# "There is no data to display" on metric page

**URL:** <https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361>\
**Category:** Metrics\
**Created:** [June 12, 2019, 8:48am UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361 "2019-06-12T08:48:31Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![aqiank](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aqiank/32/39723_2.png) [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Post date:** [June 12, 2019, 8:48am UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/1 "2019-06-12T08:48:32Z")

</div>

I found this message in one of the HTTP requests when loading the metrics page.

```auto
[illegal_argument_exception] Fielddata is disabled on text fields by default. Set fielddata=true on [host.name] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead.

```

But **host.name** in my case is already a **keyword** field so I don't know what to do next. Does anyone know how to solve this problem?

I have the index mapping [here](https://paste.fedoraproject.org/paste/gRUnPMT5Gmy0HC3ZBXouyQ) if it helps.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [June 12, 2019, 9:09am UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/2 "2019-06-12T09:09:37Z")

</div>

Hi @aqiank,

is it possible that there are indices matching `filebeat-*` in which `host.name` is not a keyword? The Infra UI tries to access the configured log indices for the "log rate" metric, so there might be a mapping conflict between the metricbeat and filebeat indices.

---

<div class="post-metadata">

**Author:** ![aqiank](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aqiank/32/39723_2.png) [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Post date:** [June 12, 2019, 9:22am UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/3 "2019-06-12T09:22:06Z")

</div>

Hi @weltenwort,

Does `filebeat-*` affect the metric page? I was under the impression that only the `metricbeat-*` affects the page. I tried to set it so it only looks for a specific index such as `metricbeat-7.1.1-2019.05.30-000001`.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [June 12, 2019, 12:36pm UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/4 "2019-06-12T12:36:52Z")

</div>

There are some queries where it accesses the log indices too, which is why they share the same source configuration. Could you try out one of the following:

- If you have `filebeat-*` indices and use the Logs UI, make sure these indices also have the correct ECS-compatible mapping.
- If you have `filebeat-*` indices and don't use the Logs UI, set the `log indices` source configuration to something that doesn't exist, e.g. `no-index-with-this-name-*`.

If you don't have `filebeat-*` indices, we have to look for a different cause. 😉

---

<div class="post-metadata">

**Author:** ![aqiank](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aqiank/32/39723_2.png) [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Post date:** [June 12, 2019, 1:08pm UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/5 "2019-06-12T13:08:47Z")

</div>

I just deleted the `filebeat-*` indices which weren't used anymore and it seems like the page still displays "There is no data to display". When I check the browser logs, I found these:

```auto
Content Security Policy: Directive ‘child-src’ has been deprecated. Please use directive ‘worker-src’ to control workers, or directive ‘frame-src’ to control frames respectively.
Content Security Policy: The page’s settings blocked the loading of a resource at inline (“script-src”). infra:1:1
Content Security Policy: The page’s settings blocked the loading of a resource at inline (“script-src”). infra:372:1
^ A single error about an inline script not firing due to content security policy is expected! bootstrap.js:10:20
window.controllers/Controllers is deprecated. Do not use it for UA detection. vendors.bundle.dll.js:62:739542

```

I'm not sure if they are related though.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [June 12, 2019, 2:00pm UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/6 "2019-06-12T14:00:19Z")

</div>

As mentioned, a single error is expected. But in your case there seem to be additional problems with how the browser handels CSP. What version of which browser are you using?

Those errors are probably not related to the problem of data not showing up. The error message about the fielddata being disabled persists even though you deleted the filebeat indices? What are the "metric indices" and "log indices" settings you are using?

---

<div class="post-metadata">

**Author:** ![aqiank](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aqiank/32/39723_2.png) [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Post date:** [June 12, 2019, 2:36pm UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/7 "2019-06-12T14:36:50Z")

</div>

Hi @weltenwort,

My browser is Firefox 67 on Linux and macOS.

My metricbeat settings is [here](https://paste.fedoraproject.org/paste/eGXTKNzG7y26i9habqPmwQ).

My log settings is [here](https://paste.fedoraproject.org/paste/c4xH4sww~uNIqKMcnnP85Q).

I noticed the `host.name` on my `logstash` index is of type **text** that also has the field **keyword**. But if I set the **Host name** to `host.name.keyword` on the infrastructure page, I can't see my hosts and get into the metrics page.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [June 13, 2019, 9:32am UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/8 "2019-06-13T09:32:29Z")

</div>

Ok, and would you also be able to show the indices set in the infra ui source configuration?

