# The filebeat dashboard : No results found

**URL:** <https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 15, 2017, 1:07am UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479 "2017-06-15T01:07:27Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Amna\_sayed\_ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amna_sayed_ali/32/45433_2.png) [@Amna\_sayed\_ali](https://discuss.elastic.co/u/Amna_sayed_ali)\
**Post date:** [June 15, 2017, 1:07am UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/1 "2017-06-15T01:07:27Z")

</div>

Hello,  
i have 2 Servers (one is ELK and other is filebeat ) both are Centos 7.  
i have installed ELK 5.4 "tar installation" on 1st server and filebeat 5.4 "tar installation" on 2nd server. i can see the log index in my Kibana discovery but when i switch to the visualize or the dashboard tab show me (No results found).  
Also i have installed Xpack plugin for ELasticsearch and Kibana but made the (xpack.security.enabled: false) for both

\*\*\*my logstash (input/filter/output) file "/usr/local/logstash/logstash.conf"  
###################### \<! INPUT !\> ###############################  
input {  
beats {  
port =\> 5044  
}

# stdin {

# type =\> "stdin-type"

# }

file {  
type =\> "syslog"

```
# Wildcards work, here :)
path => ["/var/log/message", "/var/log/secure"]
start_position => "beginning"

```

}

file {  
type =\> "apache"  
path =\> ["/usr/local/apache/logs/_/_.log", "/usr/local/apache/logs/\*\_log"]  
start\_position =\> "beginning"  
}

}  
####################### \<! FILTER!\> ##############################  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

filter {  
if [path] =~ "access" {  
mutate { replace =\> { "type" =\> "apache\_access" } }  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}

output {

# stdout {codec =\> rubydebug}

elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

\*\*\*my filebeat conf file (/usr/local/filebeat/filebeat.yml)  
#========================== Modules configuration ============================  
#filebeat.modules:

# 

##------------------------------- System Module -------------------------------  
modules:  
2017/06/15 01:00:42.061635 metrics.go:34: INFO No non-zero metrics in the last 30s

- name: mysql
- name: syslog  
#=========================== Filebeat prospectors =============================

filebeat.prospectors:

# Each - is a prospector. Most options can be set at the prospector level, so

# you can use different prospectors for various configurations.

# Below are the prospector specific configurations.

- input\_type: log

- input\_type: log  
paths:

could u plz help me, i have spent 3 days searching on this issue but i didn't find anything valued ☹

 ![](https://us1.discourse-cdn.com/elastic/original/3X/6/a/6a5e913013dc55c2ae402bab31cf1e39cbb2020e.PNG)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 15, 2017, 10:21am UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/2 "2017-06-15T10:21:59Z")

</div>

1. Please properly format logs and configuration files with `</>` button. The post is pretty unreadable

2. Are you using filebeat modules? Filebeat modules do operate in conjunction with Elasticsearch right now. Having filebeat send to logstash, you currently can not take advantage of filebeat modules.

---

<div class="post-metadata">

**Author:** ![Amna\_sayed\_ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amna_sayed_ali/32/45433_2.png) [@Amna\_sayed\_ali](https://discuss.elastic.co/u/Amna_sayed_ali)\
**Post date:** [June 15, 2017, 10:32am UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/3 "2017-06-15T10:32:58Z")

</div>

> [@steffens](#):
>
> \</

Hello Steffens,  
Thnx for ur reply.  
ys i tried to installed filebeats modules but gave me error because i enabled logstash output in filebeat.yml file so might this effect if ys how can i remove them.

regarding log format, sorry for that...kindly find below

\*\*\*my logstash (input/filter/output) file "/usr/local/logstash/logstash.conf"

\</################

input {  
beats {  
port =\> 5044  
}

stdin {  
type =\> "stdin-type"  
}  
file {  
type =\> "syslog"  
path =\> ["/var/log/message", "/var/log/secure"]  
start\_position =\> "beginning"  
}

file {  
type =\> "apache"  
path =\> ["/usr/local/apache/logs/_/_.log", "/usr/local/apache/logs/\*\_log"]  
start\_position =\> "beginning"  
}

}

#################

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

filter {  
if [path] =~ "access" {  
mutate { replace =\> { "type" =\> "apache\_access" } }  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}

output {

stdout {codec =\> rubydebug}  
elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}\>

\*\*\*my filebeat conf file (/usr/local/filebeat/filebeat.yml)

