# Unable to see older logs in kibana after restarting the ELK

**URL:** <https://discuss.elastic.co/t/unable-to-see-older-logs-in-kibana-after-restarting-the-elk/248818>\
**Category:** Kibana\
**Tags:** docker, kql-kibana-query-language\
**Created:** [September 16, 2020, 10:45am UTC](https://discuss.elastic.co/t/unable-to-see-older-logs-in-kibana-after-restarting-the-elk/248818 "2020-09-16T10:45:47Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![neelu\_patel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelu_patel/32/75675_2.png) [@neelu\_patel](https://discuss.elastic.co/u/neelu_patel)\
**Post date:** [September 16, 2020, 10:45am UTC](https://discuss.elastic.co/t/unable-to-see-older-logs-in-kibana-after-restarting-the-elk/248818/1 "2020-09-16T10:45:47Z")

</div>

Unable to see older logs in kibana after restarting the ELK. please give your best suggestions.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 16, 2020, 10:51am UTC](https://discuss.elastic.co/t/unable-to-see-older-logs-in-kibana-after-restarting-the-elk/248818/2 "2020-09-16T10:51:21Z")

</div>

Welcome to our community! 😃

Please provide more information.  
What version are you using?  
Are you using docker? What does your config look like?  
What do the Elasticsearch logs show?

---

<div class="post-metadata">

**Author:** ![neelu\_patel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelu_patel/32/75675_2.png) [@neelu\_patel](https://discuss.elastic.co/u/neelu_patel)\
**Post date:** [September 17, 2020, 5:51am UTC](https://discuss.elastic.co/t/unable-to-see-older-logs-in-kibana-after-restarting-the-elk/248818/3 "2020-09-17T05:51:13Z")

</div>

Thank for your reply.  
yes we are using docker and currently elastic search is showing all the current logs and after we have restarted the ELK we are unable to see the older logs.

elk version : 7.7.1 and config file of docker i have attached. if you required anything please revert us back.

 ![ls](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e873d9c9235add1b38224cd4b7fe4c02d8879d33.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 17, 2020, 5:51am UTC](https://discuss.elastic.co/t/unable-to-see-older-logs-in-kibana-after-restarting-the-elk/248818/4 "2020-09-17T05:51:32Z")

</div>

Please don't post pictures of text, they are difficult to read, impossible to search and replicate (if it's code), and some people may not be even able to see them 🙂

---

<div class="post-metadata">

**Author:** ![neelu\_patel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelu_patel/32/75675_2.png) [@neelu\_patel](https://discuss.elastic.co/u/neelu_patel)\
**Post date:** [September 17, 2020, 5:58am UTC](https://discuss.elastic.co/t/unable-to-see-older-logs-in-kibana-after-restarting-the-elk/248818/5 "2020-09-17T05:58:22Z")

</div>

Actually in upload section , they are not accepting text files. is there any other way to upload the config file.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 17, 2020, 6:01am UTC](https://discuss.elastic.co/t/unable-to-see-older-logs-in-kibana-after-restarting-the-elk/248818/6 "2020-09-17T06:01:25Z")

</div>

Copy and paste it. Please do format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

---

<div class="post-metadata">

**Author:** ![neelu\_patel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelu_patel/32/75675_2.png) [@neelu\_patel](https://discuss.elastic.co/u/neelu_patel)\
**Post date:** [September 17, 2020, 6:22am UTC](https://discuss.elastic.co/t/unable-to-see-older-logs-in-kibana-after-restarting-the-elk/248818/7 "2020-09-17T06:22:08Z")

