# Fields in Table Do Not Match Fields in JSON

**URL:** <https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174>\
**Category:** Kibana\
**Created:** [July 5, 2019, 10:03pm UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174 "2019-07-05T22:03:41Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![ddodge](https://avatars.discourse-cdn.com/v4/letter/d/a3d4f5/32.png) [@ddodge](https://discuss.elastic.co/u/ddodge)\
**Post date:** [July 5, 2019, 10:03pm UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/1 "2019-07-05T22:03:42Z")

</div>

Under the Discover tab in Kibana I can see entries in the Table listing that say "No cached mapping for this field. Refresh field list from the Management \> Index Patters page"

Conversely in Discover, I can see fields in the JSON that do not show up in the Table view.

I've clicked Management \> Index Patterns then I go to my index "logstash-beats-\*" and click refresh (multiple times). This does not help. In the management view, it recognizes the JSON fields (which are the ones I want). For some reason Discover (and in my Dashboards) do not show the correct JSON fields.

Is there something that I'm missing?

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [July 25, 2019, 3:58pm UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/2 "2019-07-25T15:58:16Z")

</div>

Hi and welcome to our community! We tried to reproduce your issue, so far we were not successful. When you refresh the index pattern, the warning you've mentioned, is still there right?

Which version of kibana are you using? Could you provide us a sample of your data and an export of the index mapping? That would be great.

When you select your index pattern in management, the id of your pattern is part of the URL, e.g.

[http://localhost:5601/oan/app/kibana#/management/kibana/index\_patterns/](http://localhost:5601/oan/app/kibana#/management/kibana/index_patterns/) **ff959d40-b880-11e8-a6d9-e546fe2bba5** f?\_g=()&\_a=(tab:indexedFields)

With this id you can export the pattern in **Console** of **Dev Tools** by:

`GET .kibana/_doc/index-pattern:ff959d40-b880-11e8-a6d9-e546fe2bba5`

This would be a great help to solve this problem, thank you very much

---

<div class="post-metadata">

**Author:** ![ddodge](https://avatars.discourse-cdn.com/v4/letter/d/a3d4f5/32.png) [@ddodge](https://discuss.elastic.co/u/ddodge)\
**Post date:** [July 28, 2019, 3:42am UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/3 "2019-07-28T03:42:08Z")

</div>

Sure thing, I'm using Kibana 6.7.2. I've attached a screenshot of the pattern. It's pretty long. Let me know if you need to see more. Thank you!

 ![Screenshot](https://us1.discourse-cdn.com/elastic/original/3X/d/1/d13ce751d7ef910fae1eda9cbf6bcdc49642d24d.png)

---

<div class="post-metadata">

**Author:** ![ddodge](https://avatars.discourse-cdn.com/v4/letter/d/a3d4f5/32.png) [@ddodge](https://discuss.elastic.co/u/ddodge)\
**Post date:** [July 28, 2019, 4:01am UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/4 "2019-07-28T04:01:32Z")

</div>

Sorry, I forgot to mention that yes, the warning is still there when I refresh.

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [July 29, 2019, 5:08pm UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/5 "2019-07-29T17:08:03Z")

</div>

Thanks, could you paste the textual output here, and maybe 1-2 datasets you're using? thx a lot!

---

<div class="post-metadata">

**Author:** ![ddodge](https://avatars.discourse-cdn.com/v4/letter/d/a3d4f5/32.png) [@ddodge](https://discuss.elastic.co/u/ddodge)\
**Post date:** [August 1, 2019, 9:20pm UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/6 "2019-08-01T21:20:23Z")

</div>

{  
"\_index" : ".kibana\_1",  
"\_type" : "\_doc",  
"\_id" : "index-pattern:AWBLHZaBRuBloj96jvrD",  
"\_version" : 15,  
"\_seq\_no" : 2532,  
"\_primary\_term" : 12,  
"found" : true,  
"\_source" : {  
"index-pattern" : {  
"title" : "_:logstash-beats-_",  
"timeFieldName" : "@timestamp",  
"notExpandable" : true,  
"fields" : """[{"name":"@timestamp","type":"date","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"@version","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"\_id","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":false},{"name":"\_index","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":false},{"name":"\_score","type":"number","count":0,"scripted":false,"searchable":false,"aggregatable":false,"readFromDocValues":false},{"name":"\_source","type":"\_source","count":0,"scripted":false,"searchable":false,"aggregatable":false,"readFromDocValues":false},{"name":"\_type","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":false},{"name":"aa","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":false,"readFromDocValues":false},{"name":"aa.keyword","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"ack","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":false,"readFromDocValues":false},{"name":"ack.keyword","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"action","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":false,"readFromDocValues":false},{"name":"action.keyword","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"activity\_id","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"additional\_info","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":false,"readFromDocValues":false},{"name":"additional\_info.keyword","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"age","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":false,"readFromDocValues":false},{"name":"age.keyword","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"alert","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":false,"readFromDocValues":false},{"name":"alert.keyword","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"alert\_level","type":"number","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"alert\_level.keyword","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"analyzer","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":false,"readFromDocValues":false},{"name":"analyzer.keyword","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"answers","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":false,"readFromDocValues":false},{"name":"answers.keyword","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"apache2.access.agent","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":false,"readFromDocValues":false},{"name":"apache2.access.body\_sent.bytes","type":"number","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"apache2.access.geoip.city\_name","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"apache2.access.geoip.continent\_name","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"apache2.access.geoip.country\_iso\_code","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"apache2.access.geoip.location","type":"geo\_point","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"apache2.access.geoip.region\_name","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},

---

<div class="post-metadata">

**Author:** ![ddodge](https://avatars.discourse-cdn.com/v4/letter/d/a3d4f5/32.png) [@ddodge](https://discuss.elastic.co/u/ddodge)\
**Post date:** [August 1, 2019, 9:37pm UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/7 "2019-08-01T21:37:07Z")

</div>

Here is what shows in the JSON tab for a windows log (with some data masking). Notice that the event\_id field, for example, shows up in the JSON file.