\</========================== Modules configuration ============================  
filebeat.modules:  
------------------------------- System Module -------------------------------  
modules:  
2017/06/15 01:00:42.061635 metrics.go:34: INFO No non-zero metrics in the last 30s

- name: mysql
- name: syslog

=========================== Filebeat prospectors =============================  
filebeat.prospectors:

Each - is a prospector. Most options can be set at the prospector level, so  
you can use different prospectors for various configurations.  
Below are the prospector specific configurations.  
input\_type: log  
paths:

- /var/log/messages
- /var/log/secure
- input\_type: log  
paths:
- /usr/local/apache/logs/_/_.log
- /usr/local/apache/logs/\*\_log  
fields:  
apache: true  
fields\_under\_root: true

----------------------------- Logstash output --------------------------------  
output.logstash:  
hosts: ["ELK\_server\_IP:5044"] \>

---

<div class="post-metadata">

**Author:** ![Amna\_sayed\_ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amna_sayed_ali/32/45433_2.png) [@Amna\_sayed\_ali](https://discuss.elastic.co/u/Amna_sayed_ali)\
**Post date:** [June 16, 2017, 9:18am UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/4 "2017-06-16T09:18:06Z")

</div>

any updates regarding my issue

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 16, 2017, 10:41am UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/5 "2017-06-16T10:41:49Z")

</div>

if you want to use filebeat modules, you can not use the Logstash output, but you have to use the Elasticsearch output.

Your logstash configuration is overly complex and seems to mix things not really fitting together... e.g. the elasticsearch output configuration doesn't work nicely with the other inputs you've defined in logstash.

From all these configs it's not clear to me what exactly you're planning to do and why you insist on using filebeat modules with logstash.

---

<div class="post-metadata">

**Author:** ![Amna\_sayed\_ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amna_sayed_ali/32/45433_2.png) [@Amna\_sayed\_ali](https://discuss.elastic.co/u/Amna_sayed_ali)\
**Post date:** [June 16, 2017, 10:55am UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/6 "2017-06-16T10:55:33Z")

</div>

thnx Steffens. regarding the filebeat modules i have removed them.  
actually i need to use beats \>\>logstash\>\>elasticsearch\>\>kibana.

regarding the 1st beat that i am planing to use (filebeat), if i remove my grok filer how i can visualize my logs like (message, apache, mysql) on kibana. i mean how can i use ur dashboard that attached in ur beats dashboard (like the below dashboard)

 ![](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bb69a481bf36c632dbda1691357e6940253b2fc4.PNG)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 17, 2017, 7:00pm UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/7 "2017-06-17T19:00:24Z")

</div>

These dashboards are made to work with filebeat modules. The dashboards by default assume all data written to the filebeat index. If you translate the grok filters from the filebeat modules to logstash and have logstash write similar events to elasticsearch, the dashboards should pick up your data.

The filebeat modules source code can be found at: [https://github.com/elastic/beats/tree/master/filebeat/module](https://github.com/elastic/beats/tree/master/filebeat/module)

For example see the mysql [error log](https://github.com/elastic/beats/tree/master/filebeat/module/mysql/error). The `pipeline` directory contains the ingest node pipeline definition.

As each module uses a different ingest pipeline, you might want to add some additional fields to the events (use `fields` setting in filebeat) for filtering in logstash. e.g.:

```auto
filebeat.prospectors:
- type: log
  fields.logtype: "mysqlerror"
  paths:
    - /var/log/mysql/error.log*
    - /var/log/mysqld.log*
  exclude_files: [".gz$"]
- type: log
  fields.logtype: "mysqlslow"
  paths:
    - /var/log/mysql/mysql-slow.log*
    - /var/lib/mysql/{{.builtin.hostname}}-slow.log
  exclude_files: ['.gz$']
  multiline:
    pattern: '^# User@Host: '
    negate: true
    match: after
  exclude_lines: ['^[\/\w\.]+, Version: .* started with:.*'] # Exclude the header
...

```

I did derive the filebeat configuration, by expanding the filebeat module template by myself.

