# Field added by Logstash Grok can't be used in Kibana filters

**URL:** <https://discuss.elastic.co/t/field-added-by-logstash-grok-cant-be-used-in-kibana-filters/267122>\
**Category:** Kibana\
**Created:** [March 12, 2021, 8:08pm UTC](https://discuss.elastic.co/t/field-added-by-logstash-grok-cant-be-used-in-kibana-filters/267122 "2021-03-12T20:08:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![b133](https://avatars.discourse-cdn.com/v4/letter/b/85f322/32.png) [@b133](https://discuss.elastic.co/u/b133)\
**Post date:** [March 12, 2021, 8:08pm UTC](https://discuss.elastic.co/t/field-added-by-logstash-grok-cant-be-used-in-kibana-filters/267122/1 "2021-03-12T20:08:36Z")

</div>

I added a hostname field to my index using Logstash Grok:

```auto
grok {
           match => { "originsicname" => "CN=%{HOSTNAME:hostname}," }
...

```

For some reason I cannot use this `hostname` field as a filter on my dashboards. The Kibana dropdown control panel says this field `doesn't exist on any documents in the index pattern`. And the dashboard Edit Filter dialog says `There aren't any options available.` when I try to create a filter.

 ![Screen Shot 2021-03-12 at 11.57.04 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9f66cb379abe9a6dedd3cc06f564b8d71d5d2a16.png)

Yet the Discover app shows the field does exist in the index.

 ![discover-hostnames](https://us1.discourse-cdn.com/elastic/original/3X/1/7/179b978493b50d4769077c58d130fa8a25c2fe2d.jpeg)

And the Management app shows my Index Pattern has the field and is `searchable` and `Aggregatable`:

 ![index-pattern-field](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ffb11ccd2aa9d70afc7cbe654a85be6f419e5f74.png)

On another dashboard with a separate (but nearly identical) index pattern, I'm able to use a hostname field as a filter in Kibana just fine. The only difference is on the other index, I didn't have to add the hostname field using Grok. I'm using the `filebeat-7.11.0` index pattern as a component template for both index patterns. Filebeat is the original input source to Logstash for both indices. I'm running ES 7.11 on Debian.

Any advice?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [March 12, 2021, 8:55pm UTC](https://discuss.elastic.co/t/field-added-by-logstash-grok-cant-be-used-in-kibana-filters/267122/2 "2021-03-12T20:55:11Z")

</div>

Does the index pattern one that works have a `hostname.keyword` mapping while the one that does not is missing that?

---

<div class="post-metadata">

**Author:** ![b133](https://avatars.discourse-cdn.com/v4/letter/b/85f322/32.png) [@b133](https://discuss.elastic.co/u/b133)\
**Post date:** [March 12, 2021, 10:26pm UTC](https://discuss.elastic.co/t/field-added-by-logstash-grok-cant-be-used-in-kibana-filters/267122/3 "2021-03-12T22:26:16Z")

</div>

> [@aaron-nimocks](#):
>
> Does the index pattern one that works have a `hostname.keyword` mapping while the one that does not is missing that?

Both of my index patterns just use the same component template `filebeat-7.11.0`. I see the same inherited mappings on both indices:

```auto
GET mcs-checkpoint-2021.03.05-01/_mapping
{
  "mcs-checkpoint-2021.03.05-01" : {
    "mappings" : {
...
        "checkpoint" : {
...
            "hostname" : {
              "type" : "keyword",
              "ignore_above" : 1024
            },
...

```

I just tried creating a `checkpoint.hostname` field with logstash grok to see if I was just not using the correct namespace, but that seems to have the same issue.

---

<div class="post-metadata">

**Author:** ![b133](https://avatars.discourse-cdn.com/v4/letter/b/85f322/32.png) [@b133](https://discuss.elastic.co/u/b133)\
**Post date:** [March 15, 2021, 7:42pm UTC](https://discuss.elastic.co/t/field-added-by-logstash-grok-cant-be-used-in-kibana-filters/267122/4 "2021-03-15T19:42:59Z")

</div>

Ah, you were right afterall. I've just rebuilt the index mapping just as before, but this time specified explicitly the mapping:

```auto
{
  "properties": {
    "hostname": {
      "type": "keyword"
    }
  }
}

```

And now Kibana is able to filter using this keyword as expected.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [March 15, 2021, 7:46pm UTC](https://discuss.elastic.co/t/field-added-by-logstash-grok-cant-be-used-in-kibana-filters/267122/5 "2021-03-15T19:46:48Z")

</div>

That's good because I was stuck on what to check next. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2021, 7:47pm UTC](https://discuss.elastic.co/t/field-added-by-logstash-grok-cant-be-used-in-kibana-filters/267122/6 "2021-04-12T19:47:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
