# Dec 4th, 2019: \[EN\] Explore Elastic Common Schema (ECS) with Elasticsearch and Kibana

**URL:** <https://discuss.elastic.co/t/dec-4th-2019-en-explore-elastic-common-schema-ecs-with-elasticsearch-and-kibana/209867>\
**Category:** Advent Calendar\
**Tags:** ecs-elastic-common-schema\
**Created:** [December 4, 2019, 8:00am UTC](https://discuss.elastic.co/t/dec-4th-2019-en-explore-elastic-common-schema-ecs-with-elasticsearch-and-kibana/209867 "2019-12-04T08:00:04Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![webmat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webmat/32/46191_2.png) [@webmat](https://discuss.elastic.co/u/webmat)\
**Post date:** [December 4, 2019, 8:00am UTC](https://discuss.elastic.co/t/dec-4th-2019-en-explore-elastic-common-schema-ecs-with-elasticsearch-and-kibana/209867/1 "2019-12-04T08:00:04Z")

</div>

## Introduction

[Lire la version française](https://discuss.elastic.co/t/dec-4th-2019-fr-ecs-explorer-elastic-common-schema-ecs-avec-elasticsearch-et-kibana/209766)

Many resources are already available to learn about ECS. Of course, there's the [official documentation](https://www.elastic.co/guide/en/ecs/current/ecs-reference.html). Some users also use the CSV export, located at [generated/csv/fields.csv](https://github.com/elastic/ecs/blob/1.3/generated/csv/fields.csv). This CSV lets you quickly navigate and visualize all fields at once, or import the schema in a spreadsheet.

Did you know you can also import this CSV directly in Elasticsearch?

In this article, we'll import the CSV and the following dashboard:

 ![schema_explorer_dashboard_cropped](https://us1.discourse-cdn.com/elastic/original/3X/5/f/5f1c88ead40dde3c42e211c7226914a1bd6f3f33.png)

## Steps

This tutorial requires Elasticsearch and Kibana 7.2 at a minimum, but ideally 7.4 or 7.5.

### Importing the ECS field definitions

Download the CSV for ECS 1.3.1, recently released. You can do so from this Github page [generated/csv/fields.csv](https://github.com/elastic/ecs/blob/1.3/generated/csv/fields.csv) or from your terminal:

```auto
curl -O https://raw.githubusercontent.com/elastic/ecs/1.3/generated/csv/fields.csv

```

Next, open Kibana in the "Machine Learning" section, tab "Data Visualizer". This feature is freely available via the Basic license.

Upload the `fields.csv` file.

 ![data_visualizer](https://us1.discourse-cdn.com/elastic/original/3X/1/f/1fb7c148786149a62b5c4767a403e9d3796406d9.png)

If you're using 7.4 or more recent, you can immediately click "Import" at the "File Contents" page.

If you're using 7.2 or 7.3, make sure to go in "Override Settings", select "Has header row" and apply the change. The "File stats" section should now display the right column titles. You can now click "Import".

On the next screen, "Import data", click the "Advanced" tab.

1. Name the index "schema-explorer"
2. Uncheck "Create index pattern"
3. Replace the whole content of the "Mappings" section with the following:

```auto
{
  "Description": {
    "type": "keyword",
    "fields": { "text": { "type": "text" } }
  },
  "ECS_Version": {
    "type": "keyword"
  },
  "Example": {
    "type": "keyword"
  },
  "Field": {
    "type": "keyword"
  },
  "Field_Set": {
    "type": "keyword"
  },
  "Indexed": {
    "type": "boolean"
  },
  "Level": {
    "type": "keyword"
  },
  "Type": {
    "type": "keyword"
  }
}

```

The page should now look like:

 ![import_mappings](https://us1.discourse-cdn.com/elastic/original/3X/e/2/e23db85e095bd01627bc42bd07bed6432281462c.png)

Finally, click "Import". The field definitions are now imported in the "schema-explorer" index.

### Import the dashboard

Visit [this gist](https://gist.github.com/webmat/c2c3d0bb4bd8b8bf459cbc93f4018d6c) and download the file `schema-explorer.ndjson`.

In "Kibana Management" section "Saved Objects", import the file `schema-explorer.ndjson`.

Voilà! You can now use the "Schema Explorer" dashboard.

 ![schema_explorer_dashboard](https://us1.discourse-cdn.com/elastic/original/3X/9/5/95d7f3c6202023f6758b6d67af1e7a4bf9eccf2a.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:35am UTC](https://discuss.elastic.co/t/dec-4th-2019-en-explore-elastic-common-schema-ecs-with-elasticsearch-and-kibana/209867/2 "2022-11-04T07:35:24Z")

</div>


