# Child "meta\_fields" fails?

**URL:** <https://discuss.elastic.co/t/child-meta-fields-fails/193211>\
**Category:** Kibana\
**Created:** [July 31, 2019, 7:52pm UTC](https://discuss.elastic.co/t/child-meta-fields-fails/193211 "2019-07-31T19:52:11Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kenneth\_M\_Kolano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kenneth_m_kolano/32/38752_2.png) [@Kenneth\_M\_Kolano](https://discuss.elastic.co/u/Kenneth_M_Kolano)\
**Post date:** [July 31, 2019, 7:52pm UTC](https://discuss.elastic.co/t/child-meta-fields-fails/193211/1 "2019-07-31T19:52:12Z")

</div>

Tried updating to 7.3 today. I now get this error when opening the Discover pane, or trying to review the fields of specific indexes under "Management / Index patterns"

child "meta\_fields" fails because ["meta\_fields" must be an array]

request/\<@[https://192.168.0.239/kibana/bundles/commons.bundle.js:3:2481398](https://192.168.0.239/kibana/bundles/commons.bundle.js:3:2481398)  
run@[https://192.168.0.239/kibana/built\_assets/dlls/vendors.bundle.dll.js:364:96865](https://192.168.0.239/kibana/built_assets/dlls/vendors.bundle.dll.js:364:96865)  
notify/\<@[https://192.168.0.239/kibana/built\_assets/dlls/vendors.bundle.dll.js:364:97152](https://192.168.0.239/kibana/built_assets/dlls/vendors.bundle.dll.js:364:97152)  
flush@[https://192.168.0.239/kibana/built\_assets/dlls/vendors.bundle.dll.js:364:101897](https://192.168.0.239/kibana/built_assets/dlls/vendors.bundle.dll.js:364:101897)

I can't find any discussion of this besides this old discuss topic that was never responded to...

> [@KIBANA error : meta\_fields](https://discuss.elastic.co/t/kibana-error-meta-fields/114901):
>
> I am getting an error " child "meta\_fields" fails because ["meta\_fields" must be an array] " in kibana. How to solve this issue?

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [August 12, 2019, 7:30pm UTC](https://discuss.elastic.co/t/child-meta-fields-fails/193211/2 "2019-08-12T19:30:51Z")

</div>

> [@Kenneth\_M\_Kolano](#):
>
> child "meta\_fields" fails because ["meta\_fields" must be an array] "

Hello,  
Can you provide Kibana logs, screenshots, browser console logs etc. what were the steps you took ? May be try deleting the index and re-creating it and see if it disappears.  
What is the `meta_fields` field like ?

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![Kenneth\_M\_Kolano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kenneth_m_kolano/32/38752_2.png) [@Kenneth\_M\_Kolano](https://discuss.elastic.co/u/Kenneth_M_Kolano)\
**Post date:** [August 12, 2019, 9:28pm UTC](https://discuss.elastic.co/t/child-meta-fields-fails/193211/3 "2019-08-12T21:28:55Z")

</div>

> [@rashmi](#):
>
> Can you provide Kibana logs, screenshots, browser console logs etc. what were the steps you took ? May be try deleting the index and re-creating it and see if it disappears.  
> What is the `meta_fields` field like ?

The issue seems to mysteriously now be resolved on the VM it was occurring on. I think I had played with the "Meta fields" setting, but failed to restart Kibana, but I'm not sure. I was consistently seeing the issue with 7.3 deployments though, so I'll attempt a repeat deployment shortly to see if it still re-occurs.

I'll attempt to paste in my Kibana.log in a following post; it's large so I'm unclear it will be allowed; and this site only seems to allow for image attachments.

Actions taken

- Added Elasticsearch Repo:  
wget -timeout=15 --tries=5 -qO - [https://artifacts.elastic.co/GPG-KEY-elasticsearch](https://artifacts.elastic.co/GPG-KEY-elasticsearch) | sudo apt-key add -  
sudo bash -c "echo 'deb [https://artifacts.elastic.co/packages/7.x/apt](https://artifacts.elastic.co/packages/7.x/apt) stable main' \>\> /etc/apt/sources.list.d/elastic-7.x.list"
- Installed ELK 7.3: `sudo apt-fast install -y elasticsearch kibana logstash`
- Updated my JVM config to disable illegal reflective access warnings
- Set base path for Kibana reverse proxy access
- Disabled: Application Performance Monitoring interface, Infrastructure and Logs interfaces, Telemetry
- Added delay to Kibana service to to allow for Elasticsearch initialization /wo extensive errors/warnings
- Start ELK services
- Load a default index pattern:  
{  
"attributes": {  
"title": "logstash-\*",  
"timeFieldName": "@timestamp",  
"sourceFilters": "[{"value":"@version"},{"value":"alert.metadata.engine"},{"value":"in\_iface"},{"value":"path"},{"value":"type"}]"  
}  
}
- Set a default date format: `curl --connect-timeout 15 -s -X POST http://localhost:5601/kibana/api/kibana/settings/dateFormat -H "Content-Type: application/json" -H "kbn-xsrf: true" -d '{"value": "YY-MM-DD HH:mm:ss.SSS"}'`
- Set Kibana default index pattern: `curl --connect-timeout 15 -s -X POST http://localhost:5601/kibana/api/kibana/settings/defaultIndex -H "Content-Type: application/json" -H "kbn-xsrf: true" -d '{"value": "logstash-*"}'`
- Set Kibana Discovery search size: `curl --connect-timeout 15 -X POST http://localhost:5601/kibana/api/kibana/settings/discover:sampleSize -H "Content-Type: application/json" -H "kbn-xsrf: true" -d '{"value": "1000"}'`
- Hide Kibana fields found outside of source: `curl --connect-timeout 15 -s -X POST http://localhost:5601/kibana/api/kibana/settings/metaFields -H "Content-Type: application/json" -H "kbn-xsrf: true" -d '{"value": ["_source"]}'`
- Loaded a few dashboards / visualizations
- Rebooted
- Got errors from any dashboard /w a discover pane and the discover pane itself.

