# Kibana-4.6.4 have an issues with datatables where fields is containing string values

**URL:** <https://discuss.elastic.co/t/kibana-4-6-4-have-an-issues-with-datatables-where-fields-is-containing-string-values/90271>\
**Category:** Kibana\
**Created:** [June 21, 2017, 11:13am UTC](https://discuss.elastic.co/t/kibana-4-6-4-have-an-issues-with-datatables-where-fields-is-containing-string-values/90271 "2017-06-21T11:13:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![yash\_mangla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yash_mangla/32/25889_2.png) [@yash\_mangla](https://discuss.elastic.co/u/yash_mangla)\
**Post date:** [June 21, 2017, 11:13am UTC](https://discuss.elastic.co/t/kibana-4-6-4-have-an-issues-with-datatables-where-fields-is-containing-string-values/90271/1 "2017-06-21T11:13:01Z")

</div>

Hi Guys,

I have an issue with kibana-4.6.4 datatables. can you help how can i modify the setting as latest kibana have  
In development server we are using

elasticsearch-2.x version  
kibana-4.x version

In visualization datatables it's showing like

 ![](https://us1.discourse-cdn.com/elastic/original/3X/7/7/77ae0c33677014f7bf481ef3ba8fa8d08cdb6ca7.PNG)

In above screen is showing only one random word per row instead of sentence.

On Other Side with same data and same fields in latest kibana showing pretty good.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/4/84fc1d5ce9cdec64c593ce9d274b87fb7ca4b0fb.PNG)

it's showing complete sentences per row as i expected instead of random words per row.

I want to visualize complete sentence per row in kibana-4.6.4 instead of words. I can't use latest distribution of elk stack due to some latest os version dependency issues on development server.

I just want this functionality in kibana-4.6.4 version how can i acheive this. please suggest me right way to do it ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 21, 2017, 4:39pm UTC](https://discuss.elastic.co/t/kibana-4-6-4-have-an-issues-with-datatables-where-fields-is-containing-string-values/90271/2 "2017-06-21T16:39:44Z")

</div>

In Kibana 4.6.4 it looks like you are aggregating over an analysed field, which is why you see individual tokens in the table. If you are using standard Logstash mappings, there should be a non-analysed version of the field available as `errMsg.raw`. If you use this you should see the same behaviour as in Kibana 5.x.

---

<div class="post-metadata">

**Author:** ![yash\_mangla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yash_mangla/32/25889_2.png) [@yash\_mangla](https://discuss.elastic.co/u/yash_mangla)\
**Post date:** [July 6, 2017, 8:37am UTC](https://discuss.elastic.co/t/kibana-4-6-4-have-an-issues-with-datatables-where-fields-is-containing-string-values/90271/3 "2017-07-06T08:37:13Z")

</div>

Hi @Christian_Dahlqvist,

But i'm using **logstash** to **parse the logs**. i **wrote a script** which **parse the existing logs** and pushed into **elasticsearch**. then i connect to kibana.

i found this configuration regarding `errMsg.raw` mapping [https://github.com/elastic/logstash/blob/v1.3.1/lib/logstash/outputs/elasticsearch/elasticsearch-template.json](https://github.com/elastic/logstash/blob/v1.3.1/lib/logstash/outputs/elasticsearch/elasticsearch-template.json)

but i don't know how can i use this configuration and where to use it which helps i can create `errMsg.raw` fields.

give me some hint or sample example in right direction.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 6, 2017, 9:20am UTC](https://discuss.elastic.co/t/kibana-4-6-4-have-an-issues-with-datatables-where-fields-is-containing-string-values/90271/4 "2017-07-06T09:20:55Z")

</div>

The best way would be to create an [index template](https://www.elastic.co/guide/en/elasticsearch/reference/2.4/indices-templates.html), which defines the mappings when the index is first created. The template you linked to is an example, though from a very old version of Logstash. [This](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template-es2x.json) may be a better starting point.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2017, 9:21am UTC](https://discuss.elastic.co/t/kibana-4-6-4-have-an-issues-with-datatables-where-fields-is-containing-string-values/90271/5 "2017-08-03T09:21:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
