# Nothing view in elasticsearch and kibana when import csv file

**URL:** <https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822>\
**Category:** Logstash\
**Created:** [April 27, 2017, 8:56am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822 "2017-04-27T08:56:54Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![zegdene](https://avatars.discourse-cdn.com/v4/letter/z/76d3ee/32.png) [@zegdene](https://discuss.elastic.co/u/zegdene)\
**Post date:** [April 27, 2017, 8:56am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/1 "2017-04-27T08:56:54Z")

</div>

Hi,  
I create a file.config for import csv file to elasticsearch but the connection between ES and Logstash is warning . I have this Warn:

```
> Sending Logstash's logs to C:/Project/elk/logstash/logs which is now configured
> via log4j2.properties
> [2017-04-27T09:48:51,839][INFO][logstash.outputs.elasticsearch] Elasticsearch p
> ool URLs updated {:changes=>{:removed=>[], :added=>["http://localhost:9200"]}}
> [2017-04-27T09:48:51,839][INFO][logstash.outputs.elasticsearch] Running health
> check to see if an Elasticsearch connection is working {:url=>#<URI::HTTP:0x30f6
> 9343 URL:http://localhost:9200>, :healthcheck_path=>"/"}
> [2017-04-27T09:48:51,939][WARN][logstash.outputs.elasticsearch] Restored connec
> tion to ES instance {:url=>#<URI::HTTP:0x30f69343 URL:http://localhost:9200>}
> [2017-04-27T09:48:51,939][INFO][logstash.outputs.elasticsearch] Using mapping t
> emplate from {:path=>nil}
> [2017-04-27T09:48:51,999][INFO][logstash.outputs.elasticsearch] Attempting to i
> nstall template {:manage_template=>{"template"=>"logstash-*", "version"=>50001,
> "settings"=>{"index.refresh_interval"=>"5s"}, "mappings"=>{"_default_"=>{"_all"=
> >{"enabled"=>true, "norms"=>false}, "dynamic_templates"=>[{"message_field"=>{"pa
> th_match"=>"message", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text"
> , "norms"=>false}}}, {"string_fields"=>{"match"=>"*", "match_mapping_type"=>"str
> ing", "mapping"=>{"type"=>"text", "norms"=>false, "fields"=>{"keyword"=>{"type"=
> >"keyword"}}}}}], "properties"=>{"@timestamp"=>{"type"=>"date", "include_in_all"
> =>false}, "@version"=>{"type"=>"keyword", "include_in_all"=>false}, "geoip"=>{"d
> ynamic"=>true, "properties"=>{"ip"=>{"type"=>"ip"}, "location"=>{"type"=>"geo_po
> int"}, "latitude"=>{"type"=>"half_float"}, "longitude"=>{"type"=>"half_float"}}}
> }}}}}
> [2017-04-27T09:48:52,009][INFO][logstash.outputs.elasticsearch] New Elasticsear
> ch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["http://localhos
> t:9200"]}
> [2017-04-27T09:48:52,014][INFO][logstash.pipeline] Starting pipeline {"
> id"=>"main", "pipeline.workers"=>4, "pipeline.batch.size"=>125, "pipeline.batch.
> delay"=>5, "pipeline.max_inflight"=>500}
> [2017-04-27T09:48:52,019][INFO][logstash.pipeline] Pipeline main starte
> d
> [2017-04-27T09:48:52,109][INFO][logstash.agent] Successfully started
> Logstash API endpoint {:port=>9600}

```

This is my file.config:

```
input {
  file {
    path => "/Users/salma/Desktop/creditcard.csv"
    start_position => "beginning"
    sincedb_path => "/dev/null"
  }
}
filter {
  csv {
     separator => ","
     columns => ["Time","V1","V2","V3","V4","V5","V6","V7","V8","V9","V10","V11","V12","V13","V14","V15","V16","V17","V18","V19","V20","V21","V22","V23","V24","V25","V26","V27","V28","Amount"]
     remove_field => ["class"]

  }
}
output {
   elasticsearch {
   hosts => ["http://localhost:9200"]
   index => "dataset"
   sniffing => false
       }
   stdout { codec => rubydebug }
  }

```

I use ELK 5.2.1  
Can help please

Thanks

---

<div class="post-metadata">

**Author:** ![pablosan](https://avatars.discourse-cdn.com/v4/letter/p/e19adc/32.png) [@pablosan](https://discuss.elastic.co/u/pablosan)\
**Post date:** [April 27, 2017, 9:52am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/2 "2017-04-27T09:52:26Z")

</div>

Hi

That warning is just saying the connection was restored, probably lost before.  
I see it every time I restart Logstash, but I think it should not really be a warning. I might be wrong though.

