# Filtering search on properties

**URL:** <https://discuss.elastic.co/t/filtering-search-on-properties/29491>\
**Category:** Kibana\
**Created:** [September 17, 2015, 3:39pm UTC](https://discuss.elastic.co/t/filtering-search-on-properties/29491 "2015-09-17T15:39:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jdepp99](https://avatars.discourse-cdn.com/v4/letter/j/58956e/32.png) [@jdepp99](https://discuss.elastic.co/u/jdepp99)\
**Post date:** [September 17, 2015, 3:39pm UTC](https://discuss.elastic.co/t/filtering-search-on-properties/29491/1 "2015-09-17T15:39:45Z")

</div>

I am trying to build a dashboard on an existing elasticsearch cluster index and having trouble getting the visualizations to work. I am able to query the specific fields in discover tab but when trying to aggregate by terms on a pie chart for example, I do not see the fields I want.

Firstly, this is a view of kibana that shows for the specific index that contains the data, the available fields:

```
 Available Fields
@timestamp
 _id
 _type
 etc.

```

Customer ID is not one of them. Now there are different data sources coming to the same index for example :

job records  
customer records  
project records  
etc.

This is defined by \_type field. Now I want to access the customer record object and it has its own properties:

```
customer_index": {
    "dynamic_templates": [
       {
          "string_fields": {
             "mapping": {
                "index": "analyzed",
                "omit_norms": true,
                "type": "multi_field",
                "fields": {
                   "{name}": {
                      "index": "analyzed",
                      "omit_norms": true,
                      "type": "string"
                   },
                   "raw": {
                      "ignore_above": 256,
                      "index": "not_analyzed",
                      "type": "string"
                   }
                }
             },
             "match": "*",
             "match_mapping_type": "string"
          }
       },
       {
          "message_field": {
             "mapping": {
                "index": "analyzed",
                "omit_norms": true,
                "type": "string"
             },
             "match": "message",
             "match_mapping_type": "string"
          }
       }
    ],
    "_all": {
       "enabled": true,
       "omit_norms": true
    },
    "properties": {
       "@timestamp": {
          "type": "date",
          "format": "dateOptionalTime"
       },
       "@version": {
          "type": "string",
          "index": "not_analyzed"
       },
       "CCType": {
          "type": "string",
          "norms": {
             "enabled": false
          },
          "fields": {
             "raw": {
                "type": "string",
                "index": "not_analyzed",
                "ignore_above": 256
             }
          }
       },
       "Crawled": {
          "type": "string",
          "norms": {
             "enabled": false
          },
          "fields": {
             "raw": {
                "type": "string",
                "index": "not_analyzed",
                "ignore_above": 256
             }
          }
       },
       "customerid": {
          "type": "string",
          "norms": {
             "enabled": false
          },
          "fields": {
             "raw": {
                "type": "string",
                "index": "not_analyzed",
                "ignore_above": 256
             }
          }
       },

```

Now I would like to search for these property fields: customerid, crawled, cctype. I tried saving the search which was based on filtering the field and then using that to visualize but not getting the pie chart to work again. I see the fields in the available fields list but not when I try and add the visualization.

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [September 26, 2015, 4:33am UTC](https://discuss.elastic.co/t/filtering-search-on-properties/29491/2 "2015-09-26T04:33:19Z")

</div>

Are you selecting the same index you see in Discover when building your visualization?

---

<div class="post-metadata">

**Author:** ![jdepp99](https://avatars.discourse-cdn.com/v4/letter/j/58956e/32.png) [@jdepp99](https://discuss.elastic.co/u/jdepp99)\
**Post date:** [November 17, 2015, 5:07pm UTC](https://discuss.elastic.co/t/filtering-search-on-properties/29491/3 "2015-11-17T17:07:39Z")

</div>

Yes, thanks for your response. I was able to get it to work. The default configuration was ignoring the fields and I was told how to change that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:08pm UTC](https://discuss.elastic.co/t/filtering-search-on-properties/29491/4 "2017-07-06T14:08:51Z")

</div>


