# Filter dropdown for a field missing one of the top 5 values displayed under "Available fields" section

**URL:** <https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458>\
**Category:** Kibana\
**Created:** [August 8, 2019, 2:59pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458 "2019-08-08T14:59:14Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![deepalalitaakella](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@deepalalitaakella](https://discuss.elastic.co/u/deepalalitaakella)\
**Post date:** [August 8, 2019, 2:59pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/1 "2019-08-08T14:59:15Z")

</div>

I am having an issue with the dropdown values listed for a field when trying to filter for an index. It always shows the same 10 values but doesn't show one of the top 5 values listed in the "Available fields" section for the same field

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [August 8, 2019, 3:14pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/2 "2019-08-08T15:14:04Z")

</div>

Hi @deepalalitaakella,

thanks for your question. If you open the filter editor it's just showing the first 10 entries it finds, but once you start typing it should narrow down the search and query the server for more possible values matching the already entered prefix. Do the values from the "Available fields" section show up once you start typing them?

If you don't get your desired values even if you are starting to type the prefix, it's possible that you have a lot of data and the server is running into a timeout. If that should be the case there is a setting starting 7.3 `kibana.autocompleteTimeout` and `kibana.autocompleteTerminateAfter` that can be relaxed a bit to get a more complete picture. ([https://www.elastic.co/guide/en/kibana/current/settings.html](https://www.elastic.co/guide/en/kibana/current/settings.html))

---

<div class="post-metadata">

**Author:** ![deepalalitaakella](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@deepalalitaakella](https://discuss.elastic.co/u/deepalalitaakella)\
**Post date:** [August 8, 2019, 3:17pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/3 "2019-08-08T15:17:46Z")

</div>

Thanks for the Reply Joe . No it doesn't show up the other values in the filter when I start typing in

---

<div class="post-metadata">

**Author:** ![deepalalitaakella](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@deepalalitaakella](https://discuss.elastic.co/u/deepalalitaakella)\
**Post date:** [August 8, 2019, 3:21pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/4 "2019-08-08T15:21:11Z")

</div>

We are using Kibana 7.2.0 . So are the features kibana.autocompleteTimeout and kibana.autocompleteTerminateAfter available for this version?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [August 8, 2019, 3:26pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/5 "2019-08-08T15:26:45Z")

</div>

Unfortunately the setting is only available in Kibana 7.3 and upcoming versions

---

<div class="post-metadata">

**Author:** ![deepalalitaakella](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@deepalalitaakella](https://discuss.elastic.co/u/deepalalitaakella)\
**Post date:** [August 8, 2019, 3:28pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/6 "2019-08-08T15:28:28Z")

</div>

Thanks for the help Joe!!!

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [August 8, 2019, 3:32pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/7 "2019-08-08T15:32:38Z")

</div>

Another possibility - did you start typing the full value from the start or tried to match a substring in the middle of the value? Depending on how you indexed your data you have to match the value perfectly from the start - e.g. if the value `My partial string` is indexed as a keyword and I start typing `partial` in the dropdown, it won't show up because the field is not analyzed on a word-per-word basis

---

<div class="post-metadata">

**Author:** ![deepalalitaakella](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@deepalalitaakella](https://discuss.elastic.co/u/deepalalitaakella)\
**Post date:** [August 8, 2019, 4:04pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/8 "2019-08-08T16:04:57Z")

</div>

I did type in full word since it just a 4 letter Value.

---

<div class="post-metadata">

**Author:** ![deepalalitaakella](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@deepalalitaakella](https://discuss.elastic.co/u/deepalalitaakella)\
**Post date:** [August 8, 2019, 7:58pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/9 "2019-08-08T19:58:15Z")

</div>

I was looking at another aspect to this wrt the filebeat configuration where the fields.type might be having a wrong check here and also there is no symbolic link to the log file path mentioned here.

**filebeat.yml**  
filebeat.inputs:

- type: log  
enabled: true  
fields.type: error\_log  
symlinks: true  
paths:
  - /u/logs/docker/laravel/laravel\*.log

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [August 9, 2019, 8:51am UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/10 "2019-08-09T08:51:16Z")

</div>

Do you think your data didn't get indexed correctly? You can check whether it contains the expected data by looking at the documents in Discover or by sending queries to your Elasticsearch cluster directly.

---

<div class="post-metadata">

**Author:** ![deepalalitaakella](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@deepalalitaakella](https://discuss.elastic.co/u/deepalalitaakella)\
**Post date:** [August 16, 2019, 5:31pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/11 "2019-08-16T17:31:46Z")

</div>

Yes the data seems to have indexed correctly because the same field with .keyword as the extension contains the desired filter value.

i.e.  
app is a field that doesn't show the value "SBFE" in the filter drop down but  
app.keyword does show the same value.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [August 19, 2019, 4:19am UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/12 "2019-08-19T04:19:57Z")

</div>

A field has to be indexed as a keyword field in the mapping of the index ([https://www.elastic.co/guide/en/elasticsearch/reference/current/keyword.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/keyword.html)) to provide a filter dropdown. Otherwise it should display a regular input field:

Field indexed as keyword:

 ![19](https://us1.discourse-cdn.com/elastic/original/3X/0/f/0f32c9b516ea0a0b20bd9fa3d40402d5fa709abc.png)

Field indexed as text:

 ![10](https://us1.discourse-cdn.com/elastic/original/3X/0/c/0c91f276de5b235cca6e30431598e5f0e5dc303e.png)

Make sure to use the keyword variant if you want to look at a list of all terms of a field, ideally by looking at the mapping of the index: [https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html)

---

<div class="post-metadata">

**Author:** ![deepalalitaakella](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@deepalalitaakella](https://discuss.elastic.co/u/deepalalitaakella)\
**Post date:** [August 19, 2019, 1:38pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/13 "2019-08-19T13:38:02Z")

</div>

But the issue is both the fields here i.e. app and app.keyword show the filter dropdown but the app field is missing out some important filter values while app.keyword is not.  
What I am unable to understand is why is there a difference in the filter dropdown values for both when they are extracted from the same source field.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [August 20, 2019, 8:44am UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/14 "2019-08-20T08:44:12Z")

</div>

Maybe there is something strange configured in the mapping. Could you run `GET /<YOUR_INDEX_NAME>/_mapping` in the dev console and post the result here?

---

<div class="post-metadata">

**Author:** ![deepalalitaakella](https://avatars.discourse-cdn.com/v4/letter/d/ebca7d/32.png) [@deepalalitaakella](https://discuss.elastic.co/u/deepalalitaakella)\
**Post date:** [August 28, 2019, 3:39pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/15 "2019-08-28T15:39:17Z")

</div>

```
    "app" : {
      "type" : "text",
      "norms" : false,
      "fields" : {
        "keyword" : {
          "type" : "keyword",
          "ignore_above" : 256
        }
      }
    },

    "fields" : {
      "properties" : {
        "app" : {
          "type" : "keyword"
        },
        "env" : {
          "type" : "keyword"
        },
        "infra_group" : {
          "type" : "keyword"
        },
        "loc" : {
          "type" : "keyword"
        },
        "type" : {
          "type" : "keyword"
        },
        "type2" : {
          "type" : "keyword"
        }
      }
    },

```

There are a lot of fields so just updating for the app field which is having an issue

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 25, 2019, 3:39pm UTC](https://discuss.elastic.co/t/filter-dropdown-for-a-field-missing-one-of-the-top-5-values-displayed-under-available-fields-section/194458/16 "2019-09-25T15:39:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
