# Invalid data view without timeFieldName

**URL:** <https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046>\
**Category:** Kibana\
**Tags:** elastic-stack-alerting\
**Created:** [November 2, 2022, 7:47pm UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046 "2022-11-02T19:47:46Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![breakingcode](https://avatars.discourse-cdn.com/v4/letter/b/858c86/32.png) [@breakingcode](https://discuss.elastic.co/u/breakingcode)\
**Post date:** [November 2, 2022, 7:47pm UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046/1 "2022-11-02T19:47:46Z")

</div>

Hi, I am trying to configure alerts from Kibana console. I using the option from Stack Management -\> Rules and Connector. I want to create the alert for documents in es index. For example: If I index the document where "salary" property is less or equal to some number then I want to trigger an action. When I test my rule in the console its working and returning the documents.

I want to use Index connector i.e I want to store the alert info in es index. I used below index to index in the alert info

```auto
{
  "alerts_id":"{{alert.id}}",
  "@timestamp":"{{conext.timestamp}}"
}

```

The es index for which I want to configure alerts, contains only id, name, salary properties.

When I run my rule I get below error  
`Invalid data view without timeFieldName`

I am confused, which index it is talking about, if is it mandatory to use timeFieldName in one of the index. I just started to learn Kibana , couldn't find anything related to this in document.

Thanks

---

<div class="post-metadata">

**Author:** ![jcger](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jcger](https://discuss.elastic.co/u/jcger)\
**Post date:** [November 3, 2022, 7:42am UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046/2 "2022-11-03T07:42:10Z")

</div>

Welcome to our community!

Could you please provide the Kibana version you are using? Also, there is a typo in your document to index snippet, "conext.timestamp" instead of "context.timestamp" which might be the reason behind the error.

---

<div class="post-metadata">

**Author:** ![breakingcode](https://avatars.discourse-cdn.com/v4/letter/b/858c86/32.png) [@breakingcode](https://discuss.elastic.co/u/breakingcode)\
**Post date:** [November 3, 2022, 9:11am UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046/3 "2022-11-03T09:11:05Z")

</div>

I am using 8.4.3 version and that code snippet is a typo I made in question sorry for that!

---

<div class="post-metadata">

**Author:** ![jcger](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jcger](https://discuss.elastic.co/u/jcger)\
**Post date:** [November 3, 2022, 11:03am UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046/4 "2022-11-03T11:03:13Z")

</div>

No problem 🙂

Please check that the Timestamp field is set up properly for the Data View used by the rule. You'll find it under Stack Management \> Data Views and then select the data view and click on edit. Timestamp field should be filled with a field, the most commonly used field is @timestamp, if you cannot choose that field you can add the field in the data view, its type should be date

---

<div class="post-metadata">

**Author:** ![breakingcode](https://avatars.discourse-cdn.com/v4/letter/b/858c86/32.png) [@breakingcode](https://discuss.elastic.co/u/breakingcode)\
**Post date:** [November 3, 2022, 11:40am UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046/5 "2022-11-03T11:40:52Z")

</div>

I couldn't add the @timestamp field through edit option, so I used Add Field option in Data Views and added the @timestamp of type Date, but still not working same error

---

<div class="post-metadata">

**Author:** ![jcger](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jcger](https://discuss.elastic.co/u/jcger)\
**Post date:** [November 3, 2022, 11:44am UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046/6 "2022-11-03T11:44:36Z")

</div>

After creating the timestamp field, did you update the data view to use that field as timestamp field?

---

<div class="post-metadata">

**Author:** ![breakingcode](https://avatars.discourse-cdn.com/v4/letter/b/858c86/32.png) [@breakingcode](https://discuss.elastic.co/u/breakingcode)\
**Post date:** [November 3, 2022, 11:53am UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046/7 "2022-11-03T11:53:03Z")

</div>

I still can't select that field in edit data view option

---

<div class="post-metadata">

**Author:** ![jcger](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jcger](https://discuss.elastic.co/u/jcger)\
**Post date:** [November 3, 2022, 12:07pm UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046/8 "2022-11-03T12:07:07Z")

</div>

Try by removing the @timestamp field (as I think it's a runtime field now) and try by running in the dev console this:

```auto
PUT YOUR_INDEX_NAME/_mapping
{
  "properties": {
    "@timestamp": {
      "type": "date"
    }
  }
}

```

Also, when trying to add the timestamp field make sure it refreshes, to do so you'll have to update the index name by, for example, rewriting it again

---

<div class="post-metadata">

**Author:** ![breakingcode](https://avatars.discourse-cdn.com/v4/letter/b/858c86/32.png) [@breakingcode](https://discuss.elastic.co/u/breakingcode)\
**Post date:** [November 3, 2022, 5:26pm UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046/9 "2022-11-03T17:26:18Z")

</div>

Hi error is gone form rule section, after creating new index with @timestamp I could select the @timestamp field in time field options now, but data view is not showing anything when I add data in index. I am not sending the value for @timestamp field . Do I have to send the timestamp value also, I guess it will indexed automatically. So overall error is gone from rule section but as I am checking the condition on data view and data view is not showing my alerting is not working.

---

<div class="post-metadata">

**Author:** ![jcger](https://avatars.discourse-cdn.com/v4/letter/j/6bbea6/32.png) [@jcger](https://discuss.elastic.co/u/jcger)\
**Post date:** [November 4, 2022, 9:25am UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046/10 "2022-11-04T09:25:40Z")

</div>

Hi, you'll have to populate the @timestamp field in order to make it work

---

<div class="post-metadata">

**Author:** ![breakingcode](https://avatars.discourse-cdn.com/v4/letter/b/858c86/32.png) [@breakingcode](https://discuss.elastic.co/u/breakingcode)\
**Post date:** [November 4, 2022, 10:48am UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046/11 "2022-11-04T10:48:58Z")

</div>

Its working, Thanks 🙏

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 2, 2022, 10:49am UTC](https://discuss.elastic.co/t/invalid-data-view-without-timefieldname/318046/12 "2022-12-02T10:49:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
