Hello, I'm using Kibana 5.4.0 and I've imported dashboards with (filebeat util) /usr/share/filebeat/scripts/import_dashboards (it downloaded beats-dashboards-5.4.0.zip).
Problem is that fields in Elasticsearch (added with Logstash) are different than those in dashboards.
I'm sending logs from clients with Filebeat, processing them with Logstash and saving into Elasticsearch.
In Kibana I'm using filebeat-* mapping.
For example field system.syslog.hostname:
but in index there is syslog_hostname:
Dashboard are empty then (yes, I have 90 days ago selected so range is not problem):
I can rename them, yes, thank you for suggestion. But is it neccessary? Why are columns different? system.syslog.hostname is from filebeat documentation; why is it changed in logstash?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.