By the way, the title of the topic is long and a bit unreadable, you could edit it and put something like logstash warning meaning or so.

---

<div class="post-metadata">

**Author:** ![zegdene](https://avatars.discourse-cdn.com/v4/letter/z/76d3ee/32.png) [@zegdene](https://discuss.elastic.co/u/zegdene)\
**Post date:** [April 27, 2017, 10:56am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/3 "2017-04-27T10:56:51Z")

</div>

Hi,  
My problem is in connection between logstash and elasticsearch because nothing view when i import a csv file

---

<div class="post-metadata">

**Author:** ![pablosan](https://avatars.discourse-cdn.com/v4/letter/p/e19adc/32.png) [@pablosan](https://discuss.elastic.co/u/pablosan)\
**Post date:** [April 28, 2017, 6:42am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/4 "2017-04-28T06:42:39Z")

</div>

But can you see the output of the CSV in the stdout?

> [@zegdene](#):
>
> stdout { codec =\> rubydebug }

Open the csv file edit it, and save it to test, might be an old file and Logstash is not picking it up

---

<div class="post-metadata">

**Author:** ![zegdene](https://avatars.discourse-cdn.com/v4/letter/z/76d3ee/32.png) [@zegdene](https://discuss.elastic.co/u/zegdene)\
**Post date:** [April 28, 2017, 7:52am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/5 "2017-04-28T07:52:20Z")

</div>

hi,  
the problem maybe in windows because the config file run in linux the warn it is restored connection to ES instance.

---

<div class="post-metadata">

**Author:** ![Raja1](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Post date:** [April 28, 2017, 8:00am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/6 "2017-04-28T08:00:52Z")

</div>

are you able to see the data in Kibana?

---

<div class="post-metadata">

**Author:** ![zegdene](https://avatars.discourse-cdn.com/v4/letter/z/76d3ee/32.png) [@zegdene](https://discuss.elastic.co/u/zegdene)\
**Post date:** [April 28, 2017, 8:03am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/7 "2017-04-28T08:03:19Z")

</div>

nooo nor in kibana and elasticsearch

---

<div class="post-metadata">

**Author:** ![Raja1](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Post date:** [April 28, 2017, 8:06am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/8 "2017-04-28T08:06:53Z")

</div>

Comment index line like below. Just replace this in ur configuration  
output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)" ]  
#index =\> "dataset"  
sniffing =\> false  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![Raja1](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Post date:** [April 28, 2017, 8:09am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/9 "2017-04-28T08:09:20Z")

</div>

Kindly remove the double quotes from below line.

start\_position =\> "beginning"

---

<div class="post-metadata">

**Author:** ![zegdene](https://avatars.discourse-cdn.com/v4/letter/z/76d3ee/32.png) [@zegdene](https://discuss.elastic.co/u/zegdene)\
**Post date:** [April 28, 2017, 8:16am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/10 "2017-04-28T08:16:11Z")

</div>

The same problem :

```
09:15:32.521 [[main]-pipeline-manager] WARN logstash.outputs.elasticsearch - Re
stored connection to ES instance {:url=>#<URI::HTTP:0x460208e0 URL:http://localh
ost:9200>}
```

---

<div class="post-metadata">

**Author:** ![Raja1](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Post date:** [April 28, 2017, 8:20am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/11 "2017-04-28T08:20:14Z")

</div>

This message is okay...Its restoring the connection. after changes are you able to see the data in Kibana or not?

If not, Please check how many indices are having the elasticsearch.  
If you are using Linux, Please execute the command below.

**curl [http://localhost:9200/\_cat/indices](http://localhost:9200/_cat/indices).**  
Try to execute the below command and post complete log details here.

