# Can not find mongodb log in Discover

**URL:** <https://discuss.elastic.co/t/can-not-find-mongodb-log-in-discover/334202>\
**Category:** Elasticsearch\
**Created:** [May 24, 2023, 10:19am UTC](https://discuss.elastic.co/t/can-not-find-mongodb-log-in-discover/334202 "2023-05-24T10:19:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![miladghasemi](https://avatars.discourse-cdn.com/v4/letter/m/e5b9ba/32.png) [@miladghasemi](https://discuss.elastic.co/u/miladghasemi)\
**Post date:** [May 24, 2023, 10:19am UTC](https://discuss.elastic.co/t/can-not-find-mongodb-log-in-discover/334202/1 "2023-05-24T10:19:04Z")

</div>

Hi (sorry for my bad english)  
I'm enabled mongodb module in filebeat to send mongodb log into elasticsearch.  
Filebeat created dashboard, my log show in discover but when i want to search in Dicover,it not show [event.original] content or in Dev section when i run below query

```auto
GET /filebeat-8.7.1/_search
{
  "_source": ["event.original"],
  "query": {
    "wildcard": {
      "event.original": {
        "value": "*CustomerStep*"
      }
    }
  }
}

```

it show bellow error:

```auto
failed to create query: Cannot search on field [event.original] since it is not indexed nor has doc values

```

how i can solve this problem

---

<div class="post-metadata">

**Author:** ![Priscilla\_Parodi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priscilla_parodi/32/43047_2.png) [@Priscilla\_Parodi](https://discuss.elastic.co/u/Priscilla_Parodi)\
**Post date:** [May 27, 2023, 6:44pm UTC](https://discuss.elastic.co/t/can-not-find-mongodb-log-in-discover/334202/2 "2023-05-27T18:44:16Z")

</div>

Hello, miladghasemi. Welcome to our community!

Could you please check your index mapping?

`GET filebeat-8.7.1/_mapping`

Make sure the event.original [index option value](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-index.html) is not set to false: `"index": false`

The index option controls whether field values are indexed. It accepts true or false.

If it is set to false, you will need to create a new index with the desired mappings and reindex. You can use the [reindex API](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html) for that.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 27, 2023, 10:05pm UTC](https://discuss.elastic.co/t/can-not-find-mongodb-log-in-discover/334202/3 "2023-05-27T22:05:43Z")

</div>

Hi @miladghasemi welcome to the community.

It is possible that text you are looking for is in another field like the `message` field did you search on that?

Have you looked at what [actual fields you have available?](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-mongodb.html)

> mongodb.log.message  
> type: alias
> 
> alias to: message

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2023, 10:05pm UTC](https://discuss.elastic.co/t/can-not-find-mongodb-log-in-discover/334202/4 "2023-06-24T22:05:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
