# Packetbeat dashboard can't locate index pattern

**URL:** <https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518>\
**Category:** Kibana\
**Created:** [May 3, 2018, 7:23pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518 "2018-05-03T19:23:40Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![imparker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imparker/32/29887_2.png) [@imparker](https://discuss.elastic.co/u/imparker)\
**Post date:** [May 3, 2018, 7:23pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518/1 "2018-05-03T19:23:40Z")

</div>

I've tried refreshing the pattern and having packetbeat resend the dashboards but neither seem to work.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8b912d4b1be7b8b4c548abe0b003198b180ba87b.png)

---

<div class="post-metadata">

**Author:** ![a5a](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@a5a](https://discuss.elastic.co/u/a5a)\
**Post date:** [May 3, 2018, 7:51pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518/2 "2018-05-03T19:51:09Z")

</div>

When you try something lik `GET .kibana/_search` do you see that packetbeat index pattern in there? And that Response-times repartition visualization in there? They should be objects in the .kibana index.

---

<div class="post-metadata">

**Author:** ![imparker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imparker/32/29887_2.png) [@imparker](https://discuss.elastic.co/u/imparker)\
**Post date:** [May 3, 2018, 8:06pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518/3 "2018-05-03T20:06:06Z")

</div>

> [@a5a](#):
>
> Response-times

If I'm understanding this correctly then I think yes?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ffd7d06dcf6b893f1d9ed3e20ba24654a4f7dae3.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/1/315961c39d6b34c7fe0b6e6bcf72472630da8eec.png)

---

<div class="post-metadata">

**Author:** ![a5a](https://avatars.discourse-cdn.com/v4/letter/a/a87d85/32.png) [@a5a](https://discuss.elastic.co/u/a5a)\
**Post date:** [May 3, 2018, 9:09pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518/4 "2018-05-03T21:09:51Z")

</div>

Ah, What you should see are the `_id` field of the visualization and of the index pattern; they need to match what the dashboard is looking for. Here's a better query `GET .kibana/doc/packetbeat-*` and `GET .kibana/doc/Response-times-repartition`

The packetbeat dashboard is looking for objects with those ids. If they don't exist in the kibana index, it won't find them. I'm not sure what might have happened to cause this... At some point the ids of the saved search and visualization changed, and now the dashboard is no longer referencing the current ids of those objects. If you know they exist, you can re-link them to the dashboard by removing what's there and re-adding them by going into the dashboard edit.

Was this a preconfigured packetbeat dashboard? I think you obtained it from one of our examples, where we provide some dashboards to get started? I wonder what happened here. Was this dashboard ever displaying those objects?

---

<div class="post-metadata">

**Author:** ![imparker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imparker/32/29887_2.png) [@imparker](https://discuss.elastic.co/u/imparker)\
**Post date:** [May 4, 2018, 2:13am UTC](https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518/5 "2018-05-04T02:13:27Z")

</div>

yeah, they were the preconfigured ones. No, they weren't.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [May 4, 2018, 5:02pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518/6 "2018-05-04T17:02:51Z")

</div>

Do you have the `packetbeat-*` index pattern in the Management tab under Index Patterns?

---

<div class="post-metadata">

**Author:** ![imparker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imparker/32/29887_2.png) [@imparker](https://discuss.elastic.co/u/imparker)\
**Post date:** [May 8, 2018, 9:32pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518/7 "2018-05-08T21:32:56Z")

</div>

Yes: [https://screenshots.firefox.com/dgo82daSQG64JdOP/10.200.1.122](https://screenshots.firefox.com/dgo82daSQG64JdOP/10.200.1.122)

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [May 9, 2018, 10:12am UTC](https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518/8 "2018-05-09T10:12:12Z")

</div>

Good, can you also confirm that upon creation you also set the `Custom index pattern ID` to `packetbeat-*` ?  
To be sure, the easiest way is to create another index pattern, with the same pattern, but with the field for Custom ID also as `packetbeat-*`

 ![index_pattern](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a0ab0c848893b8545ccc38a7596462fc5f0201c3.png)

---

<div class="post-metadata">

**Author:** ![imparker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imparker/32/29887_2.png) [@imparker](https://discuss.elastic.co/u/imparker)\
**Post date:** [May 9, 2018, 1:30pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518/9 "2018-05-09T13:30:48Z")

</div>

So like this? I manually entered `packetbeat-*` to the custom index pattern ID field

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f0b8df81bde66dc28c883683299c69066724798.png)

[https://screenshots.firefox.com/33CNdXydCdXIEfcx/10.200.1.122](https://screenshots.firefox.com/33CNdXydCdXIEfcx/10.200.1.122)

---

<div class="post-metadata">

**Author:** ![imparker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/imparker/32/29887_2.png) [@imparker](https://discuss.elastic.co/u/imparker)\
**Post date:** [May 10, 2018, 3:51pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518/10 "2018-05-10T15:51:01Z")

</div>

I've done what you suggested, but I'm still getting dashboard errors.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/9/69eb20d7d6bee85e17a25a02a0ba17e16b712f27.png)

[https://screenshots.firefox.com/OVIiyJot2ZpPpv6J/10.200.1.122](https://screenshots.firefox.com/OVIiyJot2ZpPpv6J/10.200.1.122)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2018, 3:51pm UTC](https://discuss.elastic.co/t/packetbeat-dashboard-cant-locate-index-pattern/130518/11 "2018-06-07T15:51:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
