# Available fields not showing in kibana \[Issue resolved\]

**URL:** <https://discuss.elastic.co/t/available-fields-not-showing-in-kibana-issue-resolved/31872>\
**Category:** Kibana\
**Created:** [October 8, 2015, 6:09pm UTC](https://discuss.elastic.co/t/available-fields-not-showing-in-kibana-issue-resolved/31872 "2015-10-08T18:09:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![raamee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raamee/32/5110_2.png) [@raamee](https://discuss.elastic.co/u/raamee)\
**Post date:** [October 8, 2015, 6:09pm UTC](https://discuss.elastic.co/t/available-fields-not-showing-in-kibana-issue-resolved/31872/1 "2015-10-08T18:09:39Z")

</div>

Hi,

I'm trying to parse Apache logs which is in this format:

```
xxx.xxx.xxx.xxx - - [06/Oct/2015:23:58:37 +0530] "GET /search/newver_smartsearchjs_ql.php HTTP/1.1" 200 47532 29330 "http://subdomain.domain.com/search/searchres_ql.php?randid=a37093s&gaact=search&gasrc=WO" "Mozilla/5.0 (iPad; CPU OS 9_0_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13A452 Safari/601.1"

```

I'm using the following grok filter:

```
filter {
  if [type] == "apache-access" {
    grok {
      match => ["message", "%{IPORHOST:clientip} %{USER:ident} %{USER:auth} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})\" %{NUMBER:response} (?:%{NUMBER:bytes}|-) %{NUMBER:response_time} %{QS:referrer} %{QS:agent}" ]
    }
date{
    match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"] 
    locale => "en" 
  }
geoip {
      source => "clientip"
      target => "geoip"
      database => "/etc/logstash/GeoLiteCity.dat"
      add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
      add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
    }
    mutate {
      convert => ["[geoip][coordinates]", "float"]
    }
  }
}

```

The logstash parse the logs well and in correct format. It identifies each field properly and it parses (I saw this in **/var/log/logstash/logstash.stdout**

But I'm not getting the Available Fields in the indices properly. FYI:

![](https://us1.discourse-cdn.com/elastic/original/2X/7/7f0eddd9aac051db822326f39880c1ee65efcd68.png)

Its not showing the proper Apache fields which I have given in logstash filter. I have also reloaded the fields in the settings--\>indices--\>

Its showing fields in settings--\>indices as shown below:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/4071aadc065ea461e8f9e754b15c0063d51addb4.png)

Please help why kibana is not displaying the proper available fields.

---

<div class="post-metadata">

**Author:** ![raamee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raamee/32/5110_2.png) [@raamee](https://discuss.elastic.co/u/raamee)\
**Post date:** [October 9, 2015, 4:34pm UTC](https://discuss.elastic.co/t/available-fields-not-showing-in-kibana-issue-resolved/31872/2 "2015-10-09T16:34:28Z")

</div>

**UPDATE at end of this post**

Ok. I found the issue why this occurs. Below is my observation:

The issue occurs when any field appears to be blank with no data . Check the below screenshot, where certain fields have no data (like IP address, referrer, etc)

 ![](https://us1.discourse-cdn.com/elastic/original/2X/f/f5b877c72a133e2ed9a83cafef40d36096d8a776.png)

Check the JSON format of that search:

![](https://us1.discourse-cdn.com/elastic/original/2X/2/2be9d68a39bf5dcd85e45ca35e6318827a010f30.png)

Below is the apache log with all the fields filled in properly:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/ac5cc141558fed28e80754254737d2bfeb4111a4.png)

In JSON format:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1d1b56dc2f07c12adb06b1e184318f52a97ee6ec.png)

So , its seems its the logstash issue rather than kibana. If so, kindly move to this logstash section or you can explain your answer here.

Thanks.

**UPDATE:** In logstash filter grok, I made the IPaddress field optional by enclosing the %{IPORHOST:clientip} with ()? . Final format is **(%{IPORHOST:clientip})?**. Issue resolved.

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [October 10, 2015, 2:58pm UTC](https://discuss.elastic.co/t/available-fields-not-showing-in-kibana-issue-resolved/31872/3 "2015-10-10T14:58:48Z")

</div>

Thanks for posting the resolution!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:11pm UTC](https://discuss.elastic.co/t/available-fields-not-showing-in-kibana-issue-resolved/31872/4 "2017-07-06T14:11:38Z")

</div>


