# Dashboards are not picking right fields

**URL:** <https://discuss.elastic.co/t/dashboards-are-not-picking-right-fields/345032>\
**Category:** Kibana\
**Tags:** kql-kibana-query-language\
**Created:** [October 14, 2023, 5:10pm UTC](https://discuss.elastic.co/t/dashboards-are-not-picking-right-fields/345032 "2023-10-14T17:10:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![huzaifa224](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/huzaifa224/32/105868_2.png) [@huzaifa224](https://discuss.elastic.co/u/huzaifa224)\
**Post date:** [October 14, 2023, 5:10pm UTC](https://discuss.elastic.co/t/dashboards-are-not-picking-right-fields/345032/1 "2023-10-14T17:10:27Z")

</div>

I am sending data from multiple Linux servers to Logstash using Filebeat, which then forwards the data to Elasticsearch after applying parsing rules for SSH logs. The problem is that when I open the default SSH dashboards, the graphs are not displaying properly. After some research and experimentation, I discovered that there are duplicate fields in the dashboards, which is causing the issue.

In the SSH login dashboard, there are two fields: (i) `system.auth.ssh.event` and (ii) `system.auth.ssh.event.keyword`. The dashboard data is being stored in the second field instead of the first one, and I'm unable to determine where this second field is coming from.

I created a custom template and set the field type to "text," but the dashboards are still using the field as `system.auth.ssh.event.keyword`.

I hope this explanation clarifies the situation.

Here is my logstash rule file:

```auto
> filter {
> grok {
> match => {
> "message" => [
> "%{SYSLOGTIMESTAMP} %{HOSTNAME:host.name} sshd\[%{NUMBER:pid}]: %{DATA:system.auth.ssh.event} %{DATA:system.auth.ssh.method} for (invalid user )?%{DATA:user.name} from %{IP:source.ip} port %{NUMBER:port} %{GREEDYDATA}",
> "%{SYSLOGTIMESTAMP} %{HOSTNAME:host.name} sshd\[%{NUMBER:pid}]: %{GREEDYDATA}: %{DATA:system.auth.ssh.event}; %{DATA}=%{DATA}=%{DATA}=%{DATA}=%{DATA}=%{DATA}=%{IP:source.ip}",
> "%{SYSLOGTIMESTAMP} %{HOSTNAME:host.name} sshd\[%{NUMBER:pid}]: %{GREEDYDATA}: %{DATA:system.auth.ssh.event} for (invalid user )?%{DATA:user.name} from %{IP:source.ip} port %{NUMBER:port} %{GREEDYDATA}",
> "\[%{TIMESTAMP_ISO8601:timestamp}\] \[%{WORD:module}:notice\] \[%{GREEDYDATA} %{POSINT:pid}:%{GREEDYDATA} %{POSINT:pid}\] %{WORD}: %{DATA}, %{WORD:service.status}%{SPACE}%{WORD:service.status}",
> "%{TIME}Z %{NUMBER} \[%{DATA}] %{DATA:system.auth.ssh.event} for user %{QUOTEDSTRING:user.name}@%{QUOTEDSTRING:source.ip}",
> "%{SYSLOGTIMESTAMP:timestamp} %{HOSTNAME:hostname} sshd\[%{NUMBER:pid}\]: Connection closed by authenticating user %{USERNAME:user.name} %{IP:source.ip} port %{NUMBER:port} \[%{DATA:auth_status}\]",
> "%{SYSLOGTIMESTAMP:timestamp} %{HOSTNAME:host} sshd\[%{NUMBER:pid}\]: %{GREEDYDATA:system.auth.ssh.event} user %{USERNAME:user.name} from %{IP:source.ip} port %{NUMBER:port}"
> ]
> }
> }
> }
> output {
> elasticsearch {
> hosts => ["http://x.x.x.x:9200"]
> user => elastic
> password => LOupmnhp
> index => "filebeat-"
> 
> }
> }

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 15, 2023, 2:07am UTC](https://discuss.elastic.co/t/dashboards-are-not-picking-right-fields/345032/2 "2023-10-15T02:07:45Z")

</div>

@huzaifa224

Apologies it is not clear exactly what you are trying to accomplish, not what the issue is.  
It looks like you have a mismatch in the the OOTB Dashboard, templates and your data.

**First What version of the Stack?**

Second, are you trying to use the Filebeat System Module for the SSH?

That is how the OOTB Dashboards would work? Using Filebeat

I highly recommend getting this to work on one of your hosts first.

Filebeat System Module -\> Elasticsearch (No Logstash)

Using the method described in the [Filebeat Quick Start?](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-installation-configuration.html)

Follow these directions and get it to work.

running  
`filebeat setup -e`  
is key steps where filebeat needs to point to elasticsearch and Kibana it loads the templates and the dashboards.

Then start filebeat And See if the Dashboards Work (you will probably need to clean up the filebeat indices)

Get this to work **BEFORE** you try putting logstash in the middle.

If so then you can work on putting logstash in the middle ...

Filebeat System Module -\> Logsash -\> Elasticsearch

Depending on the version you will need to use

**NOTE these are different.**

8.x

> **[Use ingest pipelines for parsing | Logstash Reference \[8.10\] | Elastic](https://www.elastic.co/guide/en/logstash/current/use-ingest-pipelines.html)**

7.x

> **[Use ingest pipelines for parsing | Logstash Reference \[7.17\] | Elastic](https://www.elastic.co/guide/en/logstash/7.17/use-ingest-pipelines.html)**

Also ignore this ...  
`filebeat setup --pipelines --modules nginx,system`

IF you already ran  
`filebeat setup -e` when you were going Filebeat -\> Elasticsearch Direct.

`system.auth.ssh.event` will be mapped to a `keyword` type if you properly load the templates

Are you talking about these Dashboards?

 ![Screenshot 2023-10-14 at 7.28.28 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/b/3b2659e88accbdad638e1f94561a2f90ef562b7b.png)

 ![Screenshot 2023-10-14 at 7.28.33 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/1/31de7bed372757f73e676d03253ddb575c9b168a.png)

`system.auth.ssh.event` will be mapped to a `keyword` type if you properly load the templates

 ![Screenshot 2023-10-14 at 7.28.51 PM](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2d93b052d9f51483b512a72537c31fdcf9a48f8c.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2023, 2:08am UTC](https://discuss.elastic.co/t/dashboards-are-not-picking-right-fields/345032/3 "2023-11-12T02:08:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
