# Why isn't POST showing up in Kibana Discover tab?

**URL:** <https://discuss.elastic.co/t/why-isnt-post-showing-up-in-kibana-discover-tab/191034>\
**Category:** Elasticsearch\
**Created:** [July 17, 2019, 2:43pm UTC](https://discuss.elastic.co/t/why-isnt-post-showing-up-in-kibana-discover-tab/191034 "2019-07-17T14:43:10Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![samuelburnett](https://avatars.discourse-cdn.com/v4/letter/s/bbce88/32.png) [@samuelburnett](https://discuss.elastic.co/u/samuelburnett)\
**Post date:** [July 17, 2019, 2:43pm UTC](https://discuss.elastic.co/t/why-isnt-post-showing-up-in-kibana-discover-tab/191034/1 "2019-07-17T14:43:10Z")

</div>

I am using the Developer Console in Kibana to add a document to my index. This is the command:

> POST my\_index/\_doc/test02?op\_type=create  
> {  
> "user": "USERTEST055"  
> }

I was wondering why this isn't showing up in the discover tab? If I run the GET command it gives me the results I expect.

> GET my\_index/\_search  
> {  
> "query": {"match": {"user": "USERTEST055"}}  
> }

I am guessing this has something to do with the missing @timestamp field? If so, why isn't a @timestamp field being added when it gets added to the index?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 17, 2019, 2:58pm UTC](https://discuss.elastic.co/t/why-isnt-post-showing-up-in-kibana-discover-tab/191034/2 "2019-07-17T14:58:29Z")

</div>

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

This is the icon to use if you are not using markdown format:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/e/7e6e239431ec2d71cbf1beef741f2e93e7cc762c.jpg)

> [@samuelburnett](#):
>
> If so, why isn't a @timestamp field being added when it gets added to the index?

Because elasticsearch just index what you are sending to it.  
You sent:

```auto
{
  "user": "USERTEST055"
}

```

Elasticsearch only indexes that.

---

<div class="post-metadata">

**Author:** ![samuelburnett](https://avatars.discourse-cdn.com/v4/letter/s/bbce88/32.png) [@samuelburnett](https://discuss.elastic.co/u/samuelburnett)\
**Post date:** [July 17, 2019, 3:15pm UTC](https://discuss.elastic.co/t/why-isnt-post-showing-up-in-kibana-discover-tab/191034/3 "2019-07-17T15:15:12Z")

</div>

Ok, then how do you get a @timestamp field to generate upon creation?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 17, 2019, 3:16pm UTC](https://discuss.elastic.co/t/why-isnt-post-showing-up-in-kibana-discover-tab/191034/4 "2019-07-17T15:16:40Z")

</div>

```auto
POST test/_doc 
{
  "@timestamp": "-ENTER-A-DATE-HERE-",
  "user": "USERTEST055"
}

```

---

<div class="post-metadata">

**Author:** ![samuelburnett](https://avatars.discourse-cdn.com/v4/letter/s/bbce88/32.png) [@samuelburnett](https://discuss.elastic.co/u/samuelburnett)\
**Post date:** [July 17, 2019, 3:24pm UTC](https://discuss.elastic.co/t/why-isnt-post-showing-up-in-kibana-discover-tab/191034/5 "2019-07-17T15:24:04Z")

</div>

I have tried this, but it still does not show up in the discover tab and I cannot search for it based on a time range.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 17, 2019, 3:26pm UTC](https://discuss.elastic.co/t/why-isnt-post-showing-up-in-kibana-discover-tab/191034/6 "2019-07-17T15:26:08Z")

</div>

> I have tried this

What did you enter?

> I cannot search for it based on a time range.

Do you need to filter by time actually?

---

<div class="post-metadata">

**Author:** ![samuelburnett](https://avatars.discourse-cdn.com/v4/letter/s/bbce88/32.png) [@samuelburnett](https://discuss.elastic.co/u/samuelburnett)\
**Post date:** [July 17, 2019, 3:35pm UTC](https://discuss.elastic.co/t/why-isnt-post-showing-up-in-kibana-discover-tab/191034/7 "2019-07-17T15:35:59Z")

</div>

```
POST filebeat-7.2.0/_doc/test05?op_type=create
{
  "@timestamp": "2019-07-17T10:25:23Z",
  "user": "NEWTEST02"
}

```

And then I search for what I just created:

```
GET filebeat-7.2.0/_search
{
  "query": {"match": {"user": "NEWTEST02"}}
}

```

With results:

```
{
  "took" : 0,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 1,
      "relation" : "eq"
    },
    "max_score" : 3.028522,
    "hits" : [
      {
        "_index" : "filebeat-7.2.0",
        "_type" : "_doc",
        "_id" : "test05",
        "_score" : 3.028522,
        "_source" : {
          "@timestamp" : "2019-07-17T10:25:23Z",
          "user" : "NEWTEST02"
        }
      }
    ]
  }
}

```

But then I try to search based on a time range:

```
GET filebeat-7.2.0/_search
{
  "query": {
    "bool": {
      "filter": [
        {
          "match": {
            "user": "NEWTEST02"
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": "now-30m"
            }
          }
        }
      ]
    }
  }
}

```

And I get 0 hits

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 17, 2019, 3:44pm UTC](https://discuss.elastic.co/t/why-isnt-post-showing-up-in-kibana-discover-tab/191034/8 "2019-07-17T15:44:04Z")

</div>

All timestamps stored in Elasticsearch are in UTC timezone, so the timestamp you provided is more than 30 minutes old unless you ran the query several hours ago.

---

<div class="post-metadata">

**Author:** ![samuelburnett](https://avatars.discourse-cdn.com/v4/letter/s/bbce88/32.png) [@samuelburnett](https://discuss.elastic.co/u/samuelburnett)\
**Post date:** [July 17, 2019, 3:57pm UTC](https://discuss.elastic.co/t/why-isnt-post-showing-up-in-kibana-discover-tab/191034/9 "2019-07-17T15:57:51Z")

</div>

Thank you, silly mistake on my part.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2019, 4:03pm UTC](https://discuss.elastic.co/t/why-isnt-post-showing-up-in-kibana-discover-tab/191034/10 "2019-08-14T16:03:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
