# Field value not found in aggregatable field

**URL:** <https://discuss.elastic.co/t/field-value-not-found-in-aggregatable-field/323182>\
**Category:** Elasticsearch\
**Created:** [January 14, 2023, 6:16pm UTC](https://discuss.elastic.co/t/field-value-not-found-in-aggregatable-field/323182 "2023-01-14T18:16:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nnet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nnet/32/25982_2.png) [@nnet](https://discuss.elastic.co/u/nnet)\
**Post date:** [January 14, 2023, 6:16pm UTC](https://discuss.elastic.co/t/field-value-not-found-in-aggregatable-field/323182/1 "2023-01-14T18:16:54Z")

</div>

Hi folks, I'm at a loss to understand this.  
ELK stack 5.6.  
Using filebeat i send json logs of nginx to logstash where they're parsed and fed into elasticsearch. No errors, all seems good.  
In kibana I have a visualization data table to display counts of useragents, but I discovered today there's one useragent string that doesn't appear in the data table:

```
Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers&#39; presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com

```

I can search the field `http_user_agent` for the string just fine, but for some reason I get no results when aggregating on `http_user_agent.keyword` which is what the visualization uses.

Looking at each fields properties shows both as type string and searchable, and the .keyword field aggregatable.

Is there a char limit or something thats preventing the above string from being included in aggregate operations?

Thanks

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 14, 2023, 8:18pm UTC](https://discuss.elastic.co/t/field-value-not-found-in-aggregatable-field/323182/2 "2023-01-14T20:18:11Z")

</div>

Check the mapping for the field. It may be that only strings at 256 characters and below are indexed.

---

<div class="post-metadata">

**Author:** ![nnet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nnet/32/25982_2.png) [@nnet](https://discuss.elastic.co/u/nnet)\
**Post date:** [January 14, 2023, 8:40pm UTC](https://discuss.elastic.co/t/field-value-not-found-in-aggregatable-field/323182/3 "2023-01-14T20:40:16Z")

</div>

```auto
{ - 
  "nginx-2023.01.14": { - 
    "mappings": { - 
      "log": { - 
        "http_user_agent.keyword": { - 
          "full_name": "http_user_agent.keyword",
          "mapping": { - 
            "keyword": { - 
              "type": "keyword",
              "ignore_above": 256
            }
          }
        }
      }
    }
  }
}

```

Sure enough, thats the culprit.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2023, 8:40pm UTC](https://discuss.elastic.co/t/field-value-not-found-in-aggregatable-field/323182/4 "2023-02-11T20:40:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
