not-getting-logs-entries-on-the-kibana-after-xpack-configuration-elk-v7-1/188485/3 "2019-07-30T11:06:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
