# How to make a field aggregatable in Kibana

**URL:** <https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470>\
**Category:** Kibana\
**Created:** [June 22, 2017, 1:57pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470 "2017-06-22T13:57:55Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [June 22, 2017, 1:57pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/1 "2017-06-22T13:57:55Z")

</div>

I am running the latest versions of Kibana, Logstash and Elasticsearch. I am unsure how to make my logMessage field aggregatable. I have searched on the forums for a solid answer but can't seem to find a definitive one. Here is my mappings.

![](https://us1.discourse-cdn.com/elastic/original/3X/4/1/41fd1859568a75e726f38d87dcf9ae5a19957599.png)

```
"mappings": {
		"prnformat": {
			"properties":{
				"@timestamp": {
					"type": "date",
					"format": "strict_date_optional_time||epoch_millis"
				},
				"hostName": {
					"type": "string",
					"index": "not_analyzed"
				},
				"processName": {
					"type": "string",
					"index": "not_analyzed"
				},
				"sourcefilename": {
					"type": "string",
					"index": "not_analyzed"
				},
				"processID": {
					"type": "integer"
				},
				"fileName": {
					"type": "string",
					"index": "not_analyzed"
				},
				"lineNumber": {
					"type": "integer"
				},
				"logMessage": {
					"type": "string",
					"analyzer": "simple",
				}

```

Can someone provide some guidance?

Thanks!

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [June 22, 2017, 4:21pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/2 "2017-06-22T16:21:41Z")

</div>

More than likely, the field you are trying to aggregate on is not populated with data in your index. Here is a [link](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/83860/4?u=bigfunger) to another thread that asked a similar question.

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [June 22, 2017, 4:45pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/3 "2017-06-22T16:45:49Z")

</div>

![](https://us1.discourse-cdn.com/elastic/original/3X/5/b/5b8ee67d0648ce3c4e44510b8aab6cfc2d54d2cb.png)

I have data in that index.

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [June 22, 2017, 4:48pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/4 "2017-06-22T16:48:10Z")

</div>

Is there data in that field in your index?

If so, are you using a wildcard in your index pattern?

This can also occur when there is a type inconsistency for a field between two indexes in the same index pattern. You could start by creating a new index pattern in kibana that only examines a single index to see if that field shows up as aggregatable.

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [June 22, 2017, 4:57pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/5 "2017-06-22T16:57:18Z")

</div>

I did have a wildcard in the index pattern. But when I created an index without the wildcard there was data present and the field was still unaggregatable

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [June 22, 2017, 5:05pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/6 "2017-06-22T17:05:11Z")

</div>

Can you execute this in the Dev Tools console and report the results?

`GET <whatever your index is>/_mapping/<whatever your type is>/field/logMessage`

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [June 22, 2017, 5:11pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/7 "2017-06-22T17:11:21Z")

</div>

![](https://us1.discourse-cdn.com/elastic/original/3X/8/4/8495c61df1e16d3ffc1f8cfef4f1cbe022b5ae55.png)

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [June 22, 2017, 5:14pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/8 "2017-06-22T17:14:06Z")

</div>

Yeah, sorry I missed that earlier. You can't aggregate on a text field type. You need a keyword field type to aggregate.

[https://www.elastic.co/guide/en/elasticsearch/reference/current/text.html#text](https://www.elastic.co/guide/en/elasticsearch/reference/current/text.html#text)

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [June 22, 2017, 6:11pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/9 "2017-06-22T18:11:53Z")

</div>

I changed it in my json template and rebooted the system and it still comes up as a text type.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9bc756c3fca6eed29cde13bf952de615c0f17270.png)

 ![](https://us1.discourse-cdn.com/elastic/original/3X/6/2/62f16b72fd1499388a96698091e99eaabf0271dd.png)

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [June 22, 2017, 6:25pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/10 "2017-06-22T18:25:18Z")

</div>

You should be able to add a field to the existing mapping: [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-fields.html)

```auto

PUT prn-/_mapping/prnformat
{
  "properties": {
    "logMessage": {
      "type": "text",
      "fields": {
        "raw": { 
          "type": "keyword"
        }
      }
    }
  }
}

```

Then you should be able to aggregate on the raw field. However, keep in mind that this field will only be populated for new documents being indexed.

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [June 22, 2017, 7:27pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/11 "2017-06-22T19:27:04Z")

</div>

I am sorry for all of these questions. I am not terribly good with Kibana and the json templates. I prefer logstash. I made my json template this:

![](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9f2b36f411d5960dbe0fb6bb18df8bb1f5470c9b.png)

And the new logMessage.raw never showed up when I created a new index. I put that message in the console and this is what the output came out to be:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/9/3/93162b34b1ac4024e20c51014708f0e939d3f177.png)

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [June 22, 2017, 7:40pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/12 "2017-06-22T19:40:40Z")

</div>

The message returns seems to indicate that you're attempting to change the analyzer. With mappings, you can only add things. Most things can't be changed.

These are the steps that I went through to try and figure out the issue:

```auto
# Delete any existing test index
DELETE test_index

# Create a new index mapping that has a text field
PUT test_index
{
  "mappings": {
    "doc": {
      "properties": {
        "city": {
          "type": "text",
          "analyzer": "simple"
        }
      }
    }
  }
}

# Examine the mapping
GET test_index/_mapping

# Index a document that populates that field
PUT test_index/doc/1
{
  "city": "I am a text value, and will get analyzed, but cannot be aggregated"
}

# Examine the document
POST test_index/_search

# Modify the mapping to add the city.raw field
PUT test_index/_mapping/doc 
{
  "properties": {
    "city": {
      "type": "text",
      "fields": {
        "raw": { 
          "type": "keyword"
        }
      },
      "analyzer": "simple"
    }
  }
}

# Index another document that populates the city field
PUT test_index/doc/2
{
  "city": "I am also a text value, and will get analyzed, but cannot be aggregated, but I also have an unanalyzed aggregatable .raw field that can"
}

# Notice that I can now aggregate on the city.raw field, but only the new document has values.
POST test_index/_search
{
  "size": 0,
  "aggs": {
    "my-term-aggregation": {
      "terms": {
        "field": "city.raw",
        "size": 5,
        "order": {
          "_count": "desc"
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [June 22, 2017, 7:42pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/13 "2017-06-22T19:42:06Z")

</div>

I see you using the syntax 'string' in many places. That has been deprecated and replaced with the 'text' and 'keyword' syntax. That may be another source of conflict.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2017, 7:42pm UTC](https://discuss.elastic.co/t/how-to-make-a-field-aggregatable-in-kibana/90470/14 "2017-07-20T19:42:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
