# Fields not coming in discover

**URL:** <https://discuss.elastic.co/t/fields-not-coming-in-discover/301181>\
**Category:** Kibana\
**Created:** [March 31, 2022, 10:27am UTC](https://discuss.elastic.co/t/fields-not-coming-in-discover/301181 "2022-03-31T10:27:40Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shubham\_Singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_singh/32/96820_2.png) [@Shubham\_Singh](https://discuss.elastic.co/u/Shubham_Singh)\
**Post date:** [March 31, 2022, 10:27am UTC](https://discuss.elastic.co/t/fields-not-coming-in-discover/301181/1 "2022-03-31T10:27:40Z")

</div>

I have a stack\_trace field in log file but in kibana it turn out to be in hidden field with no value. Rest other fields are coming as expected. I can see the field in vizualization but not in discover . The field type is `keyword` for strack\_trace field

{"@timestamp":"2022-03-31T09:39:59.185+00:00","@version":1,"message":"Exception:","logger\_name":"com.nethum.errorhandling.exception.handler.RestResponseEntityExceptionHandler","thread\_name":"http-nio-10020-exec-1","level":"ERROR","level\_value":40000,"stack\_trace":"java.lang.NullPointerException: null\n\tat com.engati.livechat.v2.controller.DevOpsController.test(DevOpsController.java:21)\n\tat sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)\n\tat sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)\n\tat sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)\n\tat java.lang.reflect.Method.invoke(Method.java:498)\n\tat org.springframework.web.method.support.InvocableHandlerMethod.doInvoke(InvocableHandlerMethod.java:209)\n\tat org.springframework.web.method.support.InvocableHandlerMethod.invokeForRequest(InvocableHandlerMethod.java:136)\n\tat org.springframework.web.servlet.mvc.method.annotation.ServletInvocableHandlerMethod.invokeAndHandle(ServletInvocableHandlerMethod.java:102)\n\tat org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerAdapter.invokeHandlerMethod(RequestMappingHandlerAdapter.java:891)\n\tat org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerAdapter.handleInternal(RequestMappingHandlerAdapter.java:797)\n\tat org.springframework.web.servlet.mvc.method.AbstractHandlerMethodAdapter.handle(AbstractHandlerMethodAdapter.java:87)\n\tat org.springframework.web.servlet.DispatcherServlet.doDispatch(DispatcherServlet.java:991)\n\tat org.springframework.web.servlet.DispatcherServlet.doService(DispatcherServlet.java:925)\n\tat org.springframework.web.servlet.FrameworkServlet.processRequest(FrameworkServlet.java:974)\n\tat org.springframework.web.servlet.FrameworkServlet.doGet(FrameworkServlet.java:866)\n\tat javax.servlet.http.HttpServlet.service(HttpServlet.java:635)\n\tat org.springframework.web.servlet.FrameworkServlet.service(FrameworkServlet.java:851)\n\tat javax.servlet.http.HttpServlet.service(HttpServlet.java:742)\n\tat org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:231)\n\tat org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\n\tat org.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:52)\n\tat org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)\n\tat org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\n\tat org.springframework.boot.actuate.web.trace.servlet.HttpTraceFilter.doFilterInternal(HttpTraceFilter.java:90)\n\tat org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)\n\tat org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)\n\tat org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\n\tat org.springframework.web.filter.RequestContextFilter.doFilterInternal(RequestContextFilter.java:99)\n\tat org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)\n\tat org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)\n\tat org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\n\tat org.springframework.web.filter.HttpPutFormContentFilter.doFilterInternal(HttpPutFormContentFilter.java:109)\n\tat org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)\n\tat org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)\n\tat org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\n\tat org.springframework.web.filter.HiddenHttpMethodFilter.doFilterInternal(HiddenHttpMethodFilter.java:93)\n\tat org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)\n\tat org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)\n\tat org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\n\tat org.springframework.boot.actuate.metrics.web.servlet.WebMvcMetricsFilter.filterAndRecordMetrics(WebMvcMetricsFilter.java:155)\n\tat org.springframework.boot.actuate.metrics.web.servlet.WebMvcMetricsFilter.filterAndRecordMetrics(WebMvcMetricsFilter.java:123)\n\tat org.springframework.boot.actuate.metrics.web.servlet.WebMvcMetricsFilter.doFilterInternal(WebMvcMetricsFilter.java:108)\n\tat org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)\n\tat org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)\n\tat org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\n\tat org.springframework.web.filter.CharacterEncodingFilter.doFilterInternal(CharacterEncodingFilter.java:200)\n\tat org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)\n\tat org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)\n\tat org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)\n\tat org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:198)\n\tat org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96)\n\tat org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:493)\n\tat org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:140)\n\tat org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:81)\n\tat org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:87)\n\tat org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:342)\n\tat org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:800)\n\tat org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:66)\n\tat org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:806)\n\tat org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1498)\n\tat org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49)\n\tat java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)\n\tat java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)\n\tat org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)\n\tat java.lang.Thread.run(Thread.java:748)\n","app\_name":"livechat-service","log\_type":"app"}

