# Windows FileBeat not found in Kibana

**URL:** <https://discuss.elastic.co/t/windows-filebeat-not-found-in-kibana/122185>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 2, 2018, 3:49am UTC](https://discuss.elastic.co/t/windows-filebeat-not-found-in-kibana/122185 "2018-03-02T03:49:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Simonhawk](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@Simonhawk](https://discuss.elastic.co/u/Simonhawk)\
**Post date:** [March 2, 2018, 3:49am UTC](https://discuss.elastic.co/t/windows-filebeat-not-found-in-kibana/122185/1 "2018-03-02T03:49:13Z")

</div>

OS? Windows 10.  
Guide used? [http://robwillis.info/2016/05/installing-elasticsearch-logstash-and-kibana-elk-on-windows-server-2012-r2/](http://robwillis.info/2016/05/installing-elasticsearch-logstash-and-kibana-elk-on-windows-server-2012-r2/)  
Did I research before coming here? YES  
Error? No matching indices found: No indices match pattern "filebeat-\*" (found on Kibana)

Set up ELK stack with the beats: filebeat, metricbeat, packetbeat, and winlogbeat. Everything seems to be working except filebeat. All services are running. Here is a copy of my filebeat config, thank you very much for your assistance!  
\*PS - if you have any suggestions to implement, i am open minded. This is used on my personal, host computer for learning purposes.

```
#=========================== Filebeat prospectors =============================

filebeat.prospectors:

- type: log

  enabled: true

  paths:
    #- /var/log/*.log
    - C:\ProgramData\Elastic\Elasticsearch\logs\*
    - C:\ProgramData\winlogbeat\logs\*
    - C:\ProgramData\packetbeat\logs\*
    - C:\ProgramData\metricbeat\logs\*
    - C:\ProgramData\filebeat\logs\*
    - C:\Snort\logs\*.logs\*

  #exclude_lines: ['^DBG']

  #include_lines: ['^ERR', '^WARN']

  #exclude_files: ['.gz$']

  #fields:
  # level: debug
  # review: 1

  ### Multiline options

  #multiline.pattern: ^\[

  #multiline.negate: false

  #multiline.match: after

#============================= Filebeat modules ===============================

filebeat.config.modules:

  path: ${path.config}/modules.d/*.yml

  reload.enabled: false

  #reload.period: 10s

#==================== Elasticsearch template setting ==========================

setup.template.settings:
  index.number_of_shards: 3
  #index.codec: best_compression
  #_source.enabled: false

#================================ General =====================================

#name:

#tags: ["service-X", "web-tier"]

#fields:
# env: staging

#============================== Dashboards =====================================

#setup.dashboards.enabled: false

#setup.dashboards.url:

#============================== Kibana =====================================

setup.kibana:
  host: "localhost:5601"

#============================= Elastic Cloud ==================================

#cloud.id:

#cloud.auth:

#================================ Outputs =====================================

# Configure what output to use when sending the data collected by the beat.

#-------------------------- Elasticsearch output ------------------------------
output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["localhost:9200"]

  # Optional protocol and basic auth credentials.
  #protocol: "https"
  #username: "elastic"
  #password: "changeme"

#----------------------------- Logstash output --------------------------------
#output.logstash:
  # The Logstash hosts
  #hosts: ["localhost:5044"]

  # Optional SSL. By default is off.
  # List of root certificates for HTTPS server verifications
  #ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]

  # Certificate for SSL client authentication
  #ssl.certificate: "/etc/pki/client/cert.pem"

  # Client Certificate Key
  #ssl.key: "/etc/pki/client/cert.key"

#================================ Logging =====================================

# Sets log level. The default log level is info.
# Available log levels are: error, warning, info, debug
#logging.level: debug

# At debug level, you can selectively enable logging only for some components.
# To enable all selectors use ["*"]. Examples of other selectors are "beat",
# "publish", "service".
#logging.selectors: ["*"]

#============================== Xpack Monitoring ===============================

#xpack.monitoring.enabled: false

#xpack.monitoring.elasticsearch:
```

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 6, 2018, 5:21am UTC](https://discuss.elastic.co/t/windows-filebeat-not-found-in-kibana/122185/2 "2018-03-06T05:21:38Z")

</div>

Could you share your filebeat log file and the version of filebeat you are using?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2018, 5:21am UTC](https://discuss.elastic.co/t/windows-filebeat-not-found-in-kibana/122185/3 "2018-04-03T05:21:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