</div>

Okay i hope it will be useful.

```
    "Id": "670df04618cf636f58a56231d7e69546d707f82b506789f8a2004539fee86e04",
    "Created": "2020-09-16T14:17:39.894724143Z",
    "Path": "/usr/local/bin/start.sh",
    "Args": [],
    "State": {
        "Status": "running",
        "Running": true,
        "Paused": false,
        "Restarting": false,
        "OOMKilled": false,
        "Dead": false,
        "Pid": 8679,
        "ExitCode": 0,
        "Error": "",
        "StartedAt": "2020-09-16T14:17:40.460234211Z",
        "FinishedAt": "0001-01-01T00:00:00Z"
    },
    "Image": "sha256:bcb4da1ba9b8796cc1ba026d0f03478ce40579594644aeb9dd7e1597df78fd67",
    "ResolvConfPath": "/var/lib/docker/containers/670df04618cf636f58a56231d7e69546d707f82b506789f8a2004539fee86e04/resolv.conf",
    "HostnamePath": "/var/lib/docker/containers/670df04618cf636f58a56231d7e69546d707f82b506789f8a2004539fee86e04/hostname",
    "HostsPath": "/var/lib/docker/containers/670df04618cf636f58a56231d7e69546d707f82b506789f8a2004539fee86e04/hosts",
    "LogPath": "/var/lib/docker/containers/670df04618cf636f58a56231d7e69546d707f82b506789f8a2004539fee86e04/670df04618cf636f58a56231d7e69546d707f82b506789f8a2004539fee86e04-json.log",
    "Name": "/elk",
    "RestartCount": 0,
    "Driver": "overlay2",
    "Platform": "linux",
    "MountLabel": "",
    "ProcessLabel": "",
    "AppArmorProfile": "docker-default",
    "ExecIDs": null,
    "HostConfig": {
        "Binds": null,
        "ContainerIDFile": "",
        "LogConfig": {
            "Type": "json-file",
            "Config": {}
        },
        "NetworkMode": "default",
        "PortBindings": {
            "5044/tcp": [
                {
                    "HostIp": "",
                    "HostPort": "5044"
                }
            ],
            "5601/tcp": [
                {
                    "HostIp": "",
                    "HostPort": "5601"
                }
            ],
            "9200/tcp": [
                {
                    "HostIp": "",
                    "HostPort": "9200"
                }
            ]
        },
        "RestartPolicy": {
            "Name": "no",
            "MaximumRetryCount": 0
        },
        "AutoRemove": false,
        "VolumeDriver": "",
        "VolumesFrom": null,
        "CapAdd": null,
        "CapDrop": null,
        "Capabilities": null,
        "Dns": [],
        "DnsOptions": [],
        "DnsSearch": [],
        "ExtraHosts": null,
        "GroupAdd": null,
        "IpcMode": "private",
        "Cgroup": "",
        "Links": null,
        "OomScoreAdj": 0,
        "PidMode": "",
        "Privileged": false,
        "PublishAllPorts": false,
        "ReadonlyRootfs": false,
        "SecurityOpt": null,
        "UTSMode": "",
        "UsernsMode": "",
        "ShmSize": 67108864,
        "Runtime": "runc",
        "ConsoleSize": [
            0,
            0
        ],
        "Isolation": "",
        "CpuShares": 0,
        "Memory": 0,
        "NanoCpus": 0,
        "CgroupParent": "",
        "BlkioWeight": 0,
        "BlkioWeightDevice": [],
        "BlkioDeviceReadBps": null,
        "BlkioDeviceWriteBps": null,
        "BlkioDeviceReadIOps": null,
        "BlkioDeviceWriteIOps": null,
        "CpuPeriod": 0,
        "CpuQuota": 0,
        "CpuRealtimePeriod": 0,
        "CpuRealtimeRuntime": 0,
        "CpusetCpus": "",
        "CpusetMems": "",