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [March 31, 2022, 5:25pm UTC](https://discuss.elastic.co/t/fields-not-coming-in-discover/301181/2 "2022-03-31T17:25:16Z")

</div>

Hi,  
Could you please paste a request and response from the `Inspect` tab in Discover, as well as the name of the field you're unable to see in Discover?

---

<div class="post-metadata">

**Author:** ![Shubham\_Singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_singh/32/96820_2.png) [@Shubham\_Singh](https://discuss.elastic.co/u/Shubham_Singh)\
**Post date:** [April 1, 2022, 4:50am UTC](https://discuss.elastic.co/t/fields-not-coming-in-discover/301181/3 "2022-04-01T04:50:52Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/4/14744904a4a68b72f8dd9e6fc91e5e9898d43dc0.png)

I can see the filed when i uncheck hidden fields in discover. The logs are coming in json but the fields seems to be empty. Let me know if any changes required to fix this

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/3/63c5b1703a79dd6439ee2defa9377ba225750226.png)

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [April 1, 2022, 6:47am UTC](https://discuss.elastic.co/t/fields-not-coming-in-discover/301181/4 "2022-04-01T06:47:25Z")

</div>

Sorry, I meant - can you paste the actual request from "Request" tab and the actual response from the "Response" tab?

Hidden field means just what that second popup say - the field IS present in your Elasticsearch mapping, but not in the documents you requested, so Discover will hide it by default.

---

<div class="post-metadata">

**Author:** ![Shubham\_Singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_singh/32/96820_2.png) [@Shubham\_Singh](https://discuss.elastic.co/u/Shubham_Singh)\
**Post date:** [April 5, 2022, 6:30am UTC](https://discuss.elastic.co/t/fields-not-coming-in-discover/301181/5 "2022-04-05T06:30:25Z")