"winlog": {  
"api": "wineventlog",  
"event\_data": {  
"SubjectLogonId": "0x3e7",  
"SubjectUserSid": "S-1-5-18",  
"PrivilegeList": "SeAssignPrimaryTokenPrivilege\n\t\t\tSeTcbPrivilege\n\t\t\tSeSecurityPrivilege\n\t\t\tSeTakeOwnershipPrivilege\n\t\t\tSeLoadDriverPrivilege\n\t\t\tSeBackupPrivilege\n\t\t\tSeRestorePrivilege\n\t\t\tSeDebugPrivilege\n\t\t\tSeAuditPrivilege\n\t\t\tSeSystemEnvironmentPrivilege\n\t\t\tSeImpersonatePrivilege\n\t\t\tSeDelegateSessionUserImpersonatePrivilege",  
"SubjectDomainName": "NT AUTHORITY",  
"SubjectUserName": "SYSTEM"  
},  
"activity\_id": "{E65959B9-40BA-0000-F959-59E6BA40D501}",  
"task": "Special Logon",  
"provider\_name": "Microsoft-Windows-Security-Auditing",  
"channel": "Security",  
**"event\_id": 4672,**  
"computer\_name": "/DATA MASKED/",  
"provider\_guid": "{54849625-5478-4994-A5BA-3E3B0328C30D}",  
"record\_id": 159180,  
"process": {  
"thread": {  
"id": 824  
},  
"pid": 776  
},  
"keywords": [  
"Audit Success"  
],  
"opcode": "Info"  
},

---

<div class="post-metadata">

**Author:** ![ddodge](https://avatars.discourse-cdn.com/v4/letter/d/a3d4f5/32.png) [@ddodge](https://discuss.elastic.co/u/ddodge)\
**Post date:** [August 1, 2019, 9:40pm UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/8 "2019-08-01T21:40:32Z")

</div>

Now notice that the field _ **event\_id** _ doesn't show up in the Table view. It shows up as _ **event.code** _ which is not compatible with any of my dashboards. This is one example. The same thing applies for _ **computer\_name** _, _ **process\_id** _, _ **user.name** _, etc.

 ![Table%20View](https://us1.discourse-cdn.com/elastic/original/3X/2/1/2198bd66ac2cb8e003ae1fe0fa158babe3d176f9.png)

---

<div class="post-metadata">

**Author:** ![ddodge](https://avatars.discourse-cdn.com/v4/letter/d/a3d4f5/32.png) [@ddodge](https://discuss.elastic.co/u/ddodge)\
**Post date:** [August 1, 2019, 9:45pm UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/9 "2019-08-01T21:45:16Z")

</div>

Console view for the event\_id field:

......  
**{"name":"event\_id","type":"number","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},** {"name":"event\_timestamp","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":false,"readFromDocValues":false},{"name":"event\_timestamp.keyword","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true},{"name":"event\_type","type":"string","count":0,"scripted":false,"searchable":true,"aggregatable":false,"readFromDocValues":false},  
........

event.code field in console view is not found.

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [August 2, 2019, 4:57pm UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/10 "2019-08-02T16:57:45Z")

</div>

thanks a lot, I will try to reproduce your problem

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [August 9, 2019, 9:07am UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/11 "2019-08-09T09:07:56Z")

</div>

There's an odd thing about your index pattern, according to your screenshot, it's `*:logstash-beats-*`. How was this index pattern created? Was it migrated? Could you try adding another index pattern named `logstash-beats-*`? I can't manually create an index pattern with such a name.

thx a lot!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 9, 2019, 11:38am UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/12 "2019-08-09T11:38:49Z")

</div>

Isn’t that the index pattern format when using cross-cluster search?

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [August 9, 2019, 12:20pm UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/13 "2019-08-09T12:20:48Z")

</div>

@Christian_Dahlqvist yes, you're right. thank you very much, I wasn't aware of this

[https://www.elastic.co/guide/en/kibana/current/management-cross-cluster-search.html](https://www.elastic.co/guide/en/kibana/current/management-cross-cluster-search.html)

So maybe there's an issue with refreshing indices for cross cluster searches ? I'll continue investigating in this direction

---

<div class="post-metadata">

**Author:** ![matw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matw/32/13913_2.png) [@matw](https://discuss.elastic.co/u/matw)\
**Post date:** [August 27, 2019, 4:22pm UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/14 "2019-08-27T16:22:12Z")

</div>

Sorry for the long time since my last answer. So I couldn't reproduce it, but I have an idea what might cause the problem. It would be interesting what's the origin of the data. If e.g. beats were upgraded, your indices could now indices use different mappings.

So maybe the source of your ingested data are different beat versions? Could you provide some details about this? Furthermore it would be interesting, since you're using cross cluster search, how many clusters du you have?

thx!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 24, 2019, 4:26pm UTC](https://discuss.elastic.co/t/fields-in-table-do-not-match-fields-in-json/189174/15 "2019-09-24T16:26:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
