# Fields in Kibana 5 are non-searchable and non-aggregatable

**URL:** <https://discuss.elastic.co/t/fields-in-kibana-5-are-non-searchable-and-non-aggregatable/70565>\
**Category:** Kibana\
**Created:** [January 4, 2017, 2:30pm UTC](https://discuss.elastic.co/t/fields-in-kibana-5-are-non-searchable-and-non-aggregatable/70565 "2017-01-04T14:30:25Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Post date:** [January 4, 2017, 2:30pm UTC](https://discuss.elastic.co/t/fields-in-kibana-5-are-non-searchable-and-non-aggregatable/70565/1 "2017-01-04T14:30:25Z")

</div>

**Topbeat 1.3**  
**elasticsearch 5.1**  
**kibana 5.1**  
**Red Hat Enterprise Linux Server**  
**Version : 7.2 (Maipo)**

Installing Topbeat  
curl -L -O [https://download.elastic.co/beats/topbeat/topbeat-1.3.1-x86\_64.rpm](https://download.elastic.co/beats/topbeat/topbeat-1.3.1-x86_64.rpm)  
sudo rpm -vi topbeat-1.3.1-x86\_64.rpm

Loading the Index Template In Elasticsearch  
curl -XPUT '[http://IP:9200/\_template/topbeat](http://IP:9200/_template/topbeat)' -d@/etc/topbeat/topbeat.template.json

I have not started Topbeat on linux

I have configured **topbeat 1.2 topbeat.yml to point to linux server**  
topbeat 1.2 is installed on windows 7 machine.

Now the issue begins================  
When I configure the index pattern topbeat-\* on kibana 5.1 there are some fields which are both non-searchable and non-aggregatable.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/f/fa7e3834282e9eaaf8f5159197cce1370e12ca85.png) ![](https://us1.discourse-cdn.com/elastic/original/2X/0/076e31b89c85646df55d0fa31fb12828e44e9701.png)

As you can see these fields are both non-searchable and non-aggregatable.  
I am not able to create charts on these fields as they do not appear  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1f70e235063974f4e217314699c936ff0cc1753d.png)

**_How to make them searchable and aggregatable_ ??**

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [January 4, 2017, 4:52pm UTC](https://discuss.elastic.co/t/fields-in-kibana-5-are-non-searchable-and-non-aggregatable/70565/2 "2017-01-04T16:52:23Z")

</div>

> [@aviral\_srivastava](#):
>
> I have configured topbeat 1.2 topbeat.yml to point to linux server

Do you mean that Elasticsearch is running on your linux server, and that you are pointing the topbeat instance on your windows machine to it?

> [@aviral\_srivastava](#):
>
> I have not started Topbeat on linux

Are you using Logstash to index the data from topbeat, or did you configure it to dump directly into Elasticsearch?

If you are dumping directly into elasticsearch, I don't think that you need to manually load the index template.

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [January 4, 2017, 5:30pm UTC](https://discuss.elastic.co/t/fields-in-kibana-5-are-non-searchable-and-non-aggregatable/70565/3 "2017-01-04T17:30:25Z")

</div>

This looks like it might be related to [Saved "field" parameter is now invalid. Please select a new field. .... Visualize: "field" is a required parameter](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field-visualize-field-is-a-required-parameter/70034)

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [January 4, 2017, 7:21pm UTC](https://discuss.elastic.co/t/fields-in-kibana-5-are-non-searchable-and-non-aggregatable/70565/4 "2017-01-04T19:21:19Z")

</div>

Related to my earlier question. Are you sure that there are actual documents indexed with data for these fields?

---

<div class="post-metadata">

**Author:** ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Post date:** [January 5, 2017, 8:06am UTC](https://discuss.elastic.co/t/fields-in-kibana-5-are-non-searchable-and-non-aggregatable/70565/5 "2017-01-05T08:06:57Z")

</div>

@BigFunger

**Do you mean that Elasticsearch is running on your linux server, and that you are pointing the topbeat instance on your windows machine to it?**  
Yes, elasticsearch 5.1 is running on my linux server and topbeat1.2 instance on my windows machine is pointing to elasticsearch 5.1 on linux machine.

**Are you using Logstash to index the data from topbeat, or did you configure it to dump directly into Elasticsearch?**  
No, I am not using logstash to index the data from topbeat, I configured it to dump directly into elasticsearch 5.1 on linux machine

**If you are dumping directly into elasticsearch, I don't think that you need to manually load the index template.**  
If you don't manually load the index template, how would you ensure the datatypes?

**Related to my earlier question. Are you sure that there are actual documents indexed with data for these fields?**  
Yes

@Stacey_Gammon  
Thanks, I tried your link and it worked.  
I read the documentation and it says like that

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/ed93990b6b29a8bbb58cda7a3d59cc72d24bf3dc.png)  
Going by the documentation,  
**You can reload the index fields list to pick up any newly-added fields.**  
I manually loaded the index template for topbeat-\* index.  
I found that in topbeat.template.json all the fields which were non-searchable and non-aggregatable were present in it. So, these fields were not newly-added, they were already present.

So, what happended when I pressed the Reload button, that made kibana to recognise these fields as searchable and aggregatable??

---

<div class="post-metadata">

**Author:** ![Stacey\_Gammon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stacey_gammon/32/14025_2.png) [@Stacey\_Gammon](https://discuss.elastic.co/u/Stacey_Gammon)\
**Post date:** [January 5, 2017, 2:30pm UTC](https://discuss.elastic.co/t/fields-in-kibana-5-are-non-searchable-and-non-aggregatable/70565/6 "2017-01-05T14:30:43Z")

</div>

Awesome, glad it worked!

The reload button goes back to the field\_stats api to retrieve information about the fields such as searchacble, aggregateble, etc. The field\_stats api doesn't return any information for fields that don't have any data indexed for them, so if Kibana generated the field list while there was no data for that field, it will display the information incorrectly.

You can read more about this issue at these related tickets:

> <https://github.com/elastic/elasticsearch/issues/22438>

  

> <https://github.com/elastic/kibana/issues/9466>

---

<div class="post-metadata">

**Author:** ![aviral\_srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviral_srivastava/32/98018_2.png) [@aviral\_srivastava](https://discuss.elastic.co/u/aviral_srivastava)\
**Post date:** [January 13, 2017, 6:36am UTC](https://discuss.elastic.co/t/fields-in-kibana-5-are-non-searchable-and-non-aggregatable/70565/7 "2017-01-13T06:36:55Z")

</div>

Thanks, @Stacey_Gammon.  
For the reply.

Will look into it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 10, 2017, 6:37am UTC](https://discuss.elastic.co/t/fields-in-kibana-5-are-non-searchable-and-non-aggregatable/70565/8 "2017-02-10T06:37:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
