# (ELK 7.9.1) Security - Hosts and Security - Network missing data

**URL:** <https://discuss.elastic.co/t/elk-7-9-1-security-hosts-and-security-network-missing-data/248576>\
**Category:** SIEM\
**Created:** [September 14, 2020, 6:54pm UTC](https://discuss.elastic.co/t/elk-7-9-1-security-hosts-and-security-network-missing-data/248576 "2020-09-14T18:54:25Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [September 15, 2020, 3:25pm UTC](https://discuss.elastic.co/t/elk-7-9-1-security-hosts-and-security-network-missing-data/248576/6 "2020-09-15T15:25:53Z")

</div>

Hi @ManuelF,

> I have seen these before in my custom dashboards and I have been able to fix them by replacing `field.data` by `field.data.keyword`

I would be very careful about changes like that and here's why. What might be happening is that you are ingesting data very _quickly_ right _as_ you are deleting your mappings and then Elastic Search is _auto_ creating your indexes by "guessing" at them before you had a chance to run the beats setup:

> **[Dynamic mapping | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-mapping.html)**

What you _dont_ want really is ES taking a guess at the indexes before you had a chance to run "setup" from the beats. When that happens because your data ingest is not turned off when you're deleting beat mappings ES is going to make naive and ambiguous choices that will not work out well for most cases. Good examples will be that you would start to notice things like `source.ip` is now a `keyword` and `text` data type rather than an `ip` data type which is then not going to work with CIDR patterns from detection rules.

I put some links to other times we have helped people out, but I would ensure that your mappings match that of beats and reindex if they do not. If you do delete them, I would ensure you turn off existing beats first so you don't get auto-created indexes or you can set ES to tell it to not auto-create index mappings for a brief moment of time and get dropped messages for a few seconds while you upgrade to your next set of mappings.

fwiw, you can do a manual export of a beats mapping as well to compare them to your current mappings that might or might not be auto-created:

> **[Load the Elasticsearch index template | Filebeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html#load-template-manually-alternate)**

> [@SIEM does not show data](https://discuss.elastic.co/t/siem-does-not-show-data/229010/5):
>
> You didn't show me your mapping above? You just showed me a screen shot of where you tried to modify your mapping to turn on fielddata which is still not really recommended. I think you wanted to show me from line 23 and below which would be: GET filebeat-\*/\_mapping However, if you have a direct connection from filebeat you can follow the commands from here: [https://www.elastic.co/guide/en/beats/filebeat/current/command-line-options.html#setup-command](https://www.elastic.co/guide/en/beats/filebeat/current/command-line-options.html#setup-command) to setup your templates such as: fileb…

> [@SIEM doesn't show any Winlogbeat events, despite ES receiving them](https://discuss.elastic.co/t/siem-doesnt-show-any-winlogbeat-events-despite-es-receiving-them/224008/10):
>
> @Aura, ahhh, I think I might see what's going on. I bet when you first setup winlog beat you accidentally forgot to push your templates which control the mapping? [https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html) You can check your mapping in your dev tools: [Screen Shot 2020-04-10 at 7.47.05 AM] like so....To see the entire mapping of your winlog beats: GET winlogbeat-7.6.0/\_mapping If you want to just concentrate on…

---

_[View the full topic](https://discuss.elastic.co/t/elk-7-9-1-security-hosts-and-security-network-missing-data/248576)._
