# Index problem .keyword

**URL:** <https://discuss.elastic.co/t/index-problem-keyword/308112>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [June 24, 2022, 12:08pm UTC](https://discuss.elastic.co/t/index-problem-keyword/308112 "2022-06-24T12:08:57Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![AnotherGuy](https://avatars.discourse-cdn.com/v4/letter/a/d9b06d/32.png) [@AnotherGuy](https://discuss.elastic.co/u/AnotherGuy)\
**Post date:** [June 24, 2022, 12:08pm UTC](https://discuss.elastic.co/t/index-problem-keyword/308112/1 "2022-06-24T12:08:57Z")

</div>

Hi,

I go a big problem today and i don't know how to resolve it.

I work on **ELK 7.17.1** on the same computer and with **filebeat** on another computer which sends me log in live with a docker.

I import my template Dashboard so it's good but i found this error:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/4/647d7ab798f51dfae1243869ad2f5bc970758dc3.png)

So i checked the index **filebeat-** \* with the **Data Visualizer** and i have this :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/0/d0b2dd61bba9b854e79df03800a68f6fbaeedcfe.png)

All of my type: text have a .keyword with the entire log in it, but i want to be in the log\_data\_name type: text not in the .keyword.  
I found a "solution" it's to set the

```auto
"fielddata": true

```

source:

1. [how to set fielddata true on created index · Issue #584 · elastic/elasticsearch-ruby · GitHub](https://github.com/elastic/elasticsearch-ruby/issues/584)
2. [Text type family | Elasticsearch Guide [master] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/master/text.html#fielddata-mapping-param)

but i don't know how to do it without the curl PUT ...

So my question is, how my logs can write directly on the type: text?

---

<div class="post-metadata">

**Author:** ![AnotherGuy](https://avatars.discourse-cdn.com/v4/letter/a/d9b06d/32.png) [@AnotherGuy](https://discuss.elastic.co/u/AnotherGuy)\
**Post date:** [June 24, 2022, 1:16pm UTC](https://discuss.elastic.co/t/index-problem-keyword/308112/2 "2022-06-24T13:16:31Z")

</div>

Update!

I got this error:

> Error executing runtime field or scripted field on index pattern filebeat-\*

```auto
if (doc['log_data_name'].value == 'car_mode')
{
  
        ^---- HERE

```

> Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [log\_data\_name] in order to load field data by uninverting the inverted index. Note that this can use significant memory.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 24, 2022, 2:49pm UTC](https://discuss.elastic.co/t/index-problem-keyword/308112/3 "2022-06-24T14:49:43Z")

</div>

Most likely You did not run `filebeat setup` before you started filebeat per [the quick start instructions step 4](https://www.elastic.co/guide/en/beats/filebeat/7.17/filebeat-installation-configuration.html) therefore the correct index template and mappings did not get loaded. Which means you are getting the "default mapping" which is the behavior you are seeing.

You will need to

- Stop filebeat
- cleanup / delete the index in Kibana
- run `filebeat setup -e`
- start filebeat to reload the data.

Note filebeat will not reload a file it has already loaded unless you clean out the filebeat `data` directory

---

<div class="post-metadata">

**Author:** ![AnotherGuy](https://avatars.discourse-cdn.com/v4/letter/a/d9b06d/32.png) [@AnotherGuy](https://discuss.elastic.co/u/AnotherGuy)\
**Post date:** [June 24, 2022, 3:19pm UTC](https://discuss.elastic.co/t/index-problem-keyword/308112/4 "2022-06-24T15:19:13Z")

</div>

Ok i do that but for the **sudo filebeat setup -e** i modif my filebeat.yml  
i comment logstash.output and uncomment elasticsearch.output, but setup the filbeat i can uncomment my logstash.output ?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 24, 2022, 3:40pm UTC](https://discuss.elastic.co/t/index-problem-keyword/308112/5 "2022-06-24T15:40:11Z")

</div>

Ok 🙂

You did not say you were using logstash in the middle so there is more to do...

> [@AnotherGuy](#):
>
> but setup the filbeat i can uncomment my logstash.output ?

Yes comment out the logstash output during setup and set elasticsearch output.  
Then comment out the elasticsearch output and uncomment the logstash output when running through logstash.

I usually _ **highly** _ recommend to get everything working using the direct architecture.

Filebeat -\> Elasticsearch

Before trying and moving on to the more complex architecture.

Filebeat -\> logstash -\> Elasticsearch

Also since you are using logstash your pipeline needs to be "filebeat" aware please see [this doc](https://www.elastic.co/guide/en/logstash/7.17/use-ingest-pipelines.html)

You pipeline should look something like

```auto
input {
  beats {
    port => 5044
  }
}

output {
  if [@metadata][pipeline] {
    elasticsearch {
      hosts => "http://yourhost:9200"
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
      pipeline => "%{[@metadata][pipeline]}" 
      user => "elastic"
      password => "secret"
    }
  } else {
    elasticsearch {
      hosts => "http://yourhost:9200"
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
      user => "elastic"
      password => "secret"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![AnotherGuy](https://avatars.discourse-cdn.com/v4/letter/a/d9b06d/32.png) [@AnotherGuy](https://discuss.elastic.co/u/AnotherGuy)\
**Post date:** [June 24, 2022, 3:49pm UTC](https://discuss.elastic.co/t/index-problem-keyword/308112/6 "2022-06-24T15:49:12Z")

</div>

I have that

```auto
input {
  beats {
    port => 5044
    id => "from_filebeat"
  }
}

output {
  elasticsearch {
    hosts => ["http://192.168.66.11:9200"]
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
    #user => "elastic"
    #password => "changeme"
  }
}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 24, 2022, 3:51pm UTC](https://discuss.elastic.co/t/index-problem-keyword/308112/7 "2022-06-24T15:51:45Z")

</div>

Yup but if you ever use a module with a pipeline that will not work / support it.  
If you are not using a module or pipeline you are fine.. The if / else supports both.

You should add the

`manage_template => false`

Ohh @AnotherGuy Welcome to the community!

---

<div class="post-metadata">

**Author:** ![AnotherGuy](https://avatars.discourse-cdn.com/v4/letter/a/d9b06d/32.png) [@AnotherGuy](https://discuss.elastic.co/u/AnotherGuy)\
**Post date:** [June 24, 2022, 3:58pm UTC](https://discuss.elastic.co/t/index-problem-keyword/308112/8 "2022-06-24T15:58:26Z")

</div>

I got a new problem with my stream log because i removed  
-/var/lib/filebeat/registry/filebeat/\*  
-/var/log/filebeat/\*

I try to resolve it and i'll be back.  
Thank for the help

---

<div class="post-metadata">

**Author:** ![AnotherGuy](https://avatars.discourse-cdn.com/v4/letter/a/d9b06d/32.png) [@AnotherGuy](https://discuss.elastic.co/u/AnotherGuy)\
**Post date:** [July 6, 2022, 12:32pm UTC](https://discuss.elastic.co/t/index-problem-keyword/308112/10 "2022-07-06T12:32:00Z")

</div>

Okay i resolv the problem, i removed filebeat & follow the install [Filebeat quick start: installation and configuration | Filebeat Reference [7.17] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/7.17/filebeat-installation-configuration.html)

after the setup it's work's !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2022, 12:32pm UTC](https://discuss.elastic.co/t/index-problem-keyword/308112/11 "2022-08-03T12:32:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