</div>

Request  
{  
"track\_total\_hits": true,  
"size": 1000,  
"sort": [  
{  
"@timestamp": {  
"order": "desc",  
"unmapped\_type": "boolean"  
}  
}  
],  
"version": true,  
"fields": [  
{  
"field": "_",  
"include\_unmapped": "true"  
},  
{  
"field": "@timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "aws.cloudtrail.digest.end\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "aws.cloudtrail.digest.newest\_event\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "aws.cloudtrail.digest.oldest\_event\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "aws.cloudtrail.digest.start\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "aws.cloudtrail.user\_identity.session\_context.creation\_date",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "azure.auditlogs.properties.activity\_datetime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "azure.enqueued\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "azure.signinlogs.properties.created\_at",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cef.extensions.agentReceiptTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cef.extensions.deviceCustomDate1",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cef.extensions.deviceCustomDate2",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cef.extensions.deviceReceiptTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cef.extensions.endTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cef.extensions.fileCreateTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cef.extensions.fileModificationTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cef.extensions.flexDate1",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cef.extensions.managerReceiptTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cef.extensions.oldFileCreateTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cef.extensions.oldFileModificationTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cef.extensions.startTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "checkpoint.subs\_exp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cisco.amp.threat\_hunting.incident\_end\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cisco.amp.threat\_hunting.incident\_start\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cisco.amp.timestamp\_nanoseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "crowdstrike.event.EndTimestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "crowdstrike.event.IncidentEndTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "crowdstrike.event.IncidentStartTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "crowdstrike.event.ProcessEndTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "crowdstrike.event.ProcessStartTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "crowdstrike.event.StartTimestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "crowdstrike.event.Timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "crowdstrike.event.UTCTimestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "crowdstrike.metadata.eventCreationTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "cyberarkpas.audit.iso\_timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "event.created",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "event.end",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "event.ingested",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "event.start",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "file.accessed",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "file.created",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "file.ctime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "file.mtime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "file.x509.not\_after",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "file.x509.not\_before",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "google\_workspace.admin.email.log\_search\_filter.end\_date",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "google\_workspace.admin.email.log\_search\_filter.start\_date",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "google\_workspace.admin.user.birthdate",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "gsuite.admin.email.log\_search\_filter.end\_date",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "gsuite.admin.email.log\_search\_filter.start\_date",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "gsuite.admin.user.birthdate",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "juniper.srx.elapsed\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "juniper.srx.epoch\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "juniper.srx.timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "kafka.block\_timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "microsoft.defender\_atp.lastUpdateTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "microsoft.defender\_atp.resolvedTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "microsoft.m365\_defender.alerts.creationTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "microsoft.m365\_defender.alerts.lastUpdatedTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "microsoft.m365\_defender.alerts.resolvedTime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "misp.campaign.first\_seen",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "misp.campaign.last\_seen",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "misp.intrusion\_set.first\_seen",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "misp.intrusion\_set.last\_seen",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "misp.observed\_data.first\_observed",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "misp.observed\_data.last\_observed",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "misp.report.published",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "misp.threat\_indicator.valid\_from",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "misp.threat\_indicator.valid\_until",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.collection\_time\_milliseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.exporter.timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.flow\_end\_microseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.flow\_end\_milliseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.flow\_end\_nanoseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.flow\_end\_seconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.flow\_start\_microseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.flow\_start\_milliseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.flow\_start\_nanoseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.flow\_start\_seconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.max\_export\_seconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.max\_flow\_end\_microseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.max\_flow\_end\_milliseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.max\_flow\_end\_nanoseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.max\_flow\_end\_seconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.min\_export\_seconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.min\_flow\_start\_microseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.min\_flow\_start\_milliseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.min\_flow\_start\_nanoseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.min\_flow\_start\_seconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.monitoring\_interval\_end\_milli\_seconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.monitoring\_interval\_start\_milli\_seconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.observation\_time\_microseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.observation\_time\_milliseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.observation\_time\_nanoseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.observation\_time\_seconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "netflow.system\_init\_time\_milliseconds",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "okta.debug\_context.debug\_data.suspicious\_activity.timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "package.installed",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "panw.panos.factorcompletiontime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "pensando.dfw.timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "postgresql.log.session\_start\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "process.parent.start",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "process.start",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "rsa.internal.lc\_ctime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "rsa.internal.time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "rsa.time.effective\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "rsa.time.endtime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "rsa.time.event\_queue\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "rsa.time.event\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "rsa.time.expire\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "rsa.time.recorded\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "rsa.time.stamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "rsa.time.starttime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "snyk.vulnerabilities.disclosure\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "snyk.vulnerabilities.introduced\_date",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "snyk.vulnerabilities.publication\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "sophos.xg.date",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "sophos.xg.eventtime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "sophos.xg.start\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "sophos.xg.starttime",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "sophos.xg.timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "suricata.eve.alert.created\_at",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "suricata.eve.alert.updated\_at",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "suricata.eve.flow.start",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "suricata.eve.tls.notafter",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "suricata.eve.tls.notbefore",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "threatintel.anomali.modified",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "threatintel.anomali.valid\_from",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "threatintel.indicator.first\_seen",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "threatintel.indicator.last\_seen",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "threatintel.misp.attribute.timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "threatintel.misp.date",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "threatintel.misp.publish\_timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "threatintel.misp.timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "tls.client.not\_after",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "tls.client.not\_before",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "tls.client.x509.not\_after",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "tls.client.x509.not\_before",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "tls.server.not\_after",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "tls.server.not\_before",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "tls.server.x509.not\_after",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "tls.server.x509.not\_before",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "x509.not\_after",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "x509.not\_before",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.kerberos.valid.from",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.kerberos.valid.until",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.ntp.org\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.ntp.rec\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.ntp.ref\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.ntp.xmt\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.ocsp.revoke.time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.ocsp.update.next",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.ocsp.update.this",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.pe.compile\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.smb\_files.times.accessed",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.smb\_files.times.changed",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.smb\_files.times.created",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.smb\_files.times.modified",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.smtp.date",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.snmp.up\_since",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.x509.certificate.valid.from",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zeek.x509.certificate.valid.until",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.meeting.start\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.participant.join\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.participant.leave\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.phone.answer\_start\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.phone.call\_end\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.phone.connected\_start\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.phone.date\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.phone.ringing\_start\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.recording.recording\_file.recording\_end",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.recording.recording\_file.recording\_start",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.recording.start\_time",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.timestamp",  
"format": "strict\_date\_optional\_time"  
},  
{  
"field": "zoom.webinar.start\_time",  
"format": "strict\_date\_optional\_time"  
}  
],  
"aggs": {  
"2": {  
"date\_histogram": {  
"field": "@timestamp",  
"fixed\_interval": "30s",  
"time\_zone": "UTC",  
"min\_doc\_count": 1  
}  
}  
},  
"script\_fields": {},  
"stored\_fields": [  
"_"  
],  
"runtime\_mappings": {},  
"\_source": false,  
"query": {  
"bool": {  
"must": ,  
"filter": [  
{  
"range": {  
"@timestamp": {  
"gte": "2022-04-05T06:11:59.903Z",  
"lte": "2022-04-05T06:26:59.903Z",  
"format": "strict\_date\_optional\_time"  
}  
}  
}  
],  
"should": ,  
"must\_not":   
}  
},  
"highlight": {  
"pre\_tags": [  
"@kibana-highlighted-field@"  
],  
"post\_tags": [  
"@/kibana-highlighted-field@"  
],  
"fields": {  
"\*": {}  
},  
"fragment\_size": 2147483647  
}  
}

