# How to add fileds to index pattren , so it can be filterd by in discover search

**URL:** https://discuss.elastic.co/t/how-to-add-fileds-to-index-pattren-so-it-can-be-filterd-by-in-discover-search/259969
**Category:** Kibana
**Created:** [December 31, 2020, 3:50pm UTC](https://discuss.elastic.co/t/how-to-add-fileds-to-index-pattren-so-it-can-be-filterd-by-in-discover-search/259969 "2020-12-31T15:50:42Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)
#### Post date: [December 31, 2020, 3:50pm UTC](https://discuss.elastic.co/t/how-to-add-fileds-to-index-pattren-so-it-can-be-filterd-by-in-discover-search/259969/1 "2020-12-31T15:50:43Z")

</div>

i defined simple index pattern " filebeat-\*"  
and it has only a few fields which i can filter by:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/6/460925b463df2546bf1207a49ca3d50ef68c14ef.png)

now i like to add new fields to this index pattern. which i can see they exist

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/c/9cf1e7c872e25e31e99281671d0ae4807019ab66.png)

but i can't find anywhere how to add them so i could get the data that i could filter by  
what I'm missing here?

for example i like to add :  
kubernetes.pod.name  
and  
kubernetes.container.name

so i cloud do search like :  
kubernetes.pod.name : "my-pod-nameX"

i followed this tutorial:

> **[Run Filebeat on Kubernetes | Filebeat Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/running-on-kubernetes.html)**

  
and i do see all the logs in kibana

---

<div class="post-metadata">

### Author: ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)
#### Post date: [January 4, 2021, 4:51pm UTC](https://discuss.elastic.co/t/how-to-add-fileds-to-index-pattren-so-it-can-be-filterd-by-in-discover-search/259969/2 "2021-01-04T16:51:27Z")

</div>

The field list in discover is sampled from the first 500 documents - if the field doesn't have a value in these documents, it won't show up. You can show the complete list based on the mapping by clicking "Filter by type" and unchecking "Hide missing fields".

Alternatively you can add a new filter below the search bar and just use the field (it will show up in the suggestions of the field input) - this will make sure the 500 documents contain that field and it will also show up in the sidebar.

---

<div class="post-metadata">

### Author: ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)
#### Post date: [January 4, 2021, 8:01pm UTC](https://discuss.elastic.co/t/how-to-add-fileds-to-index-pattren-so-it-can-be-filterd-by-in-discover-search/259969/3 "2021-01-04T20:01:24Z")

</div>

Thanks for answering  
Do you have idea why i can't get the value of the kubernetes.pod.name?  
As i can see the info in the logs ?

---

<div class="post-metadata">

### Author: ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)
#### Post date: [January 5, 2021, 8:44am UTC](https://discuss.elastic.co/t/how-to-add-fileds-to-index-pattren-so-it-can-be-filterd-by-in-discover-search/259969/4 "2021-01-05T08:44:17Z")

</div>

I don't understand your question, can you explain what you seeing and what you expect to see?

---

<div class="post-metadata">

### Author: ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)
#### Post date: [January 5, 2021, 9:04am UTC](https://discuss.elastic.co/t/how-to-add-fileds-to-index-pattren-so-it-can-be-filterd-by-in-discover-search/259969/5 "2021-01-05T09:04:02Z")

</div>

hey  
thanks for answering i would happily explain more if i could make it work, as my installation have a lot of problems  
see here :

> [@DNS lookup failure "my-cluster-es-http": lookup my-cluster-es-http on 1xx.xx.xx.xx:53: no such host](https://discuss.elastic.co/t/dns-lookup-failure-my-cluster-es-http-lookup-my-cluster-es-http-on-1xx-xx-xx-xx-no-such-host/260172):
>
> Hey i followed the quickstart tutorial to setup elasticsearch on Kubernetes . installed it on pre created namespace not default . apiVersion: elasticsearch.k8s.elastic.co/v1 kind: Elasticsearch metadata: name: my-cluster namespace: test-cluster spec: version: 7.10.1 nodeSets: - name: default count: 3 config: node.master: true node.data: true node.ingest: true node.store.allow\_mmap: false now in filebeat-kubernetes.yaml i set : env: - name: E…

---

<div class="post-metadata">

### Author: ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)
#### Post date: [January 5, 2021, 9:35am UTC](https://discuss.elastic.co/t/how-to-add-fileds-to-index-pattren-so-it-can-be-filterd-by-in-discover-search/259969/6 "2021-01-05T09:35:08Z")

</div>

As Kibana is the top of the stack, it probably makes sense to resolve all problems in the lower levels first before coming back to troubleshoot Kibana. In a lot of cases the problems aren't even caused by Kibana in the first place but the data itself is not in order in Elasticsearch.

---

<div class="post-metadata">

### Author: ![umen](https://avatars.discourse-cdn.com/v4/letter/u/ec9cab/32.png) [@umen](https://discuss.elastic.co/u/umen)
#### Post date: [January 5, 2021, 10:31am UTC](https://discuss.elastic.co/t/how-to-add-fileds-to-index-pattren-so-it-can-be-filterd-by-in-discover-search/259969/7 "2021-01-05T10:31:21Z")

</div>

thanks for answering, sure you are right, the problem is that it just stopped working after and uninstall it once and installed it again but this time with a custom namespace, then everything stopped to work.  
this question from my first install with the "default" namespace. as we not allowed to use the "default" namespace.  
and even then it didn't get me all the info . like  
kubernetes.pod.name  
kubernetes.container.name

i saw allot of questions regarding the DNS with out any answer .. so I'm afraid my case will be the same

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 2, 2021, 10:31am UTC](https://discuss.elastic.co/t/how-to-add-fileds-to-index-pattren-so-it-can-be-filterd-by-in-discover-search/259969/8 "2021-02-02T10:31:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
