# Unable see logs In kibana after 15 minutes

**URL:** <https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462>\
**Category:** Kibana\
**Created:** [April 18, 2018, 5:56am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462 "2018-04-18T05:56:09Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![nikbhadane](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@nikbhadane](https://discuss.elastic.co/u/nikbhadane)\
**Post date:** [April 18, 2018, 5:56am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/1 "2018-04-18T05:56:09Z")

</div>

Hi there,  
I am new in ELK, and I setup the ELK first time on my local machine. After restarting filebeat on client i am able to see logs on kibana dashboard. But after 15 mins. I am unable to see any logs and getting "No results found" i tried very hard to figure out what is happening but fails.

I also tried recreating index but getting same issue.

i am also looking to expand time range but don't know how to do that.

Please help me resolve this:

Kibana version: 4.5.4  
Elasticsearch version: 2.X  
logstash Version : 2.2

 ![filebeat_index](https://us1.discourse-cdn.com/elastic/original/3X/1/3/13302aba0b119b349d1dd7b3e55a6b11758578a0.png)

---

<div class="post-metadata">

**Author:** ![PolterFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polterfox/32/29781_2.png) [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Post date:** [April 18, 2018, 6:24am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/2 "2018-04-18T06:24:07Z")

</div>

> [@nikbhadane](#):
>
> i am also looking to expand time range but don't know how to do that.

In Kibana 4.5 you can set the time range in the right upper corner. In the tab "Quick" you can find the time range "Today". Click on it, perhaps you´ve selected a time range while clicking on a control in a dashboard.

Do you find any messages on the page "Discover" ?

---

<div class="post-metadata">

**Author:** ![nikbhadane](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@nikbhadane](https://discuss.elastic.co/u/nikbhadane)\
**Post date:** [April 18, 2018, 6:55am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/3 "2018-04-18T06:55:30Z")

</div>

Yes  
In Quick-\>Today  
I found the logs which are available previously in Discover.

But for Quick-\>Last 15 minutes  
i am getting the "No results found".

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [April 18, 2018, 7:01am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/4 "2018-04-18T07:01:23Z")

</div>

Is the filebeat still running and producing log? Might there just not be any logs in the past 15 minutes?

If you are 100% sure, it might still be an issue with timezones, that the filebeat is delivering the time of the events in another timezone than your Kibana/Browser is set up to.

---

<div class="post-metadata">

**Author:** ![nikbhadane](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@nikbhadane](https://discuss.elastic.co/u/nikbhadane)\
**Post date:** [April 18, 2018, 7:09am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/5 "2018-04-18T07:09:06Z")

</div>

Filebeat is in active(running) state.

For the timezone client machine (where filebeat is running) is having UTC time zone.  
and the browser i am accessing kibana showing log status with local time zone.

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [April 18, 2018, 7:10am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/6 "2018-04-18T07:10:50Z")

</div>

Try to go to Management \> Kibana \> Advanced Settings and switch the `dateFormat:tz` setting to `UTC` too.

---

<div class="post-metadata">

**Author:** ![nikbhadane](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@nikbhadane](https://discuss.elastic.co/u/nikbhadane)\
**Post date:** [April 18, 2018, 7:20am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/7 "2018-04-18T07:20:54Z")

</div>

Did the changes but still unable to see latest log.

timezone setting of UTC reflected in Discover(log messages).

---

<div class="post-metadata">

**Author:** ![PolterFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polterfox/32/29781_2.png) [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Post date:** [April 18, 2018, 7:26am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/8 "2018-04-18T07:26:06Z")

</div>

Is Logstash running? Have you set any filters that affect that messages don´t send to kibana or in a other index?

Look into the logs of logstash perhaps logstash can not connect to your ES.

---

<div class="post-metadata">

**Author:** ![nikbhadane](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@nikbhadane](https://discuss.elastic.co/u/nikbhadane)\
**Post date:** [April 18, 2018, 7:32am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/9 "2018-04-18T07:32:47Z")

</div>

Logstash is in running state, and by looking into the status(logstash.log,logstash.err) no errors found in logstash.

I haven't set any filters.

---

<div class="post-metadata">

**Author:** ![nikbhadane](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@nikbhadane](https://discuss.elastic.co/u/nikbhadane)\
**Post date:** [April 18, 2018, 8:15am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/10 "2018-04-18T08:15:00Z")

</div>

I guess it is not fetching real time log unless and until i restart the filbeat service on client node.

But all the Elasticsearch, logstash are working fine.Filebeat also. But still not able to fetch recent logs.

---

<div class="post-metadata">

**Author:** ![PolterFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polterfox/32/29781_2.png) [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Post date:** [April 18, 2018, 8:19am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/11 "2018-04-18T08:19:13Z")

</div>

I do not believe you did that, but it could be a potential source of error: did you create a scripted field to calculate something (whose value is not always given)?