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [April 5, 2022, 7:13am UTC](https://discuss.elastic.co/t/fields-not-coming-in-discover/301181/6 "2022-04-05T07:13:34Z")

</div>

You haven't pasted the response, so I can't be exactly sure, but it looks like `stack_trace` field is not being requested. Most likely this is due to the fact that it is an unmapped field in your ES index AND you have field filters on your index pattern in Kibana enabled. To overcome this, you have a few options. Either:

1. remove field filters from your index pattern
2. update the mapping of your ES index and make `stack_trace` a mapped field (this is the preferred way of overcoming this)
3. in Kibana Advanced Settings, under Discover, enable `readFieldsFromSource`

---

<div class="post-metadata">

**Author:** ![Shubham\_Singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubham_singh/32/96820_2.png) [@Shubham\_Singh](https://discuss.elastic.co/u/Shubham_Singh)\
**Post date:** [April 7, 2022, 4:33am UTC](https://discuss.elastic.co/t/fields-not-coming-in-discover/301181/7 "2022-04-07T04:33:22Z")

</div>

I Have updated my fields.yml from default to only required fields

- key: mybeat  
title: mybeat  
description: These are the fields used by mybeat.  
fields:
  - name: message  
type: keyword  
required: true  
description: The actual message name.
  - name: @timestamp  
type: date  
required: true  
description: The timestamp field.
  - name: @version  
type: number  
required: false  
description: Comment made by the user.
  - name: logger\_name  
type: text  
required: true  
description: Comment made by the user.
  - name: thread\_name  
type: text  
required: true  
description: Comment made by the user.
  - name: level  
type: text  
required: false  
description: Comment made by the user.
  - name: level\_value  
type: number  
required: true  
description: Comment made by the user.
  - name: app\_name  
type: keyword  
required: true  
description: Comment made by the user.
  - name: log\_type  
type: text  
required: true  
description: Comment made by the user.
  - name: stack\_trace  
type: text  
required: true  
description: Comment made by the user.

My filebeat config -  
filebeat.inputs:

- type: log  
enabled: true  
paths:

I deleted the older index template and tried to start filebeat but new index template and index is not created. Could you tell me what is wrong in my config

---

<div class="post-metadata">

**Author:** ![majagrubic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/majagrubic/32/74459_2.png) [@majagrubic](https://discuss.elastic.co/u/majagrubic)\
**Post date:** [April 7, 2022, 6:11am UTC](https://discuss.elastic.co/t/fields-not-coming-in-discover/301181/8 "2022-04-07T06:11:16Z")

</div>

I am not super familar with filebeats, for that it's best to ask in the `Beats` forum.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2022, 6:11am UTC](https://discuss.elastic.co/t/fields-not-coming-in-discover/301181/9 "2022-05-05T06:11:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