In logstash one could do the filtering/processing like:

```auto
input {
  beat {
    port => 5044
  }
}

filter {
  if [fields][logtype] == "mysqlerr" {
    ... # translate pipeline from https://github.com/elastic/beats/blob/master/filebeat/module/mysql/error/ingest/pipeline.json
  }
  if [fields][logtype] == "mysqlslow" {
    ... # translate pipeline from https://github.com/elastic/beats/blob/master/filebeat/module/mysql/slowlog/ingest/pipeline.json
  }
}

```

translating pipelines can be non-trivial though (e.g. script filter using painless must be replaced with ruby filters and such). In logstash master branch I found a script doing some simple translation (not perfect, potentially incomplete): [https://github.com/elastic/logstash/blob/master/bin/ingest-convert.sh](https://github.com/elastic/logstash/blob/master/bin/ingest-convert.sh)

The current integration of beats modules and logstash is far from perfect. All in all we strive for full integration of modules in/with Logstash. But we're is just not there yet (I have no idea when we will be there).

---

<div class="post-metadata">

**Author:** ![Amna\_sayed\_ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amna_sayed_ali/32/45433_2.png) [@Amna\_sayed\_ali](https://discuss.elastic.co/u/Amna_sayed_ali)\
**Post date:** [June 17, 2017, 11:18pm UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/8 "2017-06-17T23:18:17Z")

</div>

```
</ Hi Steffens,

```

thnx for ur support and reply.  
Actually i tried to read the mentioned links to create custom logstash filter but i can't understand them ☹ .  
so if i use filebeat& modules with elasticsearch directly without using logstash, the dashboard will pick up my data without any custom configration,right?  
if yes, could u plz recommend the beat, elasticsearch and kibana version that i can use and it's recommended to use tar or rpm way.

Also i noticed the filebeat path only one log file, for example if i definded prospectors (/var/log/message & /var/log/secure& /usr/local/apache/log/_/_.log), the filebeat.harvester open only one file like messege so in filebeat index i can see the logs for one file.  
in log file i can see any error except  
2017-06-18T00:02:30+01:00 ERR Failed to publish events caused by: write tcp ELK\_IP:49410-\>ELK\_IP:5044: write: connection reset by peer although the client can reach server via 5044 port  
[root@s1 ~]# telnet ELK\_IP 5044  
Trying ELK\_IP...  
Connected to ELK\_IP .  
Escape character is '^]'.

# filebeat.yml

filebeat.prospectors:

- input\_type: log  
paths:
  - /var/log/secure
  - /var/log/message

- input\_type: log  
paths:
  - "/usr/local/apache/log/\*\_log"
  - "/usr/local/apache/log/_/_.log"

- input\_type: log  
paths:
  - /var/log/mysqld.log  
include\_lines: ['^ERR', '^WARN']  
output.logstash:

# The Logstash hosts
hosts: ["88.208.206.80:5044"]

# logstash.conf

input {  
beats {  
port =\> 5044  
}  
}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}\>

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 19, 2017, 9:43am UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/9 "2017-06-19T09:43:03Z")

</div>

> so if i use filebeat& modules with elasticsearch directly without using logstash, the dashboard will pick up my data without any custom configration,right?

Yes. If files are at assumed location and log format is not changed in services configuration.

> if yes, could u plz recommend the beat, elasticsearch and kibana version that i can use and it's recommended to use tar or rpm way.

modules are still a very new feature ([still in beta](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-modules-overview.html)) and are still being improved upon. I'd use the most recent versions of the complete stack. Currently version 5.4.1.  
Personally I'd prefer rpm of tar, so I can use the systems packet management tools. Just for testing/playing with beats, tar files are ok though.

> 2017-06-18T00:02:30+01:00 ERR Failed to publish events caused by: write tcp ELK\_IP:49410-\>ELK\_IP:5044: write: connection reset by peer

Logstash is closing (supposed to be) idle connections. That is, here it is Logstash closing the connection. Depending on 'timing' this occurs (before sending), it can be ok or bad (if this happens when beats is waiting for ACK). Filebeat will automatically reconnect and send again. Updating logstash to most recent version and increasing the [client\_inconnectivity\_timeout](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-beats.html#plugins-inputs-beats-client_inactivity_timeout) in the beats input normally helps. A bug in older logstash versions did sometimes close connections while Filebeat was waiting for ACK. Having this fixed, the error is tolerable, as filebeat will reconnect and send new events (no data loss).

