# Aggregations don't work in Kibana after Elastic stack upgrade to 7.2

**URL:** <https://discuss.elastic.co/t/aggregations-dont-work-in-kibana-after-elastic-stack-upgrade-to-7-2/189825>\
**Category:** Kibana\
**Created:** [July 10, 2019, 4:10pm UTC](https://discuss.elastic.co/t/aggregations-dont-work-in-kibana-after-elastic-stack-upgrade-to-7-2/189825 "2019-07-10T16:10:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Martin\_O](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@Martin\_O](https://discuss.elastic.co/u/Martin_O)\
**Post date:** [July 10, 2019, 4:10pm UTC](https://discuss.elastic.co/t/aggregations-dont-work-in-kibana-after-elastic-stack-upgrade-to-7-2/189825/1 "2019-07-10T16:10:32Z")

</div>

Aggregations don't work in Kibana after Elastic stack upgrade to 7.2 from 6.8 version. I use it to visualize logs from postfix , these are shipped ok and I can see the records in ' Discover' just OK. But when I try to visualize on any field, Kibana says 1 of XX shards failed and shows no data. The same is with the dashboards I had created in older version.  
In the elasticsearch logs, it shows:  
Caused by: java.lang.IllegalArgumentException: Fielddata is disabled on text fields by default. Set fielddata=true on [host] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead.

I have found similar topics here, regarding changing the 'text' to 'keyword', but in template, there's the correct type already. But when I look at index mapping, text type is everywhere like this:  
"host": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}}}  
Any ideas welcome

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [July 10, 2019, 6:17pm UTC](https://discuss.elastic.co/t/aggregations-dont-work-in-kibana-after-elastic-stack-upgrade-to-7-2/189825/2 "2019-07-10T18:17:47Z")

</div>

Aggregations only work for fields with fielddata enabled. By default, text fields do not have field data enabled and can not be used in aggregations. Keyword has fielddata enabled by default and can be use in aggregations

Your index mapping uses multifields to index host in 2 different ways. `host` is indexed as text while `host.keyword` is indexed as keyword.

What does the configuration look like for your visualization? Are you using `host.keyword` for your aggregation field?

---

<div class="post-metadata">

**Author:** ![Martin\_O](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@Martin\_O](https://discuss.elastic.co/u/Martin_O)\
**Post date:** [July 10, 2019, 7:16pm UTC](https://discuss.elastic.co/t/aggregations-dont-work-in-kibana-after-elastic-stack-upgrade-to-7-2/189825/3 "2019-07-10T19:16:05Z")

</div>

I tried to use host.keyword for aggregation and in visualization before, but I couldn't either find or enter 'host.keyword' anywhere in the visualisation setup.  
Do I have to use other approach to edit my old visualizations? Even if I try to create new visualization, e.g. use Terms for aggregation , it doesn't allow to enter 'host.keyword'.  
Since I'm far from being expert on this,I may misunderstand how keyword must be specified here. I'd be grateful for advice, how can I adjust my visualizations from older kibana version. Thanks for any insight

---

<div class="post-metadata">

**Author:** ![Martin\_O](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@Martin\_O](https://discuss.elastic.co/u/Martin_O)\
**Post date:** [July 11, 2019, 3:47pm UTC](https://discuss.elastic.co/t/aggregations-dont-work-in-kibana-after-elastic-stack-upgrade-to-7-2/189825/4 "2019-07-11T15:47:46Z")

</div>

E.g. I tried this, but there are no fields, that end with '.keyword' in my case:

> [@Sorting rows in Kibana based on keyword field](https://discuss.elastic.co/t/sorting-rows-in-kibana-based-on-keyword-field/109968/5):
>
> Hi Marin, This is a confusing topic even to me and I've been working on Kibana for over 2 years. But here's the issue. It's all about the mapping of the field. Strings can be loaded into Elasticsearch as 2 different types text and keyword and they are commonly stored both ways. For example, in filebeat you should have beat.name and it should be sortable; If we go to the Dev Console and do a GET on the filebeat index mapping we see that beat.name is "type": "keyword". The fact t…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2019, 3:55pm UTC](https://discuss.elastic.co/t/aggregations-dont-work-in-kibana-after-elastic-stack-upgrade-to-7-2/189825/5 "2019-08-08T15:55:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