./logstash -f --debug

---

<div class="post-metadata">

**Author:** ![zegdene](https://avatars.discourse-cdn.com/v4/letter/z/76d3ee/32.png) [@zegdene](https://discuss.elastic.co/u/zegdene)\
**Post date:** [April 28, 2017, 8:22am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/12 "2017-04-28T08:22:09Z")

</div>

nothing view in kibana and the localhost return this :  
`yellow open .kibana H3neU9_NSz6OQ64kyydhXA 1 1 1 0 3.1kb 3.1kb`

---

<div class="post-metadata">

**Author:** ![Alvaro\_Sanz\_Garrigue](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@Alvaro\_Sanz\_Garrigue](https://discuss.elastic.co/u/Alvaro_Sanz_Garrigue)\
**Post date:** [April 28, 2017, 8:22am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/13 "2017-04-28T08:22:52Z")

</div>

Salma are you working in a enterprise computer or with some restrictions of use?

I had a similar problem and I finally make it works. I was doing it in the enterprise laptop which is restricted. I create a Ubuntu VM where I have the whole control, and there with the same logstash configuration it finally works.  
So I guess that in my enterprise computer there were permissions issues or something like that which denies logstash to work as expected.

---

<div class="post-metadata">

**Author:** ![Raja1](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Post date:** [April 28, 2017, 8:27am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/14 "2017-04-28T08:27:23Z")

</div>

Yes, Because index not created.  
Please execute my 2nd command which will give complete information so that we ca troubleshoot further.

---

<div class="post-metadata">

**Author:** ![zegdene](https://avatars.discourse-cdn.com/v4/letter/z/76d3ee/32.png) [@zegdene](https://discuss.elastic.co/u/zegdene)\
**Post date:** [April 28, 2017, 8:30am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/15 "2017-04-28T08:30:59Z")

</div>

Hi ALvaro, I work in windows Os i test my file.conf in ubuntu it's work with the same data , i need to execute in windows because but i don't have any solution

---

<div class="post-metadata">

**Author:** ![Raja1](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Post date:** [April 28, 2017, 8:34am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/16 "2017-04-28T08:34:43Z")

</div>

Ohh, you are facing issue with only in Windows....Sorry i thought you are facing the issue in Linux too.

I hope Alvaro give suggestions to resolve it windows environment.

---

<div class="post-metadata">

**Author:** ![Alvaro\_Sanz\_Garrigue](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@Alvaro\_Sanz\_Garrigue](https://discuss.elastic.co/u/Alvaro_Sanz_Garrigue)\
**Post date:** [April 28, 2017, 8:48am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/17 "2017-04-28T08:48:15Z")

</div>

I can't resolve it on Windows. I solve it in Ubuntu.  
Your Windows OS user has any restrictions or is a enterprise computer?  
I'm not sure if it was the problem but my company has strong security setting on the devices and I guess that the problem was there, it produces conflicts between ELK and the security settings o restrictions of the OS user.

---

<div class="post-metadata">

**Author:** ![zegdene](https://avatars.discourse-cdn.com/v4/letter/z/76d3ee/32.png) [@zegdene](https://discuss.elastic.co/u/zegdene)\
**Post date:** [April 28, 2017, 8:50am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/18 "2017-04-28T08:50:16Z")

</div>

he is a entreprise computer

---

<div class="post-metadata">

**Author:** ![Alvaro\_Sanz\_Garrigue](https://avatars.discourse-cdn.com/v4/letter/a/4491bb/32.png) [@Alvaro\_Sanz\_Garrigue](https://discuss.elastic.co/u/Alvaro_Sanz_Garrigue)\
**Post date:** [April 28, 2017, 8:52am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/19 "2017-04-28T08:52:53Z")

</div>

So probably the problem will be there, just build a Windows VM in your computer and try there.  
I hope it solves your problems.

---

<div class="post-metadata">

**Author:** ![Raja1](https://avatars.discourse-cdn.com/v4/letter/r/85f322/32.png) [@Raja1](https://discuss.elastic.co/u/Raja1)\
**Post date:** [April 28, 2017, 10:34am UTC](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822/20 "2017-04-28T10:34:47Z")

</div>

Hi Salma,

Please change this from sincedb\_path =\> "/dev/null" to sincedb\_path =\> "NUL"

Linux -\> sincedb\_path =\> "/dev/null"  
Windows -\> sincedb\_path =\> "NUL"

It should work

Regards  
Raja

[Next page](https://discuss.elastic.co/t/nothing-view-in-elasticsearch-and-kibana-when-import-csv-file/83822.md?page=2)
