# Is there a chance to reset the settings screen of infrastructure?

**URL:** <https://discuss.elastic.co/t/is-there-a-chance-to-reset-the-settings-screen-of-infrastructure/217206>\
**Category:** Metrics\
**Created:** [January 30, 2020, 2:12pm UTC](https://discuss.elastic.co/t/is-there-a-chance-to-reset-the-settings-screen-of-infrastructure/217206 "2020-01-30T14:12:47Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Peter\_Steenbergen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_steenbergen/32/22888_2.png) [@Peter\_Steenbergen](https://discuss.elastic.co/u/Peter_Steenbergen)\
**Post date:** [January 30, 2020, 2:12pm UTC](https://discuss.elastic.co/t/is-there-a-chance-to-reset-the-settings-screen-of-infrastructure/217206/1 "2020-01-30T14:12:47Z")

</div>

I used ./metricbeat setup to import the template of metricbeat. However the screen of the settings is blank so I cant select the event.dataset.keyword field over event.dataset field to remove this message.

What would you guys recommend? Is there an easy way to edit the field where to get the data from?

 ![Schermafbeelding 2020-01-30 om 15.09.05](https://us1.discourse-cdn.com/elastic/original/3X/0/6/06278a2a1cfc6868646610ce01e5cfa0b630b223.png) ![Schermafbeelding 2020-01-30 om 15.09.12](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a76f737766fc9ee66a6e38d252883646f93340ba.png)

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [January 30, 2020, 5:01pm UTC](https://discuss.elastic.co/t/is-there-a-chance-to-reset-the-settings-screen-of-infrastructure/217206/2 "2020-01-30T17:01:34Z")

</div>

@Peter_Steenbergen I think what's happened here is that there is an index matching the `metricbeat-*` pattern that doesn't have the mappings applied properly. It's almost like an event was indexed before the mapping template (from `metricbeat setup`) was in place. When that happens Elasticsearch defaults to the `default` mappings which gives you two fields `event.dataset` which is a "text" field and `event.dataset.keyword` which is a "keyword" field. The proper Metricbeat template defines `event.dataset` as a "keyword" field.

The quick fix would be to run `DELETE metricbeat-*` in the console. Then when the next event shows up it will re-create the index with the proper mappings.

---

<div class="post-metadata">

**Author:** ![Peter\_Steenbergen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_steenbergen/32/22888_2.png) [@Peter\_Steenbergen](https://discuss.elastic.co/u/Peter_Steenbergen)\
**Post date:** [January 31, 2020, 3:51pm UTC](https://discuss.elastic.co/t/is-there-a-chance-to-reset-the-settings-screen-of-infrastructure/217206/3 "2020-01-31T15:51:48Z")

</div>

Hmm weird, deleting the index did not get it processed. I gave a server to little rights. so the ILM etc kicked in but not trigger the template. I pushed it manually now.

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [January 31, 2020, 4:29pm UTC](https://discuss.elastic.co/t/is-there-a-chance-to-reset-the-settings-screen-of-infrastructure/217206/4 "2020-01-31T16:29:19Z")

</div>

You're the second case I've seen this week with almost the same issue. It sounds like you're using ILM, is there more details you can provide around how your `metricbeat-*` indices are being managed? I wonder if there is a bug somewhere that's not setting up the indices right?

---

<div class="post-metadata">

**Author:** ![Peter\_Steenbergen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_steenbergen/32/22888_2.png) [@Peter\_Steenbergen](https://discuss.elastic.co/u/Peter_Steenbergen)\
**Post date:** [February 3, 2020, 11:47am UTC](https://discuss.elastic.co/t/is-there-a-chance-to-reset-the-settings-screen-of-infrastructure/217206/5 "2020-02-03T11:47:12Z")

</div>

I will check this out later today or tomorrow. I will stop the monitors connected to it, and connect 1 after one by resetting everything. Best way to find a bug still in beta for the cluster anyways so no big deal (yet) ;).

---

<div class="post-metadata">

**Author:** ![Peter\_Steenbergen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_steenbergen/32/22888_2.png) [@Peter\_Steenbergen](https://discuss.elastic.co/u/Peter_Steenbergen)\
**Post date:** [February 5, 2020, 10:30pm UTC](https://discuss.elastic.co/t/is-there-a-chance-to-reset-the-settings-screen-of-infrastructure/217206/6 "2020-02-05T22:30:37Z")

</div>

It was a bit weird while debugging. How I fixed it was. Stopping all the connected metricbeats as a service (systemctl stop metricbeat). Removed all the indexes, and patterns and index template of metricbeat.

I downloaded the latest update of metricbeat to my osx machine locally and connected to the live location. I ran this afterwards:

```
./metricbeat setup -e 

```

After that I got 2 index patterns of metricbeat-\* and one of which had event.dataset as a text field and subfield of keyword. The second one was the correct one of the needed keyword. Why did there were 2 index patterns after setting it up, I have no clue but after removal of the wrong one, everything works again with no changes on the workers whatsoever.

Can't seem to reproduce it on a new stack, but will try later with a 7.4.2 version and then reupgrade again to see if I can reproduce it.

---

<div class="post-metadata">

**Author:** ![simianhacker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simianhacker/32/3383_2.png) [@simianhacker](https://discuss.elastic.co/u/simianhacker)\
**Post date:** [February 5, 2020, 10:56pm UTC](https://discuss.elastic.co/t/is-there-a-chance-to-reset-the-settings-screen-of-infrastructure/217206/7 "2020-02-05T22:56:50Z")

</div>

@Peter_Steenbergen First off... Thanks for the update! This will help us come up with a work around for other users who might experience this class of issues. I'm going to send this thread to our Beats team and see if they have any insights.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 4, 2020, 11:00pm UTC](https://discuss.elastic.co/t/is-there-a-chance-to-reset-the-settings-screen-of-infrastructure/217206/8 "2020-03-04T23:00:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
