# Can't make text field aggregatable

**URL:** <https://discuss.elastic.co/t/cant-make-text-field-aggregatable/293178>\
**Category:** Kibana\
**Created:** [December 30, 2021, 6:49am UTC](https://discuss.elastic.co/t/cant-make-text-field-aggregatable/293178 "2021-12-30T06:49:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![titan\_tm](https://avatars.discourse-cdn.com/v4/letter/t/2acd7d/32.png) [@titan\_tm](https://discuss.elastic.co/u/titan_tm)\
**Post date:** [December 30, 2021, 6:49am UTC](https://discuss.elastic.co/t/cant-make-text-field-aggregatable/293178/1 "2021-12-30T06:49:21Z")

</div>

Hello guys,  
I'm currently facing with issue related to visualization and need help.

ELK gets syslogs from cisco routers via filebeat, it parses the logs fine, which is great and It also works great in discovery. However, the main field which is called "MESSAGE" is not aggregatable, unfortunately. The field is in **text** format to make it aggregatable it needs to be changed to **keyword** but I'm not sure. I've tried to change the type of the field but it is not possible in index pattern, I've changed the type in **Legacy index templates** , but nothing changed.

All I need is to add message table into dashboard.  
Thank you in advance

---

<div class="post-metadata">

**Author:** ![FALEN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/falen/32/82754_2.png) [@FALEN](https://discuss.elastic.co/u/FALEN)\
**Post date:** [December 30, 2021, 7:19am UTC](https://discuss.elastic.co/t/cant-make-text-field-aggregatable/293178/2 "2021-12-30T07:19:46Z")

</div>

Greetings from the person whose words may not be true,

Your change on legacy index template will only apply if new indices created.  
Reindex will work too

> POST \_reindex  
> {  
> "source": {  
> "index": "my-index-000001"  
> },  
> "dest": {  
> "index": "my-new-index-000001"  
> }  
> }

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [December 30, 2021, 7:40am UTC](https://discuss.elastic.co/t/cant-make-text-field-aggregatable/293178/3 "2021-12-30T07:40:15Z")

</div>

It is true that you cannot aggregate on the text field type. You should be able to add `keyword` type to your existing field ([documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-fields.html)). After reindexing, this new field will show up as aggregatable.

---

<div class="post-metadata">

**Author:** ![titan\_tm](https://avatars.discourse-cdn.com/v4/letter/t/2acd7d/32.png) [@titan\_tm](https://discuss.elastic.co/u/titan_tm)\
**Post date:** [January 3, 2022, 6:20am UTC](https://discuss.elastic.co/t/cant-make-text-field-aggregatable/293178/4 "2022-01-03T06:20:38Z")

</div>

Greetings and Happy New Year!

I just removed the old indice and created new one. Now it works fine! Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2022, 6:20am UTC](https://discuss.elastic.co/t/cant-make-text-field-aggregatable/293178/5 "2022-01-31T06:20:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
