# Differences between \_source in Kibana and in elasticsearch

**URL:** <https://discuss.elastic.co/t/differences-between--source-in-kibana-and-in-elasticsearch/21084>\
**Category:** Elasticsearch\
**Created:** [December 4, 2014, 3:08pm UTC](https://discuss.elastic.co/t/differences-between--source-in-kibana-and-in-elasticsearch/21084 "2014-12-04T15:08:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stefan\_Meisner\_Larse](https://avatars.discourse-cdn.com/v4/letter/s/7ba0ec/32.png) [@Stefan\_Meisner\_Larse](https://discuss.elastic.co/u/Stefan_Meisner_Larse)\
**Post date:** [December 4, 2014, 3:08pm UTC](https://discuss.elastic.co/t/differences-between--source-in-kibana-and-in-elasticsearch/21084/1 "2014-12-04T15:08:49Z")

</div>

Hi,

I use logstash's syslog plugin to collect logs, searching elastic search  
and kibana for the same object gives different results in the \_source  
field...

Elasticsearch version 1.4.0, Kibana 4.0.0-BETA2

When querying elasticsearch with curl I get:

curl -XGET [http://localhost:9200/logstash\*/\_search?pretty](http://localhost:9200/logstash*/_search?pretty)  
stml@riakcs:~/work/java/elasticsearch/data/stml\_elasticsearch/nodes/0/indices$  
curl -XGET  
'[http://localhost:9200/logstash\*/\_search?pretty&q=\_id:AUoVYl3Ayvv7Nc0uRA6X](http://localhost:9200/logstash*/_search?pretty&q=_id:AUoVYl3Ayvv7Nc0uRA6X)'  
{  
"took" : 7,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 5,  
"successful" : 5,  
"failed" : 0  
},  
"hits" : {  
"total" : 1,  
"max\_score" : 1.0,  
"hits" : [ {  
"\_index" : "logstash-2014.12.04",  
"\_type" : "syslog",  
"\_id" : "AUoVYl3Ayvv7Nc0uRA6X",  
"\_score" : 1.0,  
"\_source":{"message":"pam\_authenticate: Authentication  
failure","@version":"1","@timestamp":"2014-12-04T12:59:35.000Z","type":"syslog","host":"0:0:0:0:0:0:0:1","priority":83,"timestamp":"Dec  
4  
13:59:35","logsource":"riakcs","program":"su","pid":"15292","severity":3,"facility":10,"facility\_label":"security/authorization","severity\_label":"Error"}  
} ]  
}  
}

But in Kibana I get:

@timestamp December 4th 2014, 13:59:35.000 @version 1 \_id  
AUoVYl3Ayvv7Nc0uRA6X \_index logstash-2014.12.04 \_source {"message":"pam\_authenticate:  
Authentication  
failure","@version":"1","@timestamp":"2014-12-04T12:59:35.000Z","type":"syslog","host":"0:0:0:0:0:0:0:1"}  
\_type syslog host 0:0:0:0:0:0:0:1 message pam\_authenticate:  
Authentication failure type syslog

Missing a lot of fields in \_source...

I would have expected these views of the same field to be alike...have I  
misunderstood something

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/25a96d8d-6e51-4e48-8294-14bd9b52be34%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/25a96d8d-6e51-4e48-8294-14bd9b52be34%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Jay\_Swan](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@Jay\_Swan](https://discuss.elastic.co/u/Jay_Swan)\
**Post date:** [December 4, 2014, 9:47pm UTC](https://discuss.elastic.co/t/differences-between--source-in-kibana-and-in-elasticsearch/21084/2 "2014-12-04T21:47:49Z")

</div>

I would guess that you need to refresh your field list in the Settings \>  
Indices \> Index pattern section of Kibana4; this is a new thing in Kibana4  
that's very different from v3. Drove me crazy trying to figure it out until  
I filed an issue. See Rashid's answer to my Github issue here:

> <https://github.com/elastic/kibana/issues/1995>

It would be nice to see this happen at least semi-automagically in the  
future; it's going to bite a lot of people during migration.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/fa95a091-752b-40de-b5f4-99dc3cc0c5aa%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/fa95a091-752b-40de-b5f4-99dc3cc0c5aa%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Stefan\_Meisner\_Larse](https://avatars.discourse-cdn.com/v4/letter/s/7ba0ec/32.png) [@Stefan\_Meisner\_Larse](https://discuss.elastic.co/u/Stefan_Meisner_Larse)\
**Post date:** [December 5, 2014, 11:09am UTC](https://discuss.elastic.co/t/differences-between--source-in-kibana-and-in-elasticsearch/21084/3 "2014-12-05T11:09:21Z")

</div>

Hi Jay,

Thank you!

That did the trick. I did go crazy over this problem too 😉 I simply can't  
understand how Kibana can choose to fiddle with \_source before showing  
it...seems very strange to me...

Cheers,  
Stefan

Den torsdag den 4. december 2014 22.47.49 UTC+1 skrev Jay Swan:

> I would guess that you need to refresh your field list in the Settings \>  
> Indices \> Index pattern section of Kibana4; this is a new thing in Kibana4  
> that's very different from v3. Drove me crazy trying to figure it out until  
> I filed an issue. See Rashid's answer to my Github issue here:
> 
> [Discover doesn't show all fields · Issue #1995 · elastic/kibana · GitHub](https://github.com/elasticsearch/kibana/issues/1995)
> 
> It would be nice to see this happen at least semi-automagically in the  
> future; it's going to bite a lot of people during migration.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/17cf6d2f-1bbb-400f-a0a6-043c4ae7d0d8%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/17cf6d2f-1bbb-400f-a0a6-043c4ae7d0d8%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:45am UTC](https://discuss.elastic.co/t/differences-between--source-in-kibana-and-in-elasticsearch/21084/4 "2017-07-06T00:45:38Z")

</div>


