# Field content shown in json but not in table

**URL:** <https://discuss.elastic.co/t/field-content-shown-in-json-but-not-in-table/46656>\
**Category:** Kibana\
**Created:** [April 7, 2016, 9:45am UTC](https://discuss.elastic.co/t/field-content-shown-in-json-but-not-in-table/46656 "2016-04-07T09:45:21Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![devjr](https://avatars.discourse-cdn.com/v4/letter/d/0ea827/32.png) [@devjr](https://discuss.elastic.co/u/devjr)\
**Post date:** [April 7, 2016, 9:45am UTC](https://discuss.elastic.co/t/field-content-shown-in-json-but-not-in-table/46656/1 "2016-04-07T09:45:21Z")

</div>

Hello,

I have a weird problem : my facility field is shown as empty in kibana.  
But when I display the JSON, it seem OK.

![](https://us1.discourse-cdn.com/elastic/original/2X/0/0d5fba182150ec7895baf8fbdb01b20439c49197.png)  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/4fa89a9acf68846cbd61956d5d3f8b49d7f4dc60.png)

Am I doing something wrong or is this a bug ?  
Elasticsearch version 2.2.1 and kibana version 4.4.1.

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [April 7, 2016, 6:10pm UTC](https://discuss.elastic.co/t/field-content-shown-in-json-but-not-in-table/46656/2 "2016-04-07T18:10:50Z")

</div>

It looks like kibana thinks the field is a number. Did your mappings change at some point? Can you try refreshing your index pattern from the settings page?

---

<div class="post-metadata">

**Author:** ![devjr](https://avatars.discourse-cdn.com/v4/letter/d/0ea827/32.png) [@devjr](https://discuss.elastic.co/u/devjr)\
**Post date:** [April 8, 2016, 7:22am UTC](https://discuss.elastic.co/t/field-content-shown-in-json-but-not-in-table/46656/3 "2016-04-08T07:22:33Z")

</div>

Hello,

I never modified the index pattern, il left it to the default logstash-\*.  
Same thing for the mappings,

Here they are :