 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/7/b/7bc4967296a2f2368a26512deaab0b87ec66743b.png)

---

<div class="post-metadata">

**Author:** ![aqiank](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aqiank/32/39723_2.png) [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Post date:** [June 13, 2019, 10:55am UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/9 "2019-06-13T10:55:52Z")

</div>

Hi @weltenwort,

Certainly. Here it is.

![Screenshot%20from%202019-06-13%2018-55-18](https://us1.discourse-cdn.com/elastic/original/3X/d/f/dfa024298faa2295a492b92eefbedc7f4a0fc91c.png)

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [June 13, 2019, 11:06am UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/10 "2019-06-13T11:06:08Z")

</div>

Thank you for providing these details.

Looks like not having `host.name` being of the `keyword` type in the `logstash` index is indeed the cause. The fact that you have a `host.name.keyword` field indicates that you are using a dynamic mapping, because that is what Elasticsearch infers for text fields by default.

Are you using logstash to forward log entries read by filebeat or do you perform custom log parsing with logstash?

---

<div class="post-metadata">

**Author:** ![aqiank](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aqiank/32/39723_2.png) [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Post date:** [June 13, 2019, 3:06pm UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/11 "2019-06-13T15:06:55Z")

</div>

Hi @weltenwort,

Yes, I use Logstash to remove color codes from logs so the raw color code characters don't appear in the Kibana's log page.

Do you have any recommendation on what to do to satisfy the metric page? I find it odd that it needs the log data (e.g. what would happen if I don't send logs to Elasticsearch and just the metricbeat data?).

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [June 13, 2019, 5:03pm UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/12 "2019-06-13T17:03:34Z")

</div>

If the there were no indices that match the "log indices" settings, there shouldn't be any influence on the metrics.

I would recommend to use an appropriate static mapping for the log indices too. When sending the log entries from filebeat to Elasticsearch via logstash, though, filebeat can't install its index template. I would recommend to run [`filebeat setup --template`](https://www.elastic.co/guide/en/beats/filebeat/current/command-line-options.html#setup-command) to install the index templates and to preserve the `filebeat-*` index names even when sending via logstash.

If you only use logstash for performing the message processing as you described, you might want to look at performing this in an [`gsub` processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/gsub-processor.html) in an ingest pipeline in Elasticsearch directly. That way you could avoid having to run a separate logstash instance and would reduce the risk of running into mapping problems.

---

<div class="post-metadata">

**Author:** ![aqiank](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aqiank/32/39723_2.png) [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Post date:** [June 14, 2019, 2:49am UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/13 "2019-06-14T02:49:14Z")

</div>

Hi @weltenwort,

Do you mean the metrics should show if I use non-existent index? If I set log indices to look for non-existent index, it shows this error on the metrics page:

 ![31%20AM](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cd290579a273108052eec94349243eea40513999.png)

And thanks for the advice on the log indices. I'll take your advice!

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [June 14, 2019, 9:00am UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/14 "2019-06-14T09:00:47Z")

</div>

Is this the "inventory" page or the metrics for a specific host?

---

<div class="post-metadata">

**Author:** ![aqiank](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aqiank/32/39723_2.png) [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Post date:** [June 14, 2019, 9:03am UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/15 "2019-06-14T09:03:10Z")

</div>

Hi @weltenwort,

This is the metrics for a specific host.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [June 14, 2019, 12:20pm UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/16 "2019-06-14T12:20:17Z")

</div>

I could reproduce the effect and it looks like a bug. I will file a GitHub issue. In the meantime, try using a wildcard in the logs index setting, e.g. `qwerty*`.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [June 14, 2019, 12:52pm UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/17 "2019-06-14T12:52:50Z")

</div>

Thank you for patiently walking me through the process of reproducing it. I have created a fix in [https://github.com/elastic/kibana/pull/38976](https://github.com/elastic/kibana/pull/38976). Feel free to verify it or just follow the PR progress.

---

<div class="post-metadata">

**Author:** ![aqiank](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aqiank/32/39723_2.png) [@aqiank](https://discuss.elastic.co/u/aqiank)\
**Post date:** [June 15, 2019, 4:20am UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/18 "2019-06-15T04:20:22Z")

</div>

Hi @weltenwort,

Thank you for the fix. Using wildcard does indeed make it work!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2019, 4:20am UTC](https://discuss.elastic.co/t/there-is-no-data-to-display-on-metric-page/185361/19 "2019-07-13T04:20:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