        "Devices": [],
        "DeviceCgroupRules": null,
        "DeviceRequests": null,
        "KernelMemory": 0,
        "KernelMemoryTCP": 0,
        "MemoryReservation": 0,
        "MemorySwap": 0,
        "MemorySwappiness": null,
        "OomKillDisable": false,
        "PidsLimit": null,
        "Ulimits": null,
        "CpuCount": 0,
        "CpuPercent": 0,
        "IOMaximumIOps": 0,
        "IOMaximumBandwidth": 0,
        "MaskedPaths": [
            "/proc/asound",
            "/proc/acpi",
            "/proc/kcore",
            "/proc/keys",
            "/proc/latency_stats",
            "/proc/timer_list",
            "/proc/timer_stats",
            "/proc/sched_debug",
            "/proc/scsi",
            "/sys/firmware"
        ],
        "ReadonlyPaths": [
            "/proc/bus",
            "/proc/fs",
            "/proc/irq",
            "/proc/sys",
            "/proc/sysrq-trigger"
        ]
    },
    "GraphDriver": {
        "Data": {
            "LowerDir": "/var/lib/docker/overlay2/bda07ec61204dd2a9a359b967251d73ffd09250f1dfc84e7498f88d70ba140f3-:/var/lib/docker/overlay2/6fce2444f744a1dc7ecc73282aaa6f11c2db1264291e6f875fca73bfe0f48277/diff:/var/lib/docker/overlay2/3a6292b69fd6f5bc4f6705e92eed7d89e76931986be1a0bf0cccc45715bf53b1/diff:/var/lib/docker/overlay2/d510077bf90d7e72ad1445cd5e8cb71398109c76dedcc577b039c29a1b089b79/diff:/var/lib/docker/overlay2/b14910138bf5e426b2e845c007c9ef9f791a73ce4e853ba434c8240e1c817e46/diff:/var/lib/docker/overlay2/d88f16946a851f34a5b986cd33a3eceaa6b967a9953485eab28ef70bd09d65eb/diff:/var/lib/docker/overlay2/43f99b3b835307a4277f24fc6761dccc3f9fe4c3e2b52254665ce96381c78617/diff:/var/lib/docker/overlay2/44dc8bce6c2078d6db60553799c4879e0b9370df47f36472d1e1edcbf4cfc50c/diff:/var/lib/docker/overlay2/69fded522a8312b3071a43886d1ac014dbf56d5583e336cdc748f35a06766a6b/diff:/var/lib/docker/overlay2/30196afc7b2c974fbf53a65ec18bb695adfe336d8926c7dc78c2b6d93d046c88/diff",
            "MergedDir": "/var/lib/docker/overlay2/bda07ec61204dd2a9a359b967251d73ffd09250f1dfc84e7498f88d70ba140f3/merged",
            "UpperDir": "/var/lib/docker/overlay2/bda07ec61204dd2a9a359b967251d73ffd09250f1dfc84e7498f88d70ba140f3/diff",
            "WorkDir": "/var/lib/docker/overlay2/bda07ec61204dd2a9a359b967251d73ffd09250f1dfc84e7498f88d70ba140f3/work"
        },
        "Name": "overlay2"
    },
    "Mounts": [
        {
            "Type": "volume",
            "Name": "1d8d0f9d362ebdbd952a22132436e9092697c65dc3ca0d8aa801303862915527",
            "Source": "/var/lib/docker/volumes/1d8d0f9d362ebdbd952a22132436e9092697c65dc3ca0d8aa801303862915527/_data",
            "Destination": "/var/lib/elasticsearch",
            "Driver": "local",
            "Mode": "",
            "RW": true,
            "Propagation": ""
        }
    ],
    "Config": {
        "Hostname": "670df04618cf",
        "Domainname": "",
        "User": "",
        "AttachStdin": true,
        "AttachStdout": true,
        "AttachStderr": true,
        "ExposedPorts": {
            "5044/tcp": {},
            "5601/tcp": {},
            "9200/tcp": {},
            "9300/tcp": {}
        },
        "Tty": true,
        "OpenStdin": true,
        "StdinOnce": true,
        "Env": [
            "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin",
            "DEBIAN_FRONTEND=teletype",
            "LANG=en_US.UTF-8",
