# Fielddata is disabled, but I have added a keyword field

**URL:** <https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353>\
**Category:** Elasticsearch\
**Created:** [March 5, 2020, 6:37pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353 "2020-03-05T18:37:31Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Terran](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@Terran](https://discuss.elastic.co/u/Terran)\
**Post date:** [March 5, 2020, 6:37pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/1 "2020-03-05T18:37:31Z")

</div>

I seem to be having an issue with mapping in my template. I have a field with data type "text", when I look into the Kibana SIEM console I receive the following error for several of my fields:  
[illegal\_argument\_exception] Fielddata is disabled on text fields by default. Set fielddata=true on [host.name] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead.

However when I look up one of these fields I see that I have a keyword field mapped to each "text" type  
"name": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256

Exactly where do I need to add the type:keyword to resolve this?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 6, 2020, 2:56am UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/2 "2020-03-06T02:56:25Z")

</div>

It should be:

```
"name": {
  "type": "keyword"
}
```

---

<div class="post-metadata">

**Author:** ![Terran](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@Terran](https://discuss.elastic.co/u/Terran)\
**Post date:** [March 6, 2020, 5:55pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/3 "2020-03-06T17:55:05Z")

</div>

I am attempting to update the mapping as you suggested, but it appears, my query is malformed, but I can't spot the error. Would you mind having a look?

PUT auditbeat-7.4.2-2020.03.06/\_mapping  
{  
"properties": {  
"host": {  
"properties": {  
"name": {  
"type": "keyword"  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 7, 2020, 1:43pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/4 "2020-03-07T13:43:55Z")

</div>

I don't know as I can't see the error message. Most likely you are trying to update an existing field, but that's just a guess.

---

<div class="post-metadata">

**Author:** ![Terran](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@Terran](https://discuss.elastic.co/u/Terran)\
**Post date:** [March 9, 2020, 11:59am UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/5 "2020-03-09T11:59:43Z")

</div>

Here is the error message:

"type": "illegal\_argument\_exception",  
"reason": "mapper [host.name] of different type, current\_type [text], merged\_type [keyword]"  
},  
"status": 400

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 9, 2020, 12:10pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/6 "2020-03-09T12:10:52Z")

</div>

So that's what I thought. You can not update an existing mapping and change the type of an existing field.

---

<div class="post-metadata">

**Author:** ![Terran](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@Terran](https://discuss.elastic.co/u/Terran)\
**Post date:** [March 9, 2020, 12:23pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/7 "2020-03-09T12:23:53Z")

</div>

So is there a way to resolve the error without setting fielddate=true? or do I need to create a new index with the desired mapping?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 9, 2020, 12:47pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/8 "2020-03-09T12:47:20Z")

</div>

You need to provide the right mapping and reindex your data accordingly.

Note that you should follow Elastic Common Schema as it's used by SIEM.

BTW what is the source of your data? Are you using a custom data source which is not supported out of the box by our beat agents?

---

<div class="post-metadata">

**Author:** ![Terran](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@Terran](https://discuss.elastic.co/u/Terran)\
**Post date:** [March 9, 2020, 1:24pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/9 "2020-03-09T13:24:17Z")

</div>

I am using Auditbeat with default mapping.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 9, 2020, 1:55pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/10 "2020-03-09T13:55:20Z")

</div>

Which version of Auditbeat?

I mean that when I'm using Auditbeat with all the default values, that I set up auditbeat as written in the documentation, it installs everything for me, including the right templates for auditbeat.

---

<div class="post-metadata">

**Author:** ![Terran](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@Terran](https://discuss.elastic.co/u/Terran)\
**Post date:** [March 9, 2020, 5:18pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/11 "2020-03-09T17:18:28Z")

</div>

Installed version 7.4.2. Installed on Redhat if that matters, pretty much run it straight out of the box. Was looking to see what came through so I could start figuring out what I wanted to see, what I didn't, that sort of thing.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 10, 2020, 8:31am UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/12 "2020-03-10T08:31:15Z")

</div>

Could you check if you have an index template named `auditbeat-SOMETHING`?

---

<div class="post-metadata">

**Author:** ![Terran](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@Terran](https://discuss.elastic.co/u/Terran)\
**Post date:** [March 10, 2020, 11:14am UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/13 "2020-03-10T11:14:51Z")

</div>

I thought I did, but upon checking, that isn't true.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 10, 2020, 12:19pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/14 "2020-03-10T12:19:01Z")

</div>

So you need to fix that.

---

<div class="post-metadata">

**Author:** ![Terran](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@Terran](https://discuss.elastic.co/u/Terran)\
**Post date:** [March 11, 2020, 4:41pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/15 "2020-03-11T16:41:39Z")

</div>

> [@Terran](#):
>
> {  
> "properties": {  
> "host": {  
> "properties": {  
> "name": {  
> "type": "keyword"  
> }  
> }  
> }  
> }  
> }

So I added the template and set the above to mappings, I reindexed everything, but I think I have an issue with getting the correct syntax to update the field host.name. Any thoughts?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 11, 2020, 5:13pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/16 "2020-03-11T17:13:48Z")

</div>

What is the problem? Sorry I don't understand what is the current status.

---

<div class="post-metadata">

**Author:** ![Terran](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@Terran](https://discuss.elastic.co/u/Terran)\
**Post date:** [March 13, 2020, 11:42am UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/17 "2020-03-13T11:42:26Z")

</div>

I am still seeing the same error, I have added the template for audit\*. I have added the following in Mappings

```
{
  "properties": {
    "host": {
      "properties": {
        "name": {
          "type": "keyword"
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 13, 2020, 12:58pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/18 "2020-03-13T12:58:26Z")

</div>

What is the output of:

```auto
GET auditbeat-7.4.2-2020.03.06/_mapping

```

May be you need to change the date though.

---

<div class="post-metadata">

**Author:** ![Terran](https://avatars.discourse-cdn.com/v4/letter/t/94ad74/32.png) [@Terran](https://discuss.elastic.co/u/Terran)\
**Post date:** [March 13, 2020, 2:23pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/19 "2020-03-13T14:23:10Z")

</div>

Mappings here:  
[https://docs.google.com/document/d/1b1-zFB0JAUX5s0N6tpjnArryMyiCIac2nXuUN90H5qI/edit?usp=sharing](https://docs.google.com/document/d/1b1-zFB0JAUX5s0N6tpjnArryMyiCIac2nXuUN90H5qI/edit?usp=sharing)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 16, 2020, 2:17pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353/20 "2020-03-16T14:17:46Z")

</div>

I don't have access to this document as it's not public. Could you share it on [gist.github.com](http://gist.github.com) instead?

[Next page](https://discuss.elastic.co/t/fielddata-is-disabled-but-i-have-added-a-keyword-field/222353.md?page=2)