The meta\_fields field is set per the curl above as: "\_source"

In general the error provided here could be more explicit. I wasn't clear what meta\_fields even was; and didn't realize it was one of Kibana's Advanced Settings.

---

<div class="post-metadata">

**Author:** ![Kenneth\_M\_Kolano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kenneth_m_kolano/32/38752_2.png) [@Kenneth\_M\_Kolano](https://discuss.elastic.co/u/Kenneth_M_Kolano)\
**Post date:** [August 12, 2019, 9:31pm UTC](https://discuss.elastic.co/t/child-meta-fields-fails/193211/4 "2019-08-12T21:31:47Z")

</div>

No way to directly submit large log files here. Here is a Pastebin that will be availible till Sept 12th.

[https://pastebin.com/zkjCCiCg](https://pastebin.com/zkjCCiCg)

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [August 12, 2019, 10:01pm UTC](https://discuss.elastic.co/t/child-meta-fields-fails/193211/5 "2019-08-12T22:01:57Z")

</div>

Great to know your issue was resolved although by multiple restarts. Thanks for posting what you did. Helpful for the community.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![Kenneth\_M\_Kolano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kenneth_m_kolano/32/38752_2.png) [@Kenneth\_M\_Kolano](https://discuss.elastic.co/u/Kenneth_M_Kolano)\
**Post date:** [August 13, 2019, 3:32am UTC](https://discuss.elastic.co/t/child-meta-fields-fails/193211/6 "2019-08-13T03:32:38Z")

</div>

Not resolved. It reoccurs on a repeat deployment. I think I had just failed to restart Kibana after revising Meta fields when poking at things previously.

Here is the content of...  
[http://localhost:5601/kibana/api/kibana/settings](http://localhost:5601/kibana/api/kibana/settings)  
...returns...  
`{"settings":{"buildNum":{"userValue":25250},"dateFormat":{"userValue":"YY-MM-DD HH:mm:ss.SSS"},"defaultIndex":{"userValue":"logstash-*"},"discover:sampleSize":{"userValue":"1000"},"metaFields":{"userValue":["_source"]}}}`  
...where metaFields is an array.

Resetting "Meta fields" to the default via the UI: `_source, _id, _type, _index, _score` or any value that contains multiple fields resolves the issue; but setting it to `_source` , or any singular field (i.e. `_id` ) via the UI causes it to return; even though the singular value is still stored as an array (Kibana must be restarted between edits).

There does seem to be a bug here with how Meta fields is handled in 7.3: [https://github.com/elastic/kibana/issues/43167](https://github.com/elastic/kibana/issues/43167)

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [August 13, 2019, 4:56pm UTC](https://discuss.elastic.co/t/child-meta-fields-fails/193211/9 "2019-08-13T16:56:58Z")

</div>

Thankyou for opening the bug. We shall investigate further.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![jclemons7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jclemons7/32/20655_2.png) [@jclemons7](https://discuss.elastic.co/u/jclemons7)\
**Post date:** [August 22, 2019, 4:06am UTC](https://discuss.elastic.co/t/child-meta-fields-fails/193211/10 "2019-08-22T04:06:46Z")

</div>

Is there any update on this? I have the same error on beats indexes. I have two other indexes that are working fine.

Error fetching fields

child "meta\_fields" fails because ["meta\_fields" must be an array]

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [August 25, 2019, 10:03pm UTC](https://discuss.elastic.co/t/child-meta-fields-fails/193211/11 "2019-08-25T22:03:15Z")

</div>

plz subscribe to the bug and you will get updates when it will be fixed.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2019, 10:03pm UTC](https://discuss.elastic.co/t/child-meta-fields-fails/193211/12 "2019-09-22T22:03:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
