# There is no data in kibana

**URL:** <https://discuss.elastic.co/t/there-is-no-data-in-kibana/109332>\
**Category:** Kibana\
**Created:** [November 28, 2017, 8:18am UTC](https://discuss.elastic.co/t/there-is-no-data-in-kibana/109332 "2017-11-28T08:18:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![antony.y](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@antony.y](https://discuss.elastic.co/u/antony.y)\
**Post date:** [November 28, 2017, 8:18am UTC](https://discuss.elastic.co/t/there-is-no-data-in-kibana/109332/1 "2017-11-28T08:18:19Z")

</div>

I have lots of cisco switches and i've configured the devices to send syslogs to my logstash,the output plugin is elasticsearch.But it didn't take effect on some of the devices ,i have checked the status of the elasticsearch and logstash but i can not find any error.I do not know why.The configuration is as below.

version" : {  
"number" : "5.6.3",  
"build\_hash" : "1a2f265",  
"build\_date" : "2017-10-06T20:33:39.012Z",  
"build\_snapshot" : false,  
"lucene\_version" : "6.6.1"  
},

the status of the index is  
green open network-log-2017.11.28 0yA8wO7oTKSa5vkqXdk19Q 5 1 4245 0 5.1mb 2.5mb

when i generated some logs i can see the number of the documents keep increasing, but i can not find that in kibana

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 28, 2017, 9:46am UTC](https://discuss.elastic.co/t/there-is-no-data-in-kibana/109332/2 "2017-11-28T09:46:19Z")

</div>

Probably a misconfiguration of the index pattern in Kibana?

I moved your question to #kibana.

---

<div class="post-metadata">

**Author:** ![antony.y](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@antony.y](https://discuss.elastic.co/u/antony.y)\
**Post date:** [November 28, 2017, 10:01am UTC](https://discuss.elastic.co/t/there-is-no-data-in-kibana/109332/3 "2017-11-28T10:01:55Z")

</div>

i do not think so , i've tried to make a troubleshooting,and i found that when i change the input to udp , it does work! i thought it's the problem of the tcp input plugin.But i have no idea how to solve it

---

<div class="post-metadata">

**Author:** ![antony.y](https://avatars.discourse-cdn.com/v4/letter/a/91b2a8/32.png) [@antony.y](https://discuss.elastic.co/u/antony.y)\
**Post date:** [November 29, 2017, 5:40am UTC](https://discuss.elastic.co/t/there-is-no-data-in-kibana/109332/4 "2017-11-29T05:40:11Z")

</div>

Hi are you still there ?  
I had tried to using tcpdump , and i found that the syslog was indeed sent to the logstash . In the meantime , i configured the output as a file,if there is any pattern error , i can see that in the log,but now i can not find any error in the log,that's why i am sure it's not the problem of the pattern

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2017, 5:40am UTC](https://discuss.elastic.co/t/there-is-no-data-in-kibana/109332/5 "2017-12-27T05:40:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
