# Fields are not visible in machine learning job

**URL:** <https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-machine-learning\
**Created:** [December 17, 2018, 6:48am UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079 "2018-12-17T06:48:27Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)\
**Post date:** [December 17, 2018, 6:48am UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/1 "2018-12-17T06:48:27Z")

</div>

Hi All,

I am new to Machine learning jobs in kibana.

I've tried to create a single metric job using my data available in elasticsearch.  
But my field are not visible in filters Aggregation.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/8/388d2265b6d5d138464939b0440b324c369ac672.png)

Except for the aggregation type distinct\_count .

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/e/aebe029eef4e30d1c6c8423ce1f1b813b1378c7f.png)

By using "distinct\_count" am unable to do any prediction. Please help me.  
The fields am trying to use for the prediction is in NUMBER type.

Appreciate your response.

---

<div class="post-metadata">

**Author:** ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)\
**Post date:** [December 17, 2018, 10:08am UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/2 "2018-12-17T10:08:57Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/1/e1008c2b8e30f15ec14de55eb20a2810891d9442.png)

---

<div class="post-metadata">

**Author:** ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)\
**Post date:** [December 17, 2018, 10:10am UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/3 "2018-12-17T10:10:24Z")

</div>

I'm using ELK 6.4.2  
I tried to remove and install x-pack also.  
But no luck anybody please help me. I'm doing anything wrong?

---

<div class="post-metadata">

**Author:** ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)\
**Post date:** [December 17, 2018, 11:51am UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/4 "2018-12-17T11:51:47Z")

</div>

Any response would appreciated.

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [December 17, 2018, 5:02pm UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/5 "2018-12-17T17:02:35Z")

</div>

Hmm...I don't seem to have a problem with selecting `distinct_count` for a field that is numerical:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/d/fdf875b7eb5d84a238dbad3ffcd8e61ae90993da.png)

And here's the mapping of that field:

```auto
          "responsetime" : {
            "type" : "float"
          }

```

What is the name of the field you're interested in and what is its mapping?

---

<div class="post-metadata">

**Author:** ![Peter\_Harverson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_harverson/32/21057_2.png) [@Peter\_Harverson](https://discuss.elastic.co/u/Peter_Harverson)\
**Post date:** [December 17, 2018, 5:09pm UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/6 "2018-12-17T17:09:16Z")

</div>

@Sripal could you also check that the `number` type fields you want to use in your Single Metric job are listed in the Kibana Index Patterns tab, when filtering for `number` (switch to the Kibana Management tab, then Index Patterns, select the index pattern you are using in your job, and then filter for `number`) .

For example, in this index pattern, there are no aggregatable number type fields available for use in an ML job:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/0/c0cf3b892be718dfca94eb919a46de22279ee4ff.png)

Thanks  
Pete

---

<div class="post-metadata">

**Author:** ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)\
**Post date:** [December 18, 2018, 5:03am UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/7 "2018-12-18T05:03:32Z")

</div>

Thankyou for the response @Peter_harverson & @richcollier.

Please review my index pattern screenshot all fields treated as string.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/b/6b9293e25acfdd0f23042c4ae01fb8fc4f0b104e.png)

my config file

filter {  
grok {  
match =\> {  
"message" =\> '%{NOTSPACE:clientip}:- %{NOTSPACE:user} %{NOTSPACE:pass} %{NOTSPACE:role} [%{HTTPDATE:timestamp}] "%{WORD:method} %{DATA:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:responsecode} %{NUMBER:response} %{NOTSPACE:id1} %{NOTSPACE:id2} %{NOTSPACE:id3} %{NOTSPACE:id4} %{NOTSPACE:id5}'  
}  
}

}

Please let me know my mistake .

---

<div class="post-metadata">

**Author:** ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)\
**Post date:** [December 18, 2018, 5:06am UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/8 "2018-12-18T05:06:37Z")

</div>

@Peter_Harverson I filtered my index pattern with NUMBER please find the below screenshot

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/1/015097999127b764f927257567e412fffeeed0fc.png)

---

<div class="post-metadata">

**Author:** ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)\
**Post date:** [December 18, 2018, 5:34am UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/9 "2018-12-18T05:34:01Z")

</div>

can anybody help me how to typecast the field from string to integer.

---

<div class="post-metadata">

**Author:** ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)\
**Post date:** [December 18, 2018, 5:38am UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/10 "2018-12-18T05:38:32Z")

</div>

I've tried the below

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5ea87fffdefd9076ad1e796614382d501e385efb.png)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [December 18, 2018, 2:16pm UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/11 "2018-12-18T14:16:48Z")

</div>

Hello - it seems as if your mappings are a bit of a mess. You should not have everything be type `string`. Time stamps should be type `date` and if you have fields named `xxxxx.keyword` then those fields should be of type `keyword`.

Looks like you need to re-index your data with proper mappings. A great blog with good info: [https://www.elastic.co/blog/a-practical-introduction-to-logstash](https://www.elastic.co/blog/a-practical-introduction-to-logstash)

---

<div class="post-metadata">

**Author:** ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)\
**Post date:** [December 19, 2018, 7:07am UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/12 "2018-12-19T07:07:09Z")

</div>

@richcollier Thanks much. I didn't mutate my fields. Now i can able to see the numeric type fields.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/0/d0f9d8a8b110bd795909ed22f3cdeb632b16b32b.png)

But i'm unable to do forecast my job.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/4/44543f9815030cca2559ab5a2722aec122b807e0.png)

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [December 19, 2018, 2:19pm UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/13 "2018-12-19T14:19:47Z")

</div>

I think this problem is related to the other problem you're having as described here: [Datafeed not happening in ml job](https://discuss.elastic.co/t/datafeed-not-happening-in-ml-job/161483)

---

<div class="post-metadata">

**Author:** ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)\
**Post date:** [December 20, 2018, 8:57am UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/14 "2018-12-20T08:57:02Z")

</div>

@richcollier Thanks for the response.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2019, 9:04am UTC](https://discuss.elastic.co/t/fields-are-not-visible-in-machine-learning-job/161079/15 "2019-01-17T09:04:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
