# 5.1.1: Discover error

**URL:** https://discuss.elastic.co/t/5-1-1-discover-error/70940
**Category:** Kibana
**Created:** [January 9, 2017, 11:56am UTC](https://discuss.elastic.co/t/5-1-1-discover-error/70940 "2017-01-09T11:56:55Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)
#### Post date: [January 9, 2017, 11:56am UTC](https://discuss.elastic.co/t/5-1-1-discover-error/70940/1 "2017-01-09T11:56:55Z")

</div>

Hi,  
I'm getting errors in kibana after configuring against new elasticsearch 5.1.1 cluster:

```
Saved "field" parameter is now invalid. Please select a new field.
Discover: "field" is a required parameter

```

The only data being indexed to elasticsearch atm is logstash heartbeat data...

Regards,  
David

---

<div class="post-metadata">

### Author: ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)
#### Post date: [January 9, 2017, 4:07pm UTC](https://discuss.elastic.co/t/5-1-1-discover-error/70940/2 "2017-01-09T16:07:36Z")

</div>

This looks like it's a bug, we have an open issue for it [here](https://github.com/elastic/kibana/issues/9571). Do you have any other index patterns in kibana? Are you using a template with your elasticsearch output?

---

<div class="post-metadata">

### Author: ![Sushil\_Singh1](https://avatars.discourse-cdn.com/v4/letter/s/96bed5/32.png) [@Sushil\_Singh1](https://discuss.elastic.co/u/Sushil_Singh1)
#### Post date: [January 10, 2017, 4:58am UTC](https://discuss.elastic.co/t/5-1-1-discover-error/70940/3 "2017-01-10T04:58:08Z")

</div>

Hi,

I'm also getting same error.  
Elasticsearch and kibana latest (5.1.1) downloaded and installed as per docs.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/3/3ce4c51a1143cbd37ca010be30ac42653f85697f.png)

---

<div class="post-metadata">

### Author: ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)
#### Post date: [January 10, 2017, 11:55am UTC](https://discuss.elastic.co/t/5-1-1-discover-error/70940/4 "2017-01-10T11:55:08Z")

</div>

Hi,  
I have only one index pattern and yes, am using a template for our logs.

Regards,  
David

---

<div class="post-metadata">

### Author: ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)
#### Post date: [January 11, 2017, 8:22am UTC](https://discuss.elastic.co/t/5-1-1-discover-error/70940/5 "2017-01-11T08:22:04Z")

</div>

What may be a factor here is that we are using the mapper-size plugin. So, each document is being indexed with an '\_size' field. Kibana sees this as type 'unknown' and so i presume that is the trigger for what I'm seeing?

---

<div class="post-metadata">

### Author: ![dawiro](https://avatars.discourse-cdn.com/v4/letter/d/71e660/32.png) [@dawiro](https://discuss.elastic.co/u/dawiro)
#### Post date: [January 12, 2017, 11:21am UTC](https://discuss.elastic.co/t/5-1-1-discover-error/70940/6 "2017-01-12T11:21:00Z")

</div>

Hi,  
I think I've resolved this. I had fields in my template, including @timestamp which were set to:

`"index" : "not_analyzed"`

Reading the 5.x docs more closely i realised that while types have changed to mapping definitions for field analysis have changed as a result. So, changing that to true, ensuring that string type mapping were set correctly (keyword/text) and then recreating the index and kibana index pattern allowed the discover interface to start working.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 9, 2017, 11:21am UTC](https://discuss.elastic.co/t/5-1-1-discover-error/70940/7 "2017-02-09T11:21:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
