# Beat Dashboard Installation - Saved "field" parameter is now invalid

**URL:** <https://discuss.elastic.co/t/beat-dashboard-installation-saved-field-parameter-is-now-invalid/137239>\
**Category:** Kibana\
**Created:** [June 25, 2018, 11:31am UTC](https://discuss.elastic.co/t/beat-dashboard-installation-saved-field-parameter-is-now-invalid/137239 "2018-06-25T11:31:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lethalMango](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@lethalMango](https://discuss.elastic.co/u/lethalMango)\
**Post date:** [June 25, 2018, 11:31am UTC](https://discuss.elastic.co/t/beat-dashboard-installation-saved-field-parameter-is-now-invalid/137239/1 "2018-06-25T11:31:58Z")

</div>

I've just setup a completely new ELK environment and began testing it with the installation of Auditbeat on a Windows Server 2012 R2 machine.

When running the dashboard setup from Powershell it confirms successful installation and I can see the Visualisations and Dashboards in Kibana, however when clicking into any of the Dashboards I get the following two errors at the top of the page:

Saved "field" parameter is now invalid. Please select a new field.  
Visualize: "field" is a required parameter

Likewise, clicking into the [Auditbeat File Integrity] Overview Dashboard I get the following errors on the page:

Could not locate that index-pattern-field (id: file.group)  
Could not locate that index-pattern-field (id: file.path.raw)  
Could not locate that index-pattern-field (id: file.mode)

Having removed the index, all visualisations, searches, dashboards etc and completed the setup again I still get the same error.

Have I missed something obvious?

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [June 25, 2018, 11:29pm UTC](https://discuss.elastic.co/t/beat-dashboard-installation-saved-field-parameter-is-now-invalid/137239/2 "2018-06-25T23:29:40Z")

</div>

Are you using the same version of Beats, Kibana, and Elasticsearch? What version are you running?

---

<div class="post-metadata">

**Author:** ![lethalMango](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@lethalMango](https://discuss.elastic.co/u/lethalMango)\
**Post date:** [June 26, 2018, 9:30am UTC](https://discuss.elastic.co/t/beat-dashboard-installation-saved-field-parameter-is-now-invalid/137239/3 "2018-06-26T09:30:53Z")

</div>

Completely fresh install of Logstash, Elasticsearch and Kibana at 6.3.0.

Logstash config:

```
input {
  beats {
    port => 5044
  }
}

output {
  elasticsearch {
    hosts => "x.x.x.x:9200" #Bound to IPv4 address
    manage_template => false
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

The only data being shipped is a single server with Auditbeat on for testing purposes.

Auditbeat config (Windows Server 2012 R2)

```
auditbeat.modules:
- module: file_integrity
  paths:
  - C:/windows
  - C:/windows/system32
  - C:/Program Files
  - C:/Program Files (x86)
  
setup.template.settings:
  index.number_of_shards: 1

name: host.fqdn.local #Machine's hostname running Auditbeat

setup.kibana:
  host: "x.x.x.x:5601" #Kibana IP Address

output.logstash:
  hosts: ["x.x.x.x:5044"] #Logstash IP Address

```

Dashboards setup using the following with the output from the config changed from logstash to elasticsearch:

```
./auditbeat setup -e
```

---

<div class="post-metadata">

**Author:** ![lethalMango](https://avatars.discourse-cdn.com/v4/letter/l/da6949/32.png) [@lethalMango](https://discuss.elastic.co/u/lethalMango)\
**Post date:** [June 26, 2018, 12:26pm UTC](https://discuss.elastic.co/t/beat-dashboard-installation-saved-field-parameter-is-now-invalid/137239/4 "2018-06-26T12:26:51Z")

</div>

As an additional, the More Info button at the top of the Dashboard screen shows the following error:

```
Visualize: "field" is a required parameter

TypeError: "field" is a required parameter
    at FieldParamType.write (http://x.x.x.x:5601/bundles/commons.bundle.js:3:1269032)
    at http://x.x.x.x:5601/bundles/commons.bundle.js:3:308531
    at AggParams.forEach (<anonymous>)
    at AggParams.write (http://x.x.x.x:5601/bundles/commons.bundle.js:3:308489)
    at AggConfig.write (http://x.x.x.x:5601/bundles/commons.bundle.js:3:70339)
    at AggConfig.toDsl (http://x.x.x.x:5601/bundles/commons.bundle.js:3:71279)
    at http://x.x.x.x:5601/bundles/commons.bundle.js:3:1426036
    at Array.forEach (<anonymous>)
    at AggConfigs.VisAggConfigsProvider.AggConfigs.toDsl (http://x.x.x.x:5601/bundles/commons.bundle.js:3:1425819)
    at http://x.x.x.x:5601/bundles/commons.bundle.js:3:503899
    at SearchSource.value (http://x.x.x.x:5601/bundles/commons.bundle.js:3:93766)
    at ittr (http://x.x.x.x:5601/bundles/commons.bundle.js:3:94975)
    at http://x.x.x.x:5601/bundles/vendors.bundle.js:3:19274
    at http://x.x.x.x:5601/bundles/vendors.bundle.js:3:29454
    at baseForOwn (http://x.x.x.x:5601/bundles/vendors.bundle.js:3:16415)
    at http://x.x.x.x:5601/bundles/vendors.bundle.js:3:29014
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2018, 12:26pm UTC](https://discuss.elastic.co/t/beat-dashboard-installation-saved-field-parameter-is-now-invalid/137239/5 "2018-07-24T12:26:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
