How to enable logs being generated with both field and field.keyword on elastic search?


(yashraj) #1

Hello,

I am using ELK with version 6.1.1. I am facing problem with elastic search fields which are coming in log lines. One of my fields having identity as fieldname and fieldname.keyword (handled by Elastic search automatically) is not giving data in visualisations with both field i.e. whenever i am going to find data of fieldname so some data is given by fieldname and remaining is given by fieldname.keyword. As it was already deployed and working properly at one machine so after taking snapshot from that machine i have successfully restored my complete log line data and also dashboards and visualisations on another machine of same Ubuntu OS so log data are visible to me completely . So for new data after complete setup and configurations same as before with same version of filebeat, logstash, elasticsearch and kibana i.e. 6.1.1 (for all of them), i want to get my data as i can aggregate by fieldname as before. So i am hardly needed to aggregate by fieldname (not by fieldname.keyword) in visualisations and want to get complete data of complete log lines in visualisations which is not giving by elastic search.


(Mark Walkom) #2

Your post is a little hard to read, it'd be great if you could split the text up to make a little easier to digest :slight_smile:

Are you saying that not all of your fields have a .keyword value? If not can you post the mapping for the index?