# Kibana 4.1 change the Primary\_Field from \_all to something else

**URL:** <https://discuss.elastic.co/t/kibana-4-1-change-the-primary-field-from--all-to-something-else/26587>\
**Category:** Kibana\
**Created:** [July 30, 2015, 6:36pm UTC](https://discuss.elastic.co/t/kibana-4-1-change-the-primary-field-from--all-to-something-else/26587 "2015-07-30T18:36:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![netoben](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/netoben/32/3930_2.png) [@netoben](https://discuss.elastic.co/u/netoben)\
**Post date:** [July 30, 2015, 6:36pm UTC](https://discuss.elastic.co/t/kibana-4-1-change-the-primary-field-from--all-to-something-else/26587/1 "2015-07-30T18:36:16Z")

</div>

Hi Guys

I want to disable the "\_all" field because it consumes too much space and I really don't have a use for it. However Kibana 4.1 seems to default to that field for Visualization queries.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/9/961984572caa5862e3e8702e1f03c92b0234d3a7.png)

I found an old topic that said modifying the KibanaConfig.rb file and set up the Primary\_field = "\_all" to Primary\_field = "message" would do the trick.

However, I cannot find the KibanaConfig.rb anywhere in my installation.

Was it removed in this version? If so ... how can I change that behavior?

Thanks!

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [August 12, 2015, 12:12am UTC](https://discuss.elastic.co/t/kibana-4-1-change-the-primary-field-from--all-to-something-else/26587/2 "2015-08-12T00:12:32Z")

</div>

If you're looking at instructions mentioning KibanaConfig.rb, they are for a very old (original?) version of Kibana and are no longer current. When working with Kibana 4, you can disable the \_all field in your Elasticsearch mappings and that will not affect your Kibana functionality.

The \_all in the legend in your screenshots refers to "all returned documents". I see how this nomenclature may be a bit confusing, so I filed a Github ticket ticket with a "discuss" label on your behalf: [https://github.com/elastic/kibana/issues/4642](https://github.com/elastic/kibana/issues/4642)

---

<div class="post-metadata">

**Author:** ![netoben](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/netoben/32/3930_2.png) [@netoben](https://discuss.elastic.co/u/netoben)\
**Post date:** [August 12, 2015, 6:47pm UTC](https://discuss.elastic.co/t/kibana-4-1-change-the-primary-field-from--all-to-something-else/26587/3 "2015-08-12T18:47:22Z")

</div>

That makes sense, thank you!

I actually reinstalled my test environment and I started seeing all documents in my queries again.

At first I could not see any documents and I found this article so I assumed that was my problem. I later reinstalled my test environment and everything started working, so I guess there was another problem there.

Again, thanks and I'll follow up that discussion.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:14pm UTC](https://discuss.elastic.co/t/kibana-4-1-change-the-primary-field-from--all-to-something-else/26587/4 "2017-07-06T14:14:55Z")

</div>