---

<div class="post-metadata">

**Author:** ![nikbhadane](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@nikbhadane](https://discuss.elastic.co/u/nikbhadane)\
**Post date:** [April 18, 2018, 8:23am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/12 "2018-04-18T08:23:50Z")

</div>

i haven't created any script.

I tried it on another environment also but facing the same issue.

---

<div class="post-metadata">

**Author:** ![nikbhadane](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@nikbhadane](https://discuss.elastic.co/u/nikbhadane)\
**Post date:** [April 18, 2018, 8:26am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/13 "2018-04-18T08:26:45Z")

</div>

I referred the below document for installation and configuration.

"[https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-14-04](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elk-stack-on-ubuntu-14-04)"

---

<div class="post-metadata">

**Author:** ![PolterFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polterfox/32/29781_2.png) [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Post date:** [April 18, 2018, 9:15am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/14 "2018-04-18T09:15:02Z")

</div>

I see you have a filter in the logstash config where you look for syslogs etc.  
I don´t know but perhaps your filter is misconfigured? Check this so far.

Do you use your ELK Stack for production ? If not, you can configure a another index for your data, to see if you got data from your system.

---

<div class="post-metadata">

**Author:** ![nikbhadane](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@nikbhadane](https://discuss.elastic.co/u/nikbhadane)\
**Post date:** [April 18, 2018, 9:45am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/15 "2018-04-18T09:45:21Z")

</div>

Thank you for guidelines.

I updated logstash config file with new filter. And also updated the filebeat.yml with same name.  
But still facing the same issues.

filter {  
if [type] == "DataLogs" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:DataLogs\_timestamp} %{SYSLOGHOST:DataLogs\_hostname} %{DATA:DataLogs\_program}(?:[%{POSINT:DataLogs\_pid}])?: %{GREEDYDATA:DataLogs\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["DataLogs\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

Can you please tell me how to configure logstash without applying filter?

Or any default configuration for logstash.

---

<div class="post-metadata">

**Author:** ![PolterFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polterfox/32/29781_2.png) [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Post date:** [April 18, 2018, 10:05am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/16 "2018-04-18T10:05:50Z")

</div>

> [@nikbhadane](#):
>
> Can you please tell me how to configure logstash without applying filter?

If you want no filter you don´t need to write anything in the filter section of the logstash config. You just need the following lines

> **Filter-Section**
>
> ```
> filter{
> }
> 
> ```

and thats it, now you have no filter in your config.

But please think about it, grok match is a pattern which makes your data structured and queryable and without this you get the blank data send into your ES.

---

<div class="post-metadata">

**Author:** ![nikbhadane](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@nikbhadane](https://discuss.elastic.co/u/nikbhadane)\
**Post date:** [April 18, 2018, 10:38am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/17 "2018-04-18T10:38:05Z")

</div>

After setting no fileter, i am facing same issue.The Kibana is not updating the latest logs.  
I think the problem is not with logstash filter.

---

<div class="post-metadata">

**Author:** ![PolterFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polterfox/32/29781_2.png) [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Post date:** [April 18, 2018, 10:41am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/18 "2018-04-18T10:41:13Z")

</div>

Okay... can you send me the indices you have created/configured in Kibana ?  
Oh and it would be nice if you send me your complete logstash config, so I can see what logstash is doing with your data.

---

<div class="post-metadata">

**Author:** ![nikbhadane](https://avatars.discourse-cdn.com/v4/letter/n/ecb155/32.png) [@nikbhadane](https://discuss.elastic.co/u/nikbhadane)\
**Post date:** [April 18, 2018, 10:56am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/19 "2018-04-18T10:56:17Z")

</div>

![FilebeatIndices](https://us1.discourse-cdn.com/elastic/original/3X/c/3/c3adc135d79e3bf4719b0be22661abbbda2ca450.png)  
Above image is for indices with fields.

And 3 configurations files of logstash as below

root@ubuntu-xenial:/etc/logstash/conf.d# cat 02-beats-input.conf  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

root@ubuntu-xenial:/etc/logstash/conf.d# cat 10-syslog-filter.conf  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

root@ubuntu-xenial:/etc/logstash/conf.d# cat 30-elasticsearch-output.conf  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

---

<div class="post-metadata">

**Author:** ![PolterFox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polterfox/32/29781_2.png) [@PolterFox](https://discuss.elastic.co/u/PolterFox)\
**Post date:** [April 18, 2018, 11:17am UTC](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462/20 "2018-04-18T11:17:12Z")

</div>

Can you run this on the server where ES is running ?  
`curl 'localhost:9200/_cat/indices?v'`  
OR  
`curl -XGET http://localhost:9200/_cat/indices?v`

This will return all indices in ES. Please post the return value here.

[Next page](https://discuss.elastic.co/t/unable-see-logs-in-kibana-after-15-minutes/128462.md?page=2)
