# Can't sort by column/field in Kabana

**URL:** https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929
**Category:** Kibana
**Created:** [April 13, 2023, 1:00pm UTC](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929 "2023-04-13T13:00:14Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![JackieLaFrite](https://avatars.discourse-cdn.com/v4/letter/j/9fc29f/32.png) [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)
#### Post date: [April 13, 2023, 1:00pm UTC](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929/1 "2023-04-13T13:00:14Z")

</div>

Hello, I'm currently implementing ELK on my environment to retrieve the logs and I got a problem.

In the discover tab, I can't sort a column. I can only sort by the @Timestamp.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/4/848d24450cce8746eb2cf7c4556a9531b8a26d38.png)

I would like to be able to sort by the column time or type. Here is my logstash.conf :

```auto
input {
  file {
    path => "/var/log/serverlogs/manager.*.log"
    start_position => "beginning"
    sincedb_path => "/dev/null"
    codec => multiline {
	  pattern => "^\s"
	  what => "previous"
    }
    type => "manager"
  }
}

filter{
	if [type] == "manager" {
		grok{
			match => {"message" => [
				"%{MONTHDAY:day}-%{MONTH:month}-%{YEAR:year} %{TIME:time} %{LOGLEVEL:log_level} %{GREEDYDATA:message_of_log}"
			]}
		}
	}
}

```

---

<div class="post-metadata">

### Author: ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)
#### Post date: [April 15, 2023, 3:22am UTC](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929/2 "2023-04-15T03:22:45Z")

</div>

Can you post the mapping that you have for that index? sort will work depending on the field type. As far as I know you can sort on datetime, numeric and keyword fields. You can change the `time` field to be "numeric" in miliseconds and then set as "human readable" and "duration" type in the field formatter in Kibana. (that will be available in the Data Views menu)

---

<div class="post-metadata">

### Author: ![JackieLaFrite](https://avatars.discourse-cdn.com/v4/letter/j/9fc29f/32.png) [@JackieLaFrite](https://discuss.elastic.co/u/JackieLaFrite)
#### Post date: [April 15, 2023, 3:50pm UTC](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929/3 "2023-04-15T15:50:47Z")

</div>

Hi, thanks for your answer.

Here is the data views page :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e56c2d01d2ac32865413feaa713199a95311acb3.png)

And here is the field that I need to modify but I can't :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/0/70bd3c2f3145dd9246ef31b994b3bfac8ec5a32e.png)

I got the mapping with this command in the console (but i'm not sure that this is the mapping of the index of this dataview, because I only have the index pattern as information) :

```auto
GET /logstash/_mapping

```

Here is the mapping :

```auto
{
  "logstash-2023.03.28-000001": {
    "mappings": {
      "dynamic_templates": [
        {
          "message_field": {
            "path_match": "message",
            "match_mapping_type": "string",
            "mapping": {
              "norms": false,
              "type": "text"
            }
          }
        },
        {
          "string_fields": {
            "match": "*",
            "match_mapping_type": "string",
            "mapping": {
              "fields": {
                "keyword": {
                  "ignore_above": 256,
                  "type": "keyword"
                }
              },
              "norms": false,
              "type": "text"
            }
          }
        }
      ],
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "@version": {
          "type": "keyword"
        },
        "auth": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "bytes": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "client": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "client_ip": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "day": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "event": {
          "properties": {
            "original": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              },
              "norms": false
            }
          }
        },
        "geoip": {
          "dynamic": "true",
          "properties": {
            "ip": {
              "type": "ip"
            },
            "latitude": {
              "type": "half_float"
            },
            "location": {
              "type": "geo_point"
            },
            "longitude": {
              "type": "half_float"
            }
          }
        },
        "host": {
          "properties": {
            "name": {
              "type": "text",
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              },
              "norms": false
            }
          }
        },
        "http_version": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "httpversion": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "ident": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "log": {
          "properties": {
            "file": {
              "properties": {
                "path": {
                  "type": "text",
                  "fields": {
                    "keyword": {
                      "type": "keyword",
                      "ignore_above": 256
                    }
                  },
                  "norms": false
                }
              }
            }
          }
        },
        "logLevel": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "message": {
          "type": "text",
          "norms": false
        },
        "month": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "myloglevel": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "mymessage": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "mytime": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "request": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "response_code": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "response_size": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "status": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "tags": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "time": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "timestamp": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "type": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "user_agent": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "verb": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        },
        "year": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          },
          "norms": false
        }
      }
    }
  }
}

```

How can I modify the mapping ?

---

<div class="post-metadata">

### Author: ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)
#### Post date: [April 15, 2023, 9:18pm UTC](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929/4 "2023-04-15T21:18:50Z")

</div>

Ideally the mapping has to be set at index creation time, but you can update it for future data to be ingested.  
This is the API: [Update mapping API | Elasticsearch Guide [8.7] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html)  
There also a very nice blog about it that matches your use case of ingesting via Logstash: [​Little Logstash Lessons: Using Logstash to help create an Elasticsearch mapping template | Elastic Blog](https://www.elastic.co/blog/logstash_lesson_elasticsearch_mapping)

---

<div class="post-metadata">

### Author: ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)
#### Post date: [April 17, 2023, 8:31am UTC](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929/5 "2023-04-17T08:31:29Z")

</div>

Hi @JackieLaFrite,

Adding `time.keyword` and `type.keyword` fields to the table will allow sorting by them (instead of `time` and `type` fields with "text" type).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 15, 2023, 10:37am UTC](https://discuss.elastic.co/t/cant-sort-by-column-field-in-kabana/329929/7 "2023-05-15T10:37:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
