# Can't view fields In Discovery or via query even though they're available in Kibana visualizations

**URL:** <https://discuss.elastic.co/t/cant-view-fields-in-discovery-or-via-query-even-though-theyre-available-in-kibana-visualizations/234582>\
**Category:** Elasticsearch\
**Created:** [May 27, 2020, 4:16pm UTC](https://discuss.elastic.co/t/cant-view-fields-in-discovery-or-via-query-even-though-theyre-available-in-kibana-visualizations/234582 "2020-05-27T16:16:07Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![schoffelman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/schoffelman/32/18461_2.png) [@schoffelman](https://discuss.elastic.co/u/schoffelman)\
**Post date:** [May 27, 2020, 4:16pm UTC](https://discuss.elastic.co/t/cant-view-fields-in-discovery-or-via-query-even-though-theyre-available-in-kibana-visualizations/234582/1 "2020-05-27T16:16:07Z")

</div>

I have a few indexes, defined by a template, and each index is distinguished by year. When querying the current years index (previous years are fine), I get no fields to return any values. When looking at visualizations in Kibana, the fields are there and can be calculated.

I've also refreshed my index in Kibana and there are no mapping conflicts. Any thoughts on something I may be missing. I feel like it should be obvious, but I'm getting hung up on it.

Here is the template:

```auto
{
      "cr-ops-wrike*" : {
    "order" : 0,
    "index_patterns" : [
      "cr-ops-wrike-*",
      "cr-ops-test-wrike-*"
    ],
    "settings" : {
      "index" : {
        "number_of_shards" : "1"
      }
    },
    "mappings" : {
      "_source" : {
        "enabled" : false
      },
      "properties" : {
        "timelog_hours_logged" : {
          "type" : "float"
        }
      }
    },
    "aliases" : { }
      }
}
```

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 27, 2020, 4:30pm UTC](https://discuss.elastic.co/t/cant-view-fields-in-discovery-or-via-query-even-though-theyre-available-in-kibana-visualizations/234582/2 "2020-05-27T16:30:09Z")

</div>

Hello @schoffelman

Can you share the output of `GET cr-ops-*wrike-*` and an example of the query which doesn't return any value vs one which returns the results?

---

<div class="post-metadata">

**Author:** ![schoffelman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/schoffelman/32/18461_2.png) [@schoffelman](https://discuss.elastic.co/u/schoffelman)\
**Post date:** [May 27, 2020, 4:36pm UTC](https://discuss.elastic.co/t/cant-view-fields-in-discovery-or-via-query-even-though-theyre-available-in-kibana-visualizations/234582/3 "2020-05-27T16:36:26Z")

</div>

You bet. Here's the query:

```auto
GET /cr-ops-wrike-time-2020/_search
{
  "query": {
    "range": {
      "@timestamp": {
        "gte": "2020-03-01"
      }
    }
  }
}

```

And here is a sample result:

```auto
{
  "took" : 10,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 10000,
      "relation" : "gte"
    },
    "max_score" : 1.0,
    "hits" : [
      {
        "_index" : "cr-ops-wrike-time-2020",
        "_type" : "_doc",
        "_id" : "3f6BwHABnH_-7kJihrsw",
        "_score" : 1.0
      },

```

---

<div class="post-metadata">

**Author:** ![schoffelman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/schoffelman/32/18461_2.png) [@schoffelman](https://discuss.elastic.co/u/schoffelman)\
**Post date:** [May 27, 2020, 4:40pm UTC](https://discuss.elastic.co/t/cant-view-fields-in-discovery-or-via-query-even-though-theyre-available-in-kibana-visualizations/234582/4 "2020-05-27T16:40:41Z")

</div>

The previous index looks like this:

Query:

```auto
GET /cr-ops-wrike-time-2019/_search
{
  "query": {
    "range": {
      "@timestamp": {
        "gte": "2020-02-01"
      }
    }
  }
}

