# Fielddata is disabled on \[host.name\] in \[metricbeat-8.10.3\]

**URL:** <https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261>\
**Category:** Kibana\
**Created:** [November 29, 2023, 5:21pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261 "2023-11-29T17:21:56Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![efrainMZ](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Post date:** [November 29, 2023, 5:21pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261/1 "2023-11-29T17:21:56Z")

</div>

Hello good morning!

I am ingesting data from metricbeat to elasticsearch and loading the dashboards of version metricbeat 8.10.3 with the command "./metricbeat setup --dashboard" but when viewing the dashboards it shows a warning:

```auto
Shard
0
Index
metricbeat-8.10.3-2023.11.29
Type
illegal_argument_exception
Node
TzlnKYr2SluYz1O-f9M8lg
Reason
Fielddata is disabled on [host.name] in [metricbeat-8.10.3-2023.11.29]. Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [host.name] in order to load field data by uninverting the inverted index. Note that this can use significant memory.

```

But when I see my template the value "host.name" is keyword, I loaded the template with the command "./metricbeat setup --index-management"

aid please

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 29, 2023, 6:40pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261/2 "2023-11-29T18:40:37Z")

</div>

Hi @efrainMZ

Delete the index ... `metricbeat-8.10.3-2023.11.29`

then run

`./metricbeat setup -e`

Pro-Tip : Always run `./metricbeat setup -e` not `--dashboards` or `--index-management` etc.... just run without the parameters so all assets get loaded.

Then start metricbeat again.

---

<div class="post-metadata">

**Author:** ![efrainMZ](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Post date:** [November 29, 2023, 8:45pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261/3 "2023-11-29T20:45:16Z")

</div>

Hi Stephenb!

I performed the steps you suggested but I receive the same error when entering the dashboard again:

```auto
Shard
0
Index
metricbeat-8.10.3-2023.11.29
Type
illegal_argument_exception
Node
L9pncMC4QeSlR85fKLS9eQ
Reason
Fielddata is disabled on [host.name] in [metricbeat-8.10.3-2023.11.29]. Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [host.name] in order to load field data by uninverting the inverted index. Note that this can use significant memory.

```

Delete the index and then run the command "./metricbeat setup -e", do you have any other reason?

The version of my metricbeat is 8.10.3

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 29, 2023, 9:02pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261/4 "2023-11-29T21:02:00Z")

</div>

When I see this... there is something else writing to that index before you run `setup`

did you stop ALL the metricbeats?

Also you can check in Kibana Dev Tools

`GET metricbeat-8.10.3-2023.11.29/_mapping/field/host.name`

Should look something like

```auto
{
  "metricbeat-8.10.3-2023.11.29": {
    "mappings": {
      "host.name": {
        "full_name": "host.name",
        "mapping": {
          "name": {
            "type": "keyword",
            "ignore_above": 1024
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![efrainMZ](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Post date:** [November 30, 2023, 5:47pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261/5 "2023-11-30T17:47:08Z")

</div>

If I stopped all metricbeat and run the command "./metricbeat setup -e".  
Use dev tools as requested to perform the query and this is the result:

```auto
{
  "metricbeat-8.10.3-2023.11.30": {
    "mappings": {
      "host.name": {
        "full_name": "host.name",
        "mapping": {
          "name": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
        }
      }
    }
  }
}

```

Something strange that I saw is that when creating the template I could see that it has two hostname attributes but named differently, I attach an image

 ![CONFIG-APM](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fbd96e6de77533a0b039a079918dffc89c2e6b41.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 30, 2023, 6:16pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261/6 "2023-11-30T18:16:41Z")

</div>

> [@efrainMZ](#):
>
> Something strange that I saw is that when creating the template I could see that it has two hostname attributes but named differently, I attach an image

That has been around for a long time... that is normal.

> [@efrainMZ](#):
>
> ```auto
> {
> "metricbeat-8.10.3-2023.11.30": {
> "mappings": {
> "host.name": {
> "full_name": "host.name",
> "mapping": {
> "name": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> 
> ```

I am not sure why you are seeing that

Go to the next step 4 and see the mappings for those fields in the template...

You are somehow still getting a default mapping...

---

<div class="post-metadata">

**Author:** ![efrainMZ](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Post date:** [November 30, 2023, 9:04pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261/7 "2023-11-30T21:04:43Z")

</div>

I don't know why it loads the template like this. I show you the mapping in step 4, I attach the image

 ![STEP-4](https://us1.discourse-cdn.com/elastic/original/3X/b/e/bed0b5fda8ac3fce8123aa8e87c3bc5d48ac90c2.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 30, 2023, 10:00pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261/8 "2023-11-30T22:00:59Z")

</div>

That picture looks correct in the template... Not sure why your templates not being applied

It is saying both these are `keyword`

```auto
host.name
host.hostname

```

Which is correct.

I would delete the templates, delete the indices, delete everything and try setup one more time.  
There's something fundamental going on..

---

<div class="post-metadata">

**Author:** ![efrainMZ](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@efrainMZ](https://discuss.elastic.co/u/efrainMZ)\
**Post date:** [December 12, 2023, 9:03pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261/9 "2023-12-12T21:03:10Z")

</div>

Returns the fields "host.name" and "host.hostname" as keyword, I did not modify that part. I have tried to eliminate indexes and templates but it has not worked. ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2024, 9:03pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled-on-host-name-in-metricbeat-8-10-3/348261/10 "2024-01-09T21:03:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
