# Discover. Field data loading is forbidden on \[timestamp\]

**URL:** <https://discuss.elastic.co/t/discover-field-data-loading-is-forbidden-on-timestamp/50434>\
**Category:** Kibana\
**Created:** [May 19, 2016, 12:25pm UTC](https://discuss.elastic.co/t/discover-field-data-loading-is-forbidden-on-timestamp/50434 "2016-05-19T12:25:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dr\_rock](https://avatars.discourse-cdn.com/v4/letter/d/9de0a6/32.png) [@dr\_rock](https://discuss.elastic.co/u/dr_rock)\
**Post date:** [May 19, 2016, 12:25pm UTC](https://discuss.elastic.co/t/discover-field-data-loading-is-forbidden-on-timestamp/50434/1 "2016-05-19T12:25:46Z")

</div>

Hi,

I am currently using, E(2.3.2)L(2.3.2)K(4.5.0) to aggregate logs from a syslog source.  
I am using logstash default template, my output config is :

```
output {
  elasticsearch {
    hosts => ["host1:port1", "host2:port2", "host3:port3"]
  }
}

```

Here is the thing :  
Our syslog logs comme with **timestamp** field which have a funny pattern _"May 19 02:01:33"_.  
We were originally parsing this field threw **date** filter to populate **@timestamp** and dropping it.  
We are using **@timestamp** in our Kibana configuration.

For some reason, we've updated our Logstash conf and **timestamp** is not deleted anymore.

When I open Kibana's Discover, I now have the following error :

```
Discover: Field data loading is forbidden on [timestamp] More Info OK

```

When I had a look at the **\_mapping** I found out that **timestamp** was not detected as a date (probably thank to funny date format). Same thing in Kibana in **Setting \> Indices**.

Any clue?

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 19, 2016, 4:03pm UTC](https://discuss.elastic.co/t/discover-field-data-loading-is-forbidden-on-timestamp/50434/2 "2016-05-19T16:03:06Z")

</div>

Is `timestamp` set as your time field in Kibana now, or is it still `@timestamp`?

It sounds like you may have

```auto
"fielddata": {
  "format": "disabled" 
}

```

set for the `timestamp` field. This should only cause issues on Discover if you're trying to sort on that field, which Kibana would by default if `timestamp` is set as the time field.

In any case, you definitely need to point Kibana to a `Date` type field in Elasticsearch. If `@timestamp` still exists, updating your index pattern to use that field again would be the quick fix. Otherwise you'll probably need to re-index your data with a proper date field.

---

<div class="post-metadata">

**Author:** ![dr\_rock](https://avatars.discourse-cdn.com/v4/letter/d/9de0a6/32.png) [@dr\_rock](https://discuss.elastic.co/u/dr_rock)\
**Post date:** [May 19, 2016, 4:31pm UTC](https://discuss.elastic.co/t/discover-field-data-loading-is-forbidden-on-timestamp/50434/3 "2016-05-19T16:31:09Z")

</div>

Sorry if i was not clear : `@timestamp` is our time field. We do not use `timestamp` at all.

All `string` fields (including `timestamp`) are indexed :

```
"timestamp": {
   "type": "string",
   "norms": {
      "enabled": false
   },
   "fielddata": {
      "format": "disabled"
   },
   "fields": {
      "raw": {
         "type": "string",
         "index": "not_analyzed",
         "ignore_above": 256
      }
   }
}

```

And `timestamp` seems to be the only one causing this kind of errors.

Any clue?

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 20, 2016, 2:32pm UTC](https://discuss.elastic.co/t/discover-field-data-loading-is-forbidden-on-timestamp/50434/4 "2016-05-20T14:32:17Z")

</div>

Hmmm well the error you're seeing is coming from Elasticsearch. Could you open the network tab of your browser's devtools and look at the details of the request that's failing? It would be helpful to see the request url and body as well as the full response text. For some reason Kibana is using the `timestamp` field in a way that's incompatible with having fielddata disabled. Usually that would something like sorting or aggregations, but if we look at the request we can see exactly what's happening.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:52pm UTC](https://discuss.elastic.co/t/discover-field-data-loading-is-forbidden-on-timestamp/50434/5 "2017-07-06T13:52:45Z")

</div>


