# Field Available in Discovery, but Not in Visualization

**URL:** <https://discuss.elastic.co/t/field-available-in-discovery-but-not-in-visualization/298903>\
**Category:** Beats\
**Tags:** beats-module\
**Created:** [March 6, 2022, 3:56am UTC](https://discuss.elastic.co/t/field-available-in-discovery-but-not-in-visualization/298903 "2022-03-06T03:56:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cyberphor](https://avatars.discourse-cdn.com/v4/letter/c/8edcca/32.png) [@cyberphor](https://discuss.elastic.co/u/cyberphor)\
**Post date:** [March 6, 2022, 3:56am UTC](https://discuss.elastic.co/t/field-available-in-discovery-but-not-in-visualization/298903/1 "2022-03-06T03:56:39Z")

</div>

Hello,

I'm running Elasticsearch, Kibana, and Winlogbeat (all of which are version 8.0.1) on a Windows 10 desktop.

When I query for `event.code:4104` using the "Discovery" tab, one of the available fields is `powershell.file.script_block_text`.

Yet, when I attempt to make the same query while building a visualization (using the same index and timeline), this specific field is not available. I also attempted to use the original/pre-processor field name (`winlog.event_data.ScriptBlockText`), but the result is the same.

Can anyone help in what direction I should take to address this issue?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2022, 5:56am UTC](https://discuss.elastic.co/t/field-available-in-discovery-but-not-in-visualization/298903/2 "2022-04-03T05:56:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
