# Timelion shows 0 count in .monotoring-\* indices

**URL:** <https://discuss.elastic.co/t/timelion-shows-0-count-in-monotoring-indices/89735>\
**Category:** Elasticsearch\
**Created:** [June 16, 2017, 2:59pm UTC](https://discuss.elastic.co/t/timelion-shows-0-count-in-monotoring-indices/89735 "2017-06-16T14:59:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikolay\_Shushkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolay_shushkin/32/13809_2.png) [@Nikolay\_Shushkin](https://discuss.elastic.co/u/Nikolay_Shushkin)\
**Post date:** [June 16, 2017, 2:59pm UTC](https://discuss.elastic.co/t/timelion-shows-0-count-in-monotoring-indices/89735/1 "2017-06-16T14:59:10Z")

</div>

There are .monitoring indices in elasticsearch, but timelion shows 0 count in all of them

> green open .monitoring-es-2-2017.06.15 pFz6Q-zmR124GWlrBndM4A 1 1 2549064 30425 2.9gb 1.4gb  
> green open .monitoring-es-2-2017.06.16 3bEfPiWCRHyT8CLNZdv5lw 1 1 1436472 21735 1.7gb 911.5mb  
> green open .monitoring-kibana-2-2017.06.15 \_xQOnYqdQaCghi2prEEP9w 1 1 8638 0 3.7mb 1.8mb  
> green open .monitoring-kibana-2-2017.06.16 JrM9z4xfQ1mnS0Eiwfi2Tw 1 1 4804 0 2.1mb 1mb  
> green open .monitoring-logstash-2-2017.06.15 hXEfMPaNQe6G\_TNqglZtPQ 1 1 17276 0 8.6mb 4.3mb  
> green open .monitoring-logstash-2-2017.06.16 FMAGgHC5Sc6CD9JY0ZH7Rg 1 1 9606 0 4.6mb 2.3mb

However count is 0 in timelion for all of them. E.g:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/2/7/27e9f9be0029926bac53531ffb6c22756bda1cce.png)

Do I do something wrong?

---

<div class="post-metadata">

**Author:** ![bohyun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bohyun/32/10087_2.png) [@bohyun](https://discuss.elastic.co/u/bohyun)\
**Post date:** [June 18, 2017, 8:53pm UTC](https://discuss.elastic.co/t/timelion-shows-0-count-in-monotoring-indices/89735/2 "2017-06-18T20:53:36Z")

</div>

Hi @Nikolay_Shushkin

Did you configure `timelion:es.timefield` to be `timestamp` in Kibana's Advanced Settings? It's `@timestamp` by default and to query the monitoring indices, you will need to change that as shown below.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0eddfa54fd98d2ddd61bb4bce28df6d195ec91f8.png)

After you've changed the setting, start querying the .monitoring index by

`.es(index='.monitoring-es-2-*', timefield='timestamp', metric='avg:node_stats.indices.segments.count')`

You can switch the index with logstash monitoring index, and choose the specific field that you want to visualize.

For more examples, please visit the [Timelion getting started guide](https://www.elastic.co/guide/en/kibana/current/timelion-getting-started.html).

Thanks,  
Bohyun

---

<div class="post-metadata">

**Author:** ![Nikolay\_Shushkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikolay_shushkin/32/13809_2.png) [@Nikolay\_Shushkin](https://discuss.elastic.co/u/Nikolay_Shushkin)\
**Post date:** [June 19, 2017, 10:48am UTC](https://discuss.elastic.co/t/timelion-shows-0-count-in-monotoring-indices/89735/3 "2017-06-19T10:48:35Z")

</div>

Thank you Bohyun.

I hope got the problem.  
But don't you think that only one of the actions has to be done:  
either change timelion:es.timefield to be timestamp  
or always use timefield='timestamp' in .es queries  
?  
It works as I can see.

Anyway, thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2017, 10:48am UTC](https://discuss.elastic.co/t/timelion-shows-0-count-in-monotoring-indices/89735/4 "2017-07-17T10:48:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