> Actually i tried to read the mentioned links to create custom logstash filter but i can't understand them

The link points to a script in the logstash development branch. You will need a development environment with Java (and maybe NodeJS) to build and run this script. Still, the script can not translate all filters in the pipeline configuration and it's a non-trivial task. I'd recommend using the ingest node pipeline. If you really need to use Logstash, but want to use the ingest pipeline from ES as well (it's somewhat inefficient as it duplicates some effort), here is another trick you can try:

```auto
filebeat.prospectors:
- type: log
  fields:
    logtype: "mysqlerror"
    pipeline: "mysqlerror"
  paths:
    - /var/log/mysql/error.log*
    - /var/log/mysqld.log*
  exclude_files: [".gz$"]
- type: log
  fields:
    logtype: "mysqlslow"
    pipeline: "mysqlslow"
  paths:
    - /var/log/mysql/mysql-slow.log*
    - /var/lib/mysql/{{.builtin.hostname}}-slow.log
  exclude_files: ['.gz$']
  multiline:
    pattern: '^# User@Host: '
    negate: true
    match: after
  exclude_lines: ['^[\/\w\.]+, Version: .* started with:.*'] # Exclude the header

```

in logstash:

```auto
input {
  beat {
    port => 5044
  }
}

outputs {
  elasticsearch {
    hosts => "localhost:9200"
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
    pipeline => "%{[fields][pipeline]}"
  }
}

```

Here we configure the `fields.pipeline` event field in filebeat and use the field in the logstash output to use the ingest pipeline configured in filebeat. The pipeline you will have to install by yourself using curl on the modules pipeline definition (shipped with filebeat). Look for the ingest directories in the modules file, to find the json file defining the pipeline. With curl, the file can be installed into ES using the [ingest API](https://www.elastic.co/guide/en/elasticsearch/reference/current/put-pipeline-api.html) as is. Again, this is a not so nice workaround. Better connect Filebeat directly to Elastchsearch if you want to use modules and the dashboards.

---

<div class="post-metadata">

**Author:** ![Amna\_sayed\_ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amna_sayed_ali/32/45433_2.png) [@Amna\_sayed\_ali](https://discuss.elastic.co/u/Amna_sayed_ali)\
**Post date:** [June 21, 2017, 10:06pm UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/10 "2017-06-21T22:06:15Z")

</div>

> [@steffens](#):
>
> increasing the client\_inconnectivity\_timeout in the beats input

Hi Steffens,  
really thanks for ur reply.  
for the dashbboard issue, i have installed (elasticsearc, filebeat+modues and kibana) on test machine and some dashboards worked fine.

for the harvester ( the filebeat path only one log file, for example if i definded prospectors "/var/log/message & /var/log/secure& /usr/local/apache/log/_/_.log",  
the filebeat.harvester open only one file like message so in filebeat index i can see the logs for one file) issue actually i tried 2 scenarios

1st: increase the client\_inconnectivity\_timeout in the beats input  
logstash.conf  
input {  
beats {  
port =\> 5044  
client\_inactivity\_timeout =\> 120  
}  
}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

2nd: remove logstash and redirect filebeat output to elasticsearch directly.

although trying both, the issue still exist and i see only one log file in filebeat index so how can i see all log files that i defined in filebeat.yml

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 22, 2017, 10:11am UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/11 "2017-06-22T10:11:06Z")

</div>

Have you checked the `source` field?

Also check the registry file (it's JSON formatted), for your files to be present and the file offsets. Maybe filebeat is thinking it did already process these files? Deleting single entries from registry file (or complete registry file), should make filebeat sending the logs again.

Have you checked filebeat logs? Filebeat normally logs a message when it starts reading a file and when it closes a file, due to missing updates.

---

<div class="post-metadata">

**Author:** ![Amna\_sayed\_ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amna_sayed_ali/32/45433_2.png) [@Amna\_sayed\_ali](https://discuss.elastic.co/u/Amna_sayed_ali)\
**Post date:** [June 22, 2017, 10:34am UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/12 "2017-06-22T10:34:40Z")

</div>

Hello Steffens,  
hoping all is good with u.... and thnx for ur support 🙂

[Have you checked the source field?]  
what do u mean source field? u mean the source files..?

[Also check the registry file (it's JSON formatted), for your files to be present and the file offsets. Maybe filebeat is thinking it did already process these files? Deleting single entries from registry file (or complete registry file), should make filebeat sending the logs again.]

where can i find the registry file ? and how can i delete it?

