# Host.hostname field bug

**URL:** <https://discuss.elastic.co/t/host-hostname-field-bug/188219>\
**Category:** SIEM\
**Created:** [July 1, 2019, 3:02am UTC](https://discuss.elastic.co/t/host-hostname-field-bug/188219 "2019-07-01T03:02:39Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chinedum\_Nwuzor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chinedum_nwuzor/32/48107_2.png) [@Chinedum\_Nwuzor](https://discuss.elastic.co/u/Chinedum_Nwuzor)\
**Post date:** [July 1, 2019, 3:02am UTC](https://discuss.elastic.co/t/host-hostname-field-bug/188219/1 "2019-07-01T03:02:39Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/0/70b3c851ce0e94f618502646c9b21e9f668305f8.png)

Can anyone please help resolve this?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 1, 2019, 4:58am UTC](https://discuss.elastic.co/t/host-hostname-field-bug/188219/2 "2019-07-01T04:58:46Z")

</div>

Please don't post images of text as they are hardly readable and not searchable.

Instead paste the text and format it with `</>` icon. Check the preview window.

Also give more context about what you did, what settings you changed, when this happens...

---

<div class="post-metadata">

**Author:** ![Chinedum\_Nwuzor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chinedum_nwuzor/32/48107_2.png) [@Chinedum\_Nwuzor](https://discuss.elastic.co/u/Chinedum_Nwuzor)\
**Post date:** [July 1, 2019, 5:18am UTC](https://discuss.elastic.co/t/host-hostname-field-bug/188219/3 "2019-07-01T05:18:29Z")

</div>

Sorry my bad. I simply just created an index pattern and tried to view data on the SIEM app and it pops up this error “[illegal\_argument\_exception] Fielddata is disabled on text fields by default. Set fielddata=true on [host.name] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 1, 2019, 8:23am UTC](https://discuss.elastic.co/t/host-hostname-field-bug/188219/4 "2019-07-01T08:23:32Z")

</div>

What is the source of your data?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [July 1, 2019, 10:29am UTC](https://discuss.elastic.co/t/host-hostname-field-bug/188219/5 "2019-07-01T10:29:05Z")

</div>

At first sight that looks like Beats data for which the Elasticsearch mapping was not loaded. If my guess is right, it would be good to give us the Beat type, version, and if you are sending data directly to Elasticsearch or via Logstash or something else.

---

<div class="post-metadata">

**Author:** ![Chinedum\_Nwuzor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chinedum_nwuzor/32/48107_2.png) [@Chinedum\_Nwuzor](https://discuss.elastic.co/u/Chinedum_Nwuzor)\
**Post date:** [July 1, 2019, 1:34pm UTC](https://discuss.elastic.co/t/host-hostname-field-bug/188219/6 "2019-07-01T13:34:49Z")

</div>

Auditbeat 7.2 and winlogbeat 7.2. I’m sending to Elasticsearch via Logstash

---

<div class="post-metadata">

**Author:** ![cwurm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cwurm/32/34882_2.png) [@cwurm](https://discuss.elastic.co/u/cwurm)\
**Post date:** [July 1, 2019, 3:55pm UTC](https://discuss.elastic.co/t/host-hostname-field-bug/188219/7 "2019-07-01T15:55:44Z")

</div>

Hi @Chinedum_Nwuzor - before sending data through Logstash you first have to load the index templates from the Beats with `./auditbeat setup` and `./winlogbeat setup`. That makes sure the `host.name` field is a `keyword` field (which supports aggregations), not a `text` field (which does not).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 29, 2019, 3:55pm UTC](https://discuss.elastic.co/t/host-hostname-field-bug/188219/8 "2019-07-29T15:55:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
