# How to set a string field as aggregable in ELK 5.0?

**URL:** <https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960>\
**Category:** Kibana\
**Created:** [November 4, 2016, 12:20am UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960 "2016-11-04T00:20:53Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![jasl](https://avatars.discourse-cdn.com/v4/letter/j/9fc348/32.png) [@jasl](https://discuss.elastic.co/u/jasl)\
**Post date:** [November 4, 2016, 12:20am UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960/1 "2016-11-04T00:20:53Z")

</div>

Hi!

I am playing with new ELK Stack, after a few bumps I got it working.

I want to create avisualization based on a string field (program) but mostly string fields are marked as "no aggreable" so don't show up in visalizaiton UI.

How can I set a field as "aggregable"?

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 4, 2016, 7:51am UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960/2 "2016-11-04T07:51:55Z")

</div>

You need to set the field itself as not analysed - or keyword as it's known now.  
See [https://www.elastic.co/guide/en/elasticsearch/reference/5.0/analysis-keyword-analyzer.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.0/analysis-keyword-analyzer.html)

---

<div class="post-metadata">

**Author:** ![jasl](https://avatars.discourse-cdn.com/v4/letter/j/9fc348/32.png) [@jasl](https://discuss.elastic.co/u/jasl)\
**Post date:** [November 4, 2016, 10:39am UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960/3 "2016-11-04T10:39:34Z")

</div>

thanks @warkolm, but there is something I dont understand. This is a portion of default logstash mapping:

```
  "mappings": {
    "_default_": {
      "dynamic_templates": [
        {
          "message_field": {
            "path_match": "message",
            "mapping": {
              "norms": false,
              "type": "text"
            },
            "match_mapping_type": "string"
          }
        },
        {
          "string_fields": {
            "mapping": {
              "norms": false,
              " fields": {
                "keyword": {
                  "type": "keyword"
                }
              },
              "type": "text"
            },
            "match_mapping_type": "string",
            "match": "*"
          }
        }
      ], 

```

So if I understand correctly, it's including a keyword subfield to string fields (foo.keyword), I will prefer to use that subfield because is already there. How can it be used in kibana visualization?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 4, 2016, 10:51pm UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960/4 "2016-11-04T22:51:40Z")

</div>

You should be able to pick that field for the visualisation.

---

<div class="post-metadata">

**Author:** ![jasl](https://avatars.discourse-cdn.com/v4/letter/j/9fc348/32.png) [@jasl](https://discuss.elastic.co/u/jasl)\
**Post date:** [November 5, 2016, 1:31am UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960/5 "2016-11-05T01:31:02Z")

</div>

no, no string field is showing up

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 5, 2016, 4:22am UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960/6 "2016-11-05T04:22:52Z")

</div>

So what is the actual mapping being applied then?

---

<div class="post-metadata">

**Author:** ![jasl](https://avatars.discourse-cdn.com/v4/letter/j/9fc348/32.png) [@jasl](https://discuss.elastic.co/u/jasl)\
**Post date:** [November 5, 2016, 1:08pm UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960/7 "2016-11-05T13:08:17Z")

</div>

The one I previously posted, the default one set by logstash when there is  
not mapping.

The main problem is kibana is not showing up subfields like foo.keyword in  
the visualization config

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 5, 2016, 9:01pm UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960/8 "2016-11-05T21:01:33Z")

</div>

Is that the `/indexname/_mapping` you receive when issuing a get? Or is it the template.

---

<div class="post-metadata">

**Author:** ![jasl](https://avatars.discourse-cdn.com/v4/letter/j/9fc348/32.png) [@jasl](https://discuss.elastic.co/u/jasl)\
**Post date:** [November 5, 2016, 10:40pm UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960/9 "2016-11-05T22:40:22Z")

</div>

is the one I get using GET in the kibana REST client.

I am going crazy here

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 5, 2016, 11:10pm UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960/10 "2016-11-05T23:10:59Z")

</div>

Have you tried refreshing the fields in KB?

---

<div class="post-metadata">

**Author:** ![jasl](https://avatars.discourse-cdn.com/v4/letter/j/9fc348/32.png) [@jasl](https://discuss.elastic.co/u/jasl)\
**Post date:** [November 29, 2016, 10:32pm UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960/11 "2016-11-29T22:32:51Z")

</div>

after recreating everything it works, so I yet don't know what happened.

Thanks for the help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:33pm UTC](https://discuss.elastic.co/t/how-to-set-a-string-field-as-aggregable-in-elk-5-0/64960/12 "2017-07-06T13:33:54Z")

</div>


