# Index Pattern behavior

**URL:** <https://discuss.elastic.co/t/index-pattern-behavior/227643>\
**Category:** Kibana\
**Created:** [April 12, 2020, 3:05am UTC](https://discuss.elastic.co/t/index-pattern-behavior/227643 "2020-04-12T03:05:29Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [April 12, 2020, 3:05am UTC](https://discuss.elastic.co/t/index-pattern-behavior/227643/1 "2020-04-12T03:05:29Z")

</div>

Hi..

I have a logstash index and already delete\_by\_query of the part of the indexes, and no more particular fields, then I've done to delete the index pattern to make sure the fields is clean.  
The strange behavior of the Kibana Index pattern is still have the fields that already removed in the index.  
Is it expected ?  
I'm using 7.6.2

Fadjar Tandabawana

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [April 12, 2020, 6:39am UTC](https://discuss.elastic.co/t/index-pattern-behavior/227643/2 "2020-04-12T06:39:48Z")

</div>

Kibana index patterns cache the fields in your indices. If you go to the index pattern management page, there is a reload button for the index pattern to refresh fields.

See also here: [https://www.elastic.co/guide/en/kibana/current/managing-fields.html](https://www.elastic.co/guide/en/kibana/current/managing-fields.html) ( **Refresh the index fields list** )

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [April 12, 2020, 7:59am UTC](https://discuss.elastic.co/t/index-pattern-behavior/227643/3 "2020-04-12T07:59:20Z")

</div>

Yes...

I did... several times...

following the page:  
**Refresh the index fields list.** You can refresh the index fields list to pick up any **newly-added** fields. Doing so also resets the Kibana popularity counters for the fields. The popularity counters are used in **Discover** to sort fields in lists.

What about deleted ones?

Still no luck to cleanup the old fields

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [April 12, 2020, 9:48am UTC](https://discuss.elastic.co/t/index-pattern-behavior/227643/4 "2020-04-12T09:48:23Z")

</div>

Did you also remove them from the mapping of your indices?

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [April 12, 2020, 10:36am UTC](https://discuss.elastic.co/t/index-pattern-behavior/227643/5 "2020-04-12T10:36:15Z")

</div>

That's what I'm afraid..  
Never done before to remove the fields in the mapping.  
I'm to afraid to remove mapping in production environment...

Any suggestion?  
Or if it possible, to make it more automagically in the next release... 🙂

Regards,  
Fadjar Tandabawana

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [April 13, 2020, 7:36am UTC](https://discuss.elastic.co/t/index-pattern-behavior/227643/6 "2020-04-13T07:36:45Z")

</div>

Kibana index patterns use the [field caps api](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-field-caps.html) to fetch the list of fields from Elasticsearch. It seems like you have to remove the fields from the mapping to prevent them from showing up in the index pattern (which would include re-indexing existing data).

I can think of one workaround. Go to Management \> saved objects, select your index pattern and export it. This will give you a JSON file of the index pattern. Go in there and remove the fields you don't want to show up anymore - be careful to not mess up the JSON syntax (no trailing commas and the like). Now re-import the file (this will overwrite the existing index pattern). Now the field should be gone from all UIs (Visualize, Discover). If you are refreshing the index pattern, you will have to do this again.

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [April 13, 2020, 8:44am UTC](https://discuss.elastic.co/t/index-pattern-behavior/227643/7 "2020-04-13T08:44:51Z")

</div>

Hi @flash1293,

Already exported...  
Unfortunately, the JSON format is not the JSON that I recognized..🙂  
It's ndjson and makes me headache to read...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/8/6891f1c9ba50941f5763092d733fd0739fb8fd68.png)

I'm eager to do it, but there's too complicated, also the result in one line, I'm afraid, even I can modify it, the result is not what i'm expected, because of the complexity.  
If in the new release can change to human readable JSON with proper indentation, I'll happy to modify it...

Regards,  
Fadjar Tandabawana

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [April 13, 2020, 9:32am UTC](https://discuss.elastic.co/t/index-pattern-behavior/227643/8 "2020-04-13T09:32:01Z")

</div>

Turning the export format into human readable json is not something on the roadmap (there are a bunch of technical hurdles)

If you can upload the complete file to pastebin or something else and tell me which fields to remove I can do it for you.

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [April 13, 2020, 9:36am UTC](https://discuss.elastic.co/t/index-pattern-behavior/227643/9 "2020-04-13T09:36:29Z")

</div>

Thank you @flash1293...  
I don't want to bother you...

I'll do it in my spare time...

Regards,  
Fadjar Tandabawana

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2020, 9:36am UTC](https://discuss.elastic.co/t/index-pattern-behavior/227643/10 "2020-05-11T09:36:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