[Have you checked filebeat logs? Filebeat normally logs a message when it starts reading a file and when it closes a file, due to missing updates.]

ys i have check the logs. the below is part of them  
2017-06-22T10:31:09+01:00 INFO No non-zero metrics in the last 30s  
2017-06-22T10:31:20+01:00 INFO Harvester started for file: /var/log/secure  
2017-06-22T10:31:39+01:00 INFO Non-zero metrics in the last 30s: filebeat.harvester.open\_files=1 filebeat.harvester.running=1 filebeat.harvester.started=1 libbeat.es.call\_count.PublishEvents=1 libbeat.es.publish.read\_bytes=339 libbeat.es.publish.write\_bytes=557 libbeat.es.published\_and\_acked\_events=1 libbeat.publisher.published\_events=1 publish.events=2 registrar.states.update=2 registrar.writes=1  
2017-06-22T10:32:09+01:00 INFO No non-zero metrics in the last 30s  
2017-06-22T10:32:39+01:00 INFO No non-zero metrics in the last 30s  
2017-06-22T10:33:09+01:00 INFO No non-zero metrics in the last 30s  
2017-06-22T10:33:39+01:00 INFO Non-zero metrics in the last 30s: libbeat.es.call\_count.PublishEvents=1 libbeat.es.publish.read\_bytes=383 libbeat.es.publish.write\_bytes=4189 libbeat.es.published\_and\_acked\_events=11 libbeat.publisher.published\_events=11 publish.events=11 registrar.states.update=11 registrar.writes=1  
2017-06-22T10:34:09+01:00 INFO No non-zero metrics in the last 30s  
2017-06-22T10:34:39+01:00 INFO No non-zero metrics in the last 30s  
2017-06-22T10:35:09+01:00 INFO Non-zero metrics in the last 30s: libbeat.es.call\_count.PublishEvents=1 libbeat.es.publish.read\_bytes=366 libbeat.es.publish.write\_bytes=2361 libbeat.es.published\_and\_acked\_events=6 libbeat.publisher.published\_events=6 publish.events=6 registrar.states.update=6 registrar.writes=1  
2017-06-22T10:35:39+01:00 INFO No non-zero metrics in the last 30s  
2017-06-22T10:36:09+01:00 INFO No non-zero metrics in the last 30s  
2017-06-22T10:36:39+01:00 INFO Non-zero metrics in the last 30s: libbeat.es.call\_count.PublishEvents=2 libbeat.es.publish.read\_bytes=727 libbeat.es.publish.write\_bytes=4392 libbeat.es.published\_and\_acked\_events=11 libbeat.publisher.published\_events=11 publish.events=11 registrar.states.update=11 registrar.writes=2  
2017-06-22T10:37:09+01:00 INFO No non-zero metrics in the last 30s  
2017-06-22T10:37:39+01:00 INFO No non-zero metrics in the last 30s  
2017-06-22T10:38:09+01:00 INFO Non-zero metrics in the last 30s: libbeat.es.call\_count.PublishEvents=1 libbeat.es.publish.read\_bytes=335 libbeat.es.publish.write\_bytes=558 libbeat.es.published\_and\_acked\_events=1 libbeat.pu \>

---

<div class="post-metadata">

**Author:** ![Amna\_sayed\_ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amna_sayed_ali/32/45433_2.png) [@Amna\_sayed\_ali](https://discuss.elastic.co/u/Amna_sayed_ali)\
**Post date:** [June 22, 2017, 1:57pm UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/13 "2017-06-22T13:57:49Z")

</div>

just found the registry file and removed it after that created with some of paths not all so where 's the remain paths ☹ ?

# registry file

[{"source":"/var/log/secure","offset":1081687,"FileStateOS":{"inode":9047291,"device":64768},"timestamp":"2017-06-21T22:42:18.401330821+01:00","ttl":-2},{"source":"/var/log/mysqld.log","offset":164974,"FileStateOS":{"inode":9044404,"device":64768},"timestamp":"2017-06-21T22:42:18.401332698+01:00","ttl":-2},{"source":"/var/log/secure","offset":9815004,"FileStateOS":{"inode":9047512,"device":64768},"timestamp":"2017-06-22T11:48:19.388508856+01:00","ttl":-2}]

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [June 26, 2017, 10:59am UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/14 "2017-06-26T10:59:56Z")

</div>

Sorry, kind of lost track on this discussion. To not mix two issues into this discussion (the dashboard one was quite interesting), can you open another disucssion with your full actual filebeat configuration, logs and registry file (Please use the `</>` button in the editor it's toolbar)? Having a separate discussion, other users/devs knowing better about this problem might join in.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2017, 11:00am UTC](https://discuss.elastic.co/t/the-filebeat-dashboard-no-results-found/89479/15 "2017-07-24T11:00:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
