Aggregations don't work in Kibana after Elastic stack upgrade to 7.2 from 6.8 version. I use it to visualize logs from postfix , these are shipped ok and I can see the records in ' Discover' just OK. But when I try to visualize on any field, Kibana says 1 of XX shards failed and shows no data. The same is with the dashboards I had created in older version.
In the elasticsearch logs, it shows:
Caused by: java.lang.IllegalArgumentException: Fielddata is disabled on text fields by default. Set fielddata=true on [host] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead.
I have found similar topics here, regarding changing the 'text' to 'keyword', but in template, there's the correct type already. But when I look at index mapping, text type is everywhere like this:
Any ideas welcome