# Kibana Dev Tools Get Field names from .kibana index

**URL:** <https://discuss.elastic.co/t/kibana-dev-tools-get-field-names-from-kibana-index/254990>\
**Category:** Kibana\
**Created:** [November 10, 2020, 11:09pm UTC](https://discuss.elastic.co/t/kibana-dev-tools-get-field-names-from-kibana-index/254990 "2020-11-10T23:09:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cwobuzz](https://avatars.discourse-cdn.com/v4/letter/c/e0b2c6/32.png) [@cwobuzz](https://discuss.elastic.co/u/cwobuzz)\
**Post date:** [November 10, 2020, 11:09pm UTC](https://discuss.elastic.co/t/kibana-dev-tools-get-field-names-from-kibana-index/254990/1 "2020-11-10T23:09:04Z")

</div>

Team,

I tried to figure this out, but I am new to using the dev tools. I am using SecOnion. I want to pull out the fields mapped to different event ids. I spent a good amount of time trying to google an answer, but I didn't find a good thread. If there is something close please point me in that direction. This is what I tried, and failed at:

GET .kibana/\_doc/index-pattern:2289a0c0-6970-11ea-a0cd-ffa0f6a1bc29/\_search  
{  
"query" : {  
"match" : {  
"event.id" : "1"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 10, 2020, 11:20pm UTC](https://discuss.elastic.co/t/kibana-dev-tools-get-field-names-from-kibana-index/254990/2 "2020-11-10T23:20:53Z")

</div>

Welcome to our community! 😃

> [@cwobuzz](#):
>
> I want to pull out the fields mapped to different event ids

Can you elaborate a little more on this part, what do you mean exactly?

---

<div class="post-metadata">

**Author:** ![cwobuzz](https://avatars.discourse-cdn.com/v4/letter/c/e0b2c6/32.png) [@cwobuzz](https://discuss.elastic.co/u/cwobuzz)\
**Post date:** [November 12, 2020, 4:05pm UTC](https://discuss.elastic.co/t/kibana-dev-tools-get-field-names-from-kibana-index/254990/3 "2020-11-12T16:05:31Z")

</div>

warkolm, thanks for getting back to me so fast. I thought this would take more time. I have used kibana it's self but have not gotten into the dev tools before. So I will will paste in returned code so hopefully you can follow what I am asking about. I think I may need to take the .kibana index and reindex it so it can be sorted. I can't figure out how to that. Thanks for the help. 🙂

{  
"\_index" : ".kibana\_1",  
"\_type" : "\_doc",  
"\_id" : "index-pattern:2289a0c0-6970-11ea-a0cd-ffa0f6a1bc29",  
"\_version" : 52,  
"\_seq\_no" : 34384,  
"\_primary\_term" : 9,  
"found" : true,  
"\_source" : {  
"index-pattern" : {  
"fieldFormatMap" : """{"network.community\_id":{"id":"url","params":{"parsedUrl":{"origin":"[https://removed.com](https://removed.com)","pathname":"/kibana/app/kibana","basePath":"/kibana"} # I am cutting out the rest of this field

## This field called "fields has the data in it that I want to map out.

"fields" : """[{"name":"@timestamp","type":"date","esTypes":["date"],"count":0,"scripted":false,"searchable":true,"aggregatable":true,"readFromDocValues":true}, #This also goes on for quite some time but it contains all the fields I want.

## I want to filter them on a field called "even.id" The dumped field names would look something like that:

@timestamp  
@version  
agent.ephemeral\_id  
agent.hostname  
agent.id  
agent.ip  
agent.name  
agent.type  
agent.version  
destination.geo.continent\_name  
destination.geo.country\_iso\_code  
destination.geo.country\_name  
destination.geo.ip

## Rest of the code not sure if it's import to you

```
  "timeFieldName" : "@timestamp",
  "title" : "*:so-*"
},
"type" : "index-pattern",
"references" : [],
"migrationVersion" : {
  "index-pattern" : "7.6.0"
},
"updated_at" : "2020-11-12T15:13:11.332Z"

```

}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 10, 2020, 4:05pm UTC](https://discuss.elastic.co/t/kibana-dev-tools-get-field-names-from-kibana-index/254990/4 "2020-12-10T16:05:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
