Winlogbeat Index created but nothing in Discover

Hi, I had Elasticsearch installed on a Windows server but moved it to Ubuntu. I am now sending Windows logs to Elasticsearch on Ubuntu. Under Management > Index Management I see the winlogbeat index created and it grows but I don't see anything under Discover or Visualize. I don't have the winlogbeat index listed but do have auditbeat and metricbeat.

When ES was on the Windows machine and I sent the logs to itself, I did see the logs under the Discover tab.

Any ideas why the index isn't showing?


Nevermind, I didn't create the initial index pattern. After that, I can see the logs now.

1 Like

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.