# Very inconsistent "No results found" Kibana 4.3.0

**URL:** <https://discuss.elastic.co/t/very-inconsistent-no-results-found-kibana-4-3-0/36430>\
**Category:** Kibana\
**Created:** [December 5, 2015, 3:35am UTC](https://discuss.elastic.co/t/very-inconsistent-no-results-found-kibana-4-3-0/36430 "2015-12-05T03:35:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![aethos](https://avatars.discourse-cdn.com/v4/letter/a/53a042/32.png) [@aethos](https://discuss.elastic.co/u/aethos)\
**Post date:** [December 5, 2015, 3:35am UTC](https://discuss.elastic.co/t/very-inconsistent-no-results-found-kibana-4-3-0/36430/1 "2015-12-05T03:35:18Z")

</div>

Hey all, having a very frustrating issue with an upgraded install and Kibana 4.3.0. I frequently get:

![](https://us1.discourse-cdn.com/elastic/original/2X/b/b0b87dbd32f690c17c7b08b66acb9bcd4fa070bb.png)

There's a lot of documents in the logstash index and if I refresh the window results come up. But if I try to do a free text search, or change the date range, or look at it cross eyed it will come up No results found.

Someone suggested I inspect the query it was sending but it doesn't show the query when no results are issued.

Thoughts on troubleshooting it are greatly appreciated! Thank you!

Just to add - basic config:

- ELK running on one box (plenty of disk space)
- One replica setup on a spare box just to make all the lights green
- Local firewall currently disabled
- Elasticsearch v2.1.0-1
- Logstash v2.1.0-1
- .kibana index deleted from old install

---

<div class="post-metadata">

**Author:** ![kaem2111](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaem2111/32/24961_2.png) [@kaem2111](https://discuss.elastic.co/u/kaem2111)\
**Post date:** [December 5, 2015, 8:50pm UTC](https://discuss.elastic.co/t/very-inconsistent-no-results-found-kibana-4-3-0/36430/2 "2015-12-05T20:50:54Z")

</div>

Hi,  
I also spent hours searching my data.

- try 'last 5 years' as date range, sometimes the log entries are at other timerange than expected
- lookup settings for logstash-\* to find out, which field (mostly @timestamp) you selected to represent the timestamp.

Good Luck!

---

<div class="post-metadata">

**Author:** ![aethos](https://avatars.discourse-cdn.com/v4/letter/a/53a042/32.png) [@aethos](https://discuss.elastic.co/u/aethos)\
**Post date:** [December 5, 2015, 9:39pm UTC](https://discuss.elastic.co/t/very-inconsistent-no-results-found-kibana-4-3-0/36430/3 "2015-12-05T21:39:59Z")

</div>

At the moment @timestamp is my time field and the time is accurate. Matches server time, local system time, everything.

For illustration I just did:

- Had a dataset up with a filter of "syslog\_program:vpopmail" and all is good.
- Changed filter to \* and got no results.
- Clicked refresh and got no results.
- Clicked the "Discover" link and got results. (With \* as the filter and last 15 minutes as the timeframe.)
- Changed filter to "KERNEL" and got no results.
- Change filter to "result\_code:200" got results.
- Changed filter to just "200" and got no results.
- Changed filter to \* and got no results.

It's all over the place.

---

<div class="post-metadata">

**Author:** ![aethos](https://avatars.discourse-cdn.com/v4/letter/a/53a042/32.png) [@aethos](https://discuss.elastic.co/u/aethos)\
**Post date:** [December 18, 2015, 8:27pm UTC](https://discuss.elastic.co/t/very-inconsistent-no-results-found-kibana-4-3-0/36430/4 "2015-12-18T20:27:50Z")

</div>

After a lot quite a bit of study I determined the issue and am sharing in case anyone else runs into it.

I had received a mapping and that mapping had set the string values as not\_analyzed. This resulted in future indexes losing the ability to search outside of whole fields. If you run into this, check your \_mapping and \_template settings for fields or default values set as not\_analyzed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:06pm UTC](https://discuss.elastic.co/t/very-inconsistent-no-results-found-kibana-4-3-0/36430/5 "2017-07-06T14:06:15Z")

</div>