            "LANGUAGE=en_US:en",
            "LC_ALL=en_US.UTF-8",
            "REFRESHED_AT=2017-02-28",
            "ES_VERSION=7.7.1",
            "ES_HOME=/opt/elasticsearch",
            "LOGSTASH_VERSION=7.7.1",
            "LOGSTASH_HOME=/opt/logstash",
            "JAVA_HOME=/usr/lib/jvm/java-8-openjdk-amd64/jre",
            "ES_PACKAGE=elasticsearch-7.7.1-linux-x86_64.tar.gz",
            "ES_GID=991",
            "ES_UID=991",
            "ES_PATH_CONF=/etc/elasticsearch",
            "ES_PATH_BACKUP=/var/backups",
            "KIBANA_VERSION=7.7.1",
            "LOGSTASH_PACKAGE=logstash-7.7.1.tar.gz",
            "LOGSTASH_GID=992",
            "LOGSTASH_UID=992",
            "LOGSTASH_PATH_CONF=/etc/logstash",
            "LOGSTASH_PATH_SETTINGS=/opt/logstash/config",
            "KIBANA_HOME=/opt/kibana",
            "KIBANA_PACKAGE=kibana-7.7.1-linux-x86_64.tar.gz",
            "KIBANA_GID=993",
            "KIBANA_UID=993"
        ],
        "Cmd": [
            "/usr/local/bin/start.sh"
        ],
        "Image": "sebp/elk",
        "Volumes": {
            "/var/lib/elasticsearch": {}
        },
        "WorkingDir": "",
        "Entrypoint": null,
        "OnBuild": null,
        "Labels": {}
    },
    "NetworkSettings": {
        "Bridge": "",
        "SandboxID": "f96541bf31992b7b9e316ec16313438c25a5b669b1d18a8f7ab64cf47883514f",
        "HairpinMode": false,
        "LinkLocalIPv6Address": "",
        "LinkLocalIPv6PrefixLen": 0,
        "Ports": {
            "5044/tcp": [
                {
                    "HostIp": "0.0.0.0",
                    "HostPort": "5044"
                }
            ],
            "5601/tcp": [
                {
                    "HostIp": "0.0.0.0",
                    "HostPort": "5601"
                }
            ],
            "9200/tcp": [
                {
                    "HostIp": "0.0.0.0",
                    "HostPort": "9200"
                }
            ],
            "9300/tcp": null
        },
        "SandboxKey": "/var/run/docker/netns/f96541bf3199",
        "SecondaryIPAddresses": null,
        "SecondaryIPv6Addresses": null,
        "EndpointID": "59b3637d40fffdf2769c5072c1893b18a45e38f68c7740d54595a591509bdb77",
        "Gateway": "172.17.0.1",
        "GlobalIPv6Address": "",
        "GlobalIPv6PrefixLen": 0,
        "IPAddress": "172.17.0.2",
        "IPPrefixLen": 16,
        "IPv6Gateway": "",
        "MacAddress": "02:42:ac:11:00:02",
        "Networks": {
            "bridge": {
                "IPAMConfig": null,
                "Links": null,
                "Aliases": null,
                "NetworkID": "9729006bbd883efb7467f7297071b45ae1b5182e7b576a5e08a214fd8175735f",
                "EndpointID": "59b3637d40fffdf2769c5072c1893b18a45e38f68c7740d54595a591509bdb77",
                "Gateway": "172.17.0.1",
                "IPAddress": "172.17.0.2",
                "IPPrefixLen": 16,
                "IPv6Gateway": "",
                "GlobalIPv6Address": "",
                "GlobalIPv6PrefixLen": 0,
                "MacAddress": "02:42:ac:11:00:02",
                "DriverOpts": null
            }
        }
    }
}

```

]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2020, 6:22am UTC](https://discuss.elastic.co/t/unable-to-see-older-logs-in-kibana-after-restarting-the-elk/248818/8 "2020-10-15T06:22:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
