# How to update Index patterns?

**URL:** <https://discuss.elastic.co/t/how-to-update-index-patterns/290636>\
**Category:** Kibana\
**Created:** [December 1, 2021, 7:38am UTC](https://discuss.elastic.co/t/how-to-update-index-patterns/290636 "2021-12-01T07:38:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [December 1, 2021, 7:38am UTC](https://discuss.elastic.co/t/how-to-update-index-patterns/290636/1 "2021-12-01T07:38:07Z")

</div>

I currently use Elastic stack 7.14. Recently, when I wanted to search for a certain field, I found that it couldn’t be searched. Kibana gave me a prompt "Unindexed fields can not be searched". I remember that index patterns can be updated on kibana Stack Management, but on kibana 7.14. I can’t find this button. How can I update index patterns from now on?

 ![微信图片_20211201153402](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b53b67b351db4c988457fe298e5ea569215cd4f2.png)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 1, 2021, 7:58am UTC](https://discuss.elastic.co/t/how-to-update-index-patterns/290636/2 "2021-12-01T07:58:39Z")

</div>

This is an automatic function now 🙂

---

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [December 2, 2021, 1:02am UTC](https://discuss.elastic.co/t/how-to-update-index-patterns/290636/3 "2021-12-02T01:02:29Z")

</div>

If it is an automatic function, why do I still find "Unindexed fields can not be searched" on discover?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 2, 2021, 1:19am UTC](https://discuss.elastic.co/t/how-to-update-index-patterns/290636/4 "2021-12-02T01:19:27Z")

</div>

That's to do with the mapping of those fields I'd say. Can you share that?

---

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [December 2, 2021, 2:22am UTC](https://discuss.elastic.co/t/how-to-update-index-patterns/290636/5 "2021-12-02T02:22:49Z")

</div>

I added an Ingest Node Pipelines to parse the json data of the original field, and then it’s a bit strange that there is no original field in the mapping, but it still exists in the apm template.

```auto
[
  {
    "json": {
      "field": "http.request.body.original",
      "target_field": "http.request.body.original_json",
      "ignore_failure": true
    }
  }
]

```

```auto
  "http": {
          "dynamic": "false",
          "properties": {
            "request": {
              "properties": {
                "body": {
                  "properties": {
                    "bytes": {
                      "type": "long"
                    },
                    "content": {
                      "type": "keyword",
                      "ignore_above": 1024,
                      "fields": {
                        "text": {
                          "type": "text",
                          "norms": false
                        }
                      }
                    }
                  }
                },
                "bytes": {
                  "type": "long"
                },
                "headers": {
                  "type": "object",
                  "enabled": false
                },
                "id": {
                  "type": "keyword",
                  "ignore_above": 1024
                },
                "method": {
                  "type": "keyword",
                  "ignore_above": 1024
                },
                "mime_type": {
                  "type": "keyword",
                  "ignore_above": 1024
                },
                "referrer": {
                  "type": "keyword",
                  "ignore_above": 1024
                }
              }
            }

```

## apm-7.14.0 template

```auto
    "http": {
      "dynamic": false,
      "type": "object",
      "properties": {
        "request": {
          "type": "object",
          "properties": {
            "headers": {
              "type": "object",
              "enabled": false
            },
            "referrer": {
              "ignore_above": 1024,
              "type": "keyword"
            },
            "method": {
              "ignore_above": 1024,
              "type": "keyword"
            },
            "mime_type": {
              "ignore_above": 1024,
              "type": "keyword"
            },
            "bytes": {
              "type": "long"
            },
            "id": {
              "ignore_above": 1024,
              "type": "keyword"
            },
            "body": {
              "type": "object",
              "properties": {
                "original": {
                  "type": "object"
                },
                "bytes": {
                  "type": "long"
                },
                "content": {
                  "ignore_above": 1024,
                  "type": "keyword",
                  "fields": {
                    "text": {
                      "norms": false,
                      "type": "text"
                    }
                  }
                }
              }
            }
          }
        }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 30, 2021, 2:23am UTC](https://discuss.elastic.co/t/how-to-update-index-patterns/290636/6 "2021-12-30T02:23:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
