How to set a string field as aggregable in ELK 5.0?

(JoseAlberto) #1


I am playing with new ELK Stack, after a few bumps I got it working.

I want to create avisualization based on a string field (program) but mostly string fields are marked as "no aggreable" so don't show up in visalizaiton UI.

How can I set a field as "aggregable"?


(Mark Walkom) #2

You need to set the field itself as not analysed - or keyword as it's known now.

(JoseAlberto) #3

thanks @warkolm, but there is something I dont understand. This is a portion of default logstash mapping:

  "mappings": {
    "_default_": {
      "dynamic_templates": [
          "message_field": {
            "path_match": "message",
            "mapping": {
              "norms": false,
              "type": "text"
            "match_mapping_type": "string"
          "string_fields": {
            "mapping": {
              "norms": false,
              " fields": {
                "keyword": {
                  "type": "keyword"
              "type": "text"
            "match_mapping_type": "string",
            "match": "*"

So if I understand correctly, it's including a keyword subfield to string fields (foo.keyword), I will prefer to use that subfield because is already there. How can it be used in kibana visualization?

(Mark Walkom) #4

You should be able to pick that field for the visualisation.

(JoseAlberto) #5

no, no string field is showing up

(Mark Walkom) #6

So what is the actual mapping being applied then?

(JoseAlberto) #7

The one I previously posted, the default one set by logstash when there is
not mapping.

The main problem is kibana is not showing up subfields like foo.keyword in
the visualization config

(Mark Walkom) #8

Is that the /indexname/_mapping you receive when issuing a get? Or is it the template.

(JoseAlberto) #9

is the one I get using GET in the kibana REST client.

I am going crazy here

(Mark Walkom) #10

Have you tried refreshing the fields in KB?

(JoseAlberto) #11

after recreating everything it works, so I yet don't know what happened.

Thanks for the help

(system) #12