```

Sample Result:

```auto
"hits" : [
      {
        "_index" : "reindexed-v7-cr-ops-wrike-time-2019",
        "_type" : "_doc",
        "_id" : "2heWDHABj8nezjVaIsOX",
        "_score" : 1.0,
        "_source" : {
          "@timestamp" : "2020-02-01T12:00:00Z",
          "task_id" : "IEABLR4CKQEXUMNV",
          "task_title" : "General Office",
          "task_created_date" : "2017-06-15T20:05:15Z",
          "task_updated_date" : "2019-09-03T13:57:36Z",
          "task_permalink" : "https://www.wrike.com/open.htm?id= **********",
          "task_status" : "Active",
          "client_folder_id" : "IEABLR4CI4EXULV7",
          "client_folder_name" : "[CR] General Ops",
          "timelog_id" : "IEABLR4CJQAE57VZ",
          "timelog_hours_logged" : 1,
          "timelog_comment" : " *******************",
          "timelog_created_date" : "2020-02-01T20:04:07Z",
          "timelog_updated_date" : "2020-02-01T20:04:07Z",
          "timelog_tracked_date" : "2020-02-01",
          "timelog_api_count" : 316,
          "meta_Client" : " **********",
          "user_id" : "KUADHE7B",
          "user_name" : " *****",
          "user_email" : " ****@*******.com",
          "user_active" : 1,
          "user_production" : 1
        }
      },

```

---

<div class="post-metadata">

**Author:** ![schoffelman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/schoffelman/32/18461_2.png) [@schoffelman](https://discuss.elastic.co/u/schoffelman)\
**Post date:** [May 27, 2020, 4:44pm UTC](https://discuss.elastic.co/t/cant-view-fields-in-discovery-or-via-query-even-though-theyre-available-in-kibana-visualizations/234582/5 "2020-05-27T16:44:53Z")

</div>

I can't remember, but I may have created the template after the previous indexes were created, but before the 2020 one was populated. In that case, would the `_source` field be the culprit?

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 27, 2020, 4:45pm UTC](https://discuss.elastic.co/t/cant-view-fields-in-discovery-or-via-query-even-though-theyre-available-in-kibana-visualizations/234582/6 "2020-05-27T16:45:58Z")

</div>

> [@Luca\_Belluccini](#):
>
> `GET cr-ops-*wrike-*`

Thanks, can you run exactly the query above (so I can check the mappings)?

* * *

On this query:

- `GET /cr-ops-wrike-time-2020/_search` you have an hit, but as you've disabled the `_source` thanks to the index template, the fields are not shown. You might be able to see the `"docvalue_fields"` for the fields where you have `docvalues`
- `GET /cr-ops-wrike-time-2019/_search` you have few hits and you're able to see the `_source`.

This happens probably because you updated/added the index template after the creation of the 2019 index, but before the creation of the index 2020.

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 27, 2020, 4:47pm UTC](https://discuss.elastic.co/t/cant-view-fields-in-discovery-or-via-query-even-though-theyre-available-in-kibana-visualizations/234582/7 "2020-05-27T16:47:43Z")

</div>

> [@schoffelman](#):
>
> In that case, would the `_source` field be the culprit?

Yes, it can be the reason.  
The problem now is `_source` is disabled so you cannot reindex.  
Do you have the original data?

---

<div class="post-metadata">

**Author:** ![schoffelman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/schoffelman/32/18461_2.png) [@schoffelman](https://discuss.elastic.co/u/schoffelman)\
**Post date:** [May 27, 2020, 4:48pm UTC](https://discuss.elastic.co/t/cant-view-fields-in-discovery-or-via-query-even-though-theyre-available-in-kibana-visualizations/234582/8 "2020-05-27T16:48:51Z")

</div>

Yep. It's not too hard to reindex. I just wanted to know the problem before redoing some of it so I didn't run into that situation again.

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [May 27, 2020, 4:49pm UTC](https://discuss.elastic.co/t/cant-view-fields-in-discovery-or-via-query-even-though-theyre-available-in-kibana-visualizations/234582/9 "2020-05-27T16:49:31Z")

</div>

Update the index template to remove `_source` (so it's enabled by default), remove the 2020 index and re-ingest and it should be fine 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2020, 4:49pm UTC](https://discuss.elastic.co/t/cant-view-fields-in-discovery-or-via-query-even-though-theyre-available-in-kibana-visualizations/234582/10 "2020-06-24T16:49:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
