# How to make a field aggregable in Kibana

**URL:** <https://discuss.elastic.co/t/how-to-make-a-field-aggregable-in-kibana/136013>\
**Category:** Kibana\
**Created:** [June 15, 2018, 12:40am UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregable-in-kibana/136013 "2018-06-15T00:40:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pradana](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@Pradana](https://discuss.elastic.co/u/Pradana)\
**Post date:** [June 15, 2018, 12:40am UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregable-in-kibana/136013/1 "2018-06-15T00:40:12Z")

</div>

I have a field, operator, How I can make this aggregable ? In previous version of Kibana, this quite easy, I just need to go to setting index and make this field become index.

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [June 15, 2018, 2:37am UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregable-in-kibana/136013/2 "2018-06-15T02:37:48Z")

</div>

It's most likely due to the mapping type of the index.

Can you provide the following for your index:

[http://localhost:9200/](http://localhost:9200/)/\_mapping

My assumption is that the field is text and should be keyword.

---

<div class="post-metadata">

**Author:** ![Pradana](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@Pradana](https://discuss.elastic.co/u/Pradana)\
**Post date:** [June 15, 2018, 3:20am UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregable-in-kibana/136013/3 "2018-06-15T03:20:55Z")

</div>

Hi,

Below are my mapping for the index :

```auto
"filebeat-2018.06.15": {
    "mappings": {
      "doc": {
        "properties": {
          "@timestamp": {
            "type": "date"
          },
          "@version": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "addrnpi": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "addrton": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "beat": {
            "properties": {
              "hostname": {
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              },
              "name": {
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              },
              "version": {
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              }
            }
          },
          "debugtype": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "destaddr": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "host": {
            "properties": {
              "name": {
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              }
            }
          },
          "input": {
            "properties": {
              "type": {
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              }
            }
          },
          "logdate": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "message": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "offset": {
            "type": "long"
          },
          "operator": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "operator_name": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "prospector": {
            "properties": {
              "type": {
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              }
            }
          },
          "smsdate": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "source": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "sourceaddr": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "sourcenpi": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "sourceton": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "status": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "tags": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
        }

```

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [June 15, 2018, 3:19pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregable-in-kibana/136013/4 "2018-06-15T15:19:32Z")

</div>

It appears to be of type keyword. Are you not able to aggregate on it? Try clicking the refresh button on the index pattern under Management.

---

<div class="post-metadata">

**Author:** ![Pradana](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@Pradana](https://discuss.elastic.co/u/Pradana)\
**Post date:** [June 16, 2018, 1:11am UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregable-in-kibana/136013/5 "2018-06-16T01:11:04Z")

</div>

After refreshing the data, then its working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2018, 1:11am UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregable-in-kibana/136013/6 "2018-07-14T01:11:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
