# Fielddata is disabled

**URL:** <https://discuss.elastic.co/t/fielddata-is-disabled/206816>\
**Category:** SIEM\
**Created:** [November 6, 2019, 3:14pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled/206816 "2019-11-06T15:14:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Manoel](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@Manoel](https://discuss.elastic.co/u/Manoel)\
**Post date:** [November 6, 2019, 3:14pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled/206816/1 "2019-11-06T15:14:31Z")

</div>

Hello.

I upgraded from Elastic Stack version 6.8 to 7.4. I installed AudioBeat on all my servers, with the configuration below.

```
auditbeat.modules:

- module: auditd
  audit_rule_files: ['${path.config}/audit.rules.d/*.conf']
  audit_rules: |
- module: file_integrity
  paths:
  - /bin
  - /usr/bin
  - /sbin
  - /usr/sbin
  - /etc
  - /opt

- module: system
  datasets:
    - host # General host information, e.g. uptime, IPs
    - login # User logins, logouts, and system boots.
    - package # Installed, updated, and removed packages
    - process # Started and stopped processes
    - socket # Opened and closed sockets
    - user # User information

  user.detect_password_changes: true

  login.wtmp_file_pattern: /var/log/wtmp*
  login.btmp_file_pattern: /var/log/btmp*

setup.template.settings:
  index.number_of_shards: 1

setup.kibana:

  host: "http://yspp0051.ymdb.com.br:80"

output.elasticsearch:
  hosts: ["yspp0053.ymdb.com.br:9200"]

processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~

```

I set up SIEM on Elastic Stack and everything was normal until yesterday. Today is presenting the following error:

 ![uncommon_process](https://us1.discourse-cdn.com/elastic/original/3X/b/a/ba895fbe362f9d9929db38d7a5d9f2a92e167a6a.png)  
 ![process](https://us1.discourse-cdn.com/elastic/original/3X/4/d/4dbc7df6f0cdd3a03d677af332382a7b2f6d45d0.png)

My mapping is:

[https://justpaste.it/3hl4g](https://justpaste.it/3hl4g)

Can you help me solve? I'm new to Elastic Stack and I don't know much.

---

<div class="post-metadata">

**Author:** ![Manoel](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@Manoel](https://discuss.elastic.co/u/Manoel)\
**Post date:** [November 7, 2019, 11:54am UTC](https://discuss.elastic.co/t/fielddata-is-disabled/206816/2 "2019-11-07T11:54:29Z")

</div>

Can someone help me?

Thanks

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [November 7, 2019, 3:10pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled/206816/3 "2019-11-07T15:10:12Z")

</div>

Hi @Manoel, did you run `./auditbeat setup` before running Auditbeat? This sets up the index with the proper data types. The error looks like it does not have the right ones.

---

<div class="post-metadata">

**Author:** ![Manoel](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@Manoel](https://discuss.elastic.co/u/Manoel)\
**Post date:** [November 7, 2019, 5:22pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled/206816/4 "2019-11-07T17:22:38Z")

</div>

Hello @cwurm, thanks for the support.

I scripted Ansible to automate the installation of AuditBeat on my 150 Linux servers. In the process I have the command: sudo auditbeat setup

In the log I can know which server is sending the wrong information?

---

<div class="post-metadata">

**Author:** ![fredrcc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fredrcc/32/58166_2.png) [@fredrcc](https://discuss.elastic.co/u/fredrcc)\
**Post date:** [November 22, 2019, 2:44pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled/206816/5 "2019-11-22T14:44:13Z")

</div>

Hi Manoel did you find out what was the problem? I'm having the same issue with Filebeat and ES 7.4.2

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [November 25, 2019, 11:52am UTC](https://discuss.elastic.co/t/fielddata-is-disabled/206816/6 "2019-11-25T11:52:12Z")

</div>

@Manoel `./auditbeat setup` should be run only once, not more.

@Manoel, @fredrcc In general, you should run `./auditbeat setup` once from an admin machine, then only run `./auditbeat` on the monitored machines. You can test it works by running both against an empty Elasticsearch cluster. If it doesn't work in your environment, there must be some difference - e.g. you're not using the default index pattern, the setup command failed - or something else.

---

<div class="post-metadata">

**Author:** ![fredrcc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fredrcc/32/58166_2.png) [@fredrcc](https://discuss.elastic.co/u/fredrcc)\
**Post date:** [November 28, 2019, 5:51pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled/206816/7 "2019-11-28T17:51:20Z")

</div>

I've run filebeat setup from the logstash server, because it's the only server with access to the ES and Kibana. Then I start filebeat from a client to send logs to my logstash.

I've tried to remove the filebeat index, index templates and dashboards and re-run filebeat setup again, but it didn't work too. There's any configuration else to remove to start a fresh filebeat setup on a production ES?

Regards.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2019, 5:51pm UTC](https://discuss.elastic.co/t/fielddata-is-disabled/206816/8 "2019-12-26T17:51:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