> root@sv-t-vnl-logs-bddr01:~# curl -XGET localhost:9200/\_template/logstash?pretty  
> {  
> "logstash" : {  
> "order" : 0,  
> "template" : "logstash-_",  
> "settings" : {  
> "index" : {  
> "number\_of\_shards" : "6",  
> "routing" : {  
> "allocation" : {  
> "include" : {  
> "type" : ""  
> },  
> "require" : {  
> "type" : "StockageChaud"  
> }  
> }  
> },  
> "refresh\_interval" : "5s"  
> }  
> },  
> "mappings" : {  
> "default" : {  
> "dynamic\_templates" : [ {  
> "message\_field" : {  
> "mapping" : {  
> "fielddata" : {  
> "format" : "disabled"  
> },  
> "index" : "analyzed",  
> "omit\_norms" : true,  
> "type" : "string"  
> },  
> "match\_mapping\_type" : "string",  
> "match" : "message"  
> }  
> }, {  
> "string\_fields" : {  
> "mapping" : {  
> "fielddata" : {  
> "format" : "disabled"  
> },  
> "index" : "analyzed",  
> "omit\_norms" : true,  
> "type" : "string",  
> "fields" : {  
> "raw" : {  
> "ignore\_above" : 256,  
> "index" : "not\_analyzed",  
> "type" : "string",  
> "doc\_values" : true  
> }  
> }  
> },  
> "match\_mapping\_type" : "string",  
> "match" : "_"  
> }  
> }, {  
> "float\_fields" : {  
> "mapping" : {  
> "type" : "float",  
> "doc\_values" : true  
> },  
> "match\_mapping\_type" : "float",  
> "match" : "_"  
> }  
> }, {  
> "double\_fields" : {  
> "mapping" : {  
> "type" : "double",  
> "doc\_values" : true  
> },  
> "match\_mapping\_type" : "double",  
> "match" : "_"  
> }  
> }, {  
> "byte\_fields" : {  
> "mapping" : {  
> "type" : "byte",  
> "doc\_values" : true  
> },  
> "match\_mapping\_type" : "byte",  
> "match" : "_"  
> }  
> }, {  
> "short\_fields" : {  
> "mapping" : {  
> "type" : "short",  
> "doc\_values" : true  
> },  
> "match\_mapping\_type" : "short",  
> "match" : "_"  
> }  
> }, {  
> "integer\_fields" : {  
> "mapping" : {  
> "type" : "integer",  
> "doc\_values" : true  
> },  
> "match\_mapping\_type" : "integer",  
> "match" : "_"  
> }  
> }, {  
> "long\_fields" : {  
> "mapping" : {  
> "type" : "long",  
> "doc\_values" : true  
> },  
> "match\_mapping\_type" : "long",  
> "match" : "_"  
> }  
> }, {  
> "date\_fields" : {  
> "mapping" : {  
> "type" : "date",  
> "doc\_values" : true  
> },  
> "match\_mapping\_type" : "date",  
> "match" : "_"  
> }  
> }, {  
> "geo\_point\_fields" : {  
> "mapping" : {  
> "type" : "geo\_point",  
> "doc\_values" : true  
> },  
> "match\_mapping\_type" : "geo\_point",  
> "match" : "_"  
> }  
> } ],  
> "\_all" : {  
> "omit\_norms" : true,  
> "enabled" : true  
> },  
> "properties" : {  
> "@timestamp" : {  
> "type" : "date",  
> "doc\_values" : true  
> },  
> "geoip" : {  
> "dynamic" : true,  
> "type" : "object",  
> "properties" : {  
> "ip" : {  
> "type" : "ip",  
> "doc\_values" : true  
> },  
> "latitude" : {  
> "type" : "float",  
> "doc\_values" : true  
> },  
> "location" : {  
> "type" : "geo\_point",  
> "doc\_values" : true  
> },  
> "longitude" : {  
> "type" : "float",  
> "doc\_values" : true  
> }  
> }  
> },  
> "@version" : {  
> "index" : "not\_analyzed",  
> "type" : "string",  
> "doc\_values" : true  
> }  
> }  
> }  
> },  
> "aliases" : { }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![Khalah\_Jones\_Golden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khalah_jones_golden/32/7169_2.png) [@Khalah\_Jones\_Golden](https://discuss.elastic.co/u/Khalah_Jones_Golden)\
**Post date:** [April 8, 2016, 12:05pm UTC](https://discuss.elastic.co/t/field-content-shown-in-json-but-not-in-table/46656/4 "2016-04-08T12:05:03Z")

</div>

Hmm then maybe your data has changed. Why don't you explicitly set the type for the facilities field?

---

<div class="post-metadata">

**Author:** ![devjr](https://avatars.discourse-cdn.com/v4/letter/d/0ea827/32.png) [@devjr](https://discuss.elastic.co/u/devjr)\
**Post date:** [April 8, 2016, 1:17pm UTC](https://discuss.elastic.co/t/field-content-shown-in-json-but-not-in-table/46656/5 "2016-04-08T13:17:23Z")

</div>

I tried to specify %{WORD:facility:string} in logstash but the problem is still here ☹

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [April 8, 2016, 6:30pm UTC](https://discuss.elastic.co/t/field-content-shown-in-json-but-not-in-table/46656/6 "2016-04-08T18:30:36Z")

</div>

If you reindex with a new mapping you'll have to refresh on the Kibana side too. On the settings page for your index there's an orange refresh button you'll have to press after changing the mapping.

---

<div class="post-metadata">

**Author:** ![devjr](https://avatars.discourse-cdn.com/v4/letter/d/0ea827/32.png) [@devjr](https://discuss.elastic.co/u/devjr)\
**Post date:** [April 11, 2016, 7:17am UTC](https://discuss.elastic.co/t/field-content-shown-in-json-but-not-in-table/46656/7 "2016-04-11T07:17:15Z")

</div>

It worked !

Many thanks for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:56pm UTC](https://discuss.elastic.co/t/field-content-shown-in-json-but-not-in-table/46656/8 "2017-07-06T13:56:26Z")

</div>


