# Kibana doesn't show the numerical tags values

**URL:** <https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053>\
**Category:** Kibana\
**Created:** [August 7, 2015, 3:16pm UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053 "2015-08-07T15:16:06Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [August 7, 2015, 3:16pm UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/1 "2015-08-07T15:16:06Z")

</div>

Hi, I'm sending messages with whis configuration\> 2015/01/06 07:15:43.073;1.849365  
And I'm using this grok filter in logstash\>

grok{  
match =\> { "message" =\> "%{YEAR:year}/%{MONTHNUM:monthnum}/%{MONTHDAY:monthday} %{TIME:time};%{NUMBER:Value}"}  
add\_field =\> ["datetime", "%{year}/%{monthnum}/%{monthday} %{time}"]  
}  
date{  
match =\> ["datetime", "yyyy/MM/dd HH:mm:ss"]  
}  
}

So at the end, what I have is the tags with it value in Kibana3, all right..  
The problem is that when I try to represent the numerical value of the tag "Value" it doesn't show me anything... I'm trying using a histogram in this way.. but it doesn't appear anything.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/3/39cb4e05bbe22362baf4c4458dc9d028d603789c.PNG)

In fact when I change "Chart Value" to Count it shows me correctly, but I want the total value

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 7, 2015, 3:46pm UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/2 "2015-08-07T15:46:02Z")

</div>

Use `%{NUMBER:Value:int}` instead of `%{NUMBER:Value}`. That field has already been mapped as a string so it might take until tomorrow's data until Kibana works as you'd expect (unless you reindex).

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [August 7, 2015, 3:55pm UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/3 "2015-08-07T15:55:40Z")

</div>

Hi!  
I have used "Float" instead integer... but I'm having the same problem with the visualization... it is no able to show me the value in the Y axis

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 7, 2015, 3:56pm UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/4 "2015-08-07T15:56:57Z")

</div>

Check how the field has been mapped for the index in question (use ES's get mapping API). That's what matters.

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [August 7, 2015, 4:06pm UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/5 "2015-08-07T16:06:24Z")

</div>

It seems that it is considering it as a string...  
I have used : localhost:9200/\_mapping for seeing it. Is that right?  
"Value":{"type":"multi\_field","fields":{"Value":{"type":"string","omit\_norms":true},"raw":{"type":"string","index":"not\_analyzed","omit\_norms":true,"index\_options":"docs","include\_in\_all":false,"ignore\_above":256}}},"datetime":{"type":"multi\_field","fields":{"datetime":{"type":"string","omit\_norms":true},"raw":

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 7, 2015, 6:24pm UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/6 "2015-08-07T18:24:42Z")

</div>

Yes, it's a string. You're presumably using daily indexes, so the next index you create should see the `Value` field correctly mapped.

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [August 10, 2015, 6:43am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/7 "2015-08-10T06:43:06Z")

</div>

Thanks for your response Magnus, How could I do it?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 10, 2015, 6:51am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/8 "2015-08-10T06:51:19Z")

</div>

The field in today's index should be mapped as a number rather than a string so there's not much for you to do.

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [August 10, 2015, 7:19am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/9 "2015-08-10T07:19:12Z")

</div>

Indexes from today have the same problem.. I've had to add a mutate sentence in the logstash configuration filter.  
mutate {  
convert =\> { "Value" =\> "float" }  
}

but I though that only with the grok filter sentence %{NUMBER:Value:float} would be enough..

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 10, 2015, 7:32am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/10 "2015-08-10T07:32:36Z")

</div>

Yes, `%{NUMBER:Value:float}` should've been enough. Can you create a minimal configuration example that exhibits the problem?

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [August 10, 2015, 7:48am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/11 "2015-08-10T07:48:06Z")

</div>

My filter is this one:  
filter {  
if [type] == "udp" {  
mutate {  
rename =\> ["@host", "host"]  
}  
dns {  
reverse =\> ["host"]  
action =\> "replace"  
}  
grok{  
match =\> {"message" =\> "%{YEAR:year}/%{MONTHNUM:monthnum}/%{MONTHDAY:monthday} %{TIME:time};%{NUMBER:Value:float}"}  
add\_field =\> ["datetime", "%{year}/%{monthnum}/%{monthday} %{time}"]  
}  
date{  
match =\> ["datetime", "yyyy/MM/dd HH:mm:ss"]  
}

```
   **mutate {**
        **convert => { "Value" => "float" }**
    **}**

}

```

}

and the messages have this structure \> 1970/01/06 08:44:45.304;2.098389

In fact when I use the grok debugger it shows me as a string too.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/aaec5c98cfe3e9acb266f91bb1ef8804996bf407.PNG)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 10, 2015, 7:55am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/12 "2015-08-10T07:55:24Z")

</div>

Works fine for me without the extra mutate filter:

```
$ cat data
1970/01/06 08:44:45.304;2.098389
$ cat test.config 
input { stdin { codec => plain } }
output { stdout { codec => rubydebug } }
filter {
  grok {
    match => [
      "message",
      "%{YEAR:year}/%{MONTHNUM:monthnum}/%{MONTHDAY:monthday} %{TIME:time};%{NUMBER:Value:float}"
    ]
  }
}
$ /opt/logstash/bin/logstash -f test.config < data
{
       "message" => "1970/01/06 08:44:45.304;2.098389",
      "@version" => "1",
    "@timestamp" => "2015-08-10T07:53:29.625Z",
          "host" => "seldlx20533",
          "year" => "1970",
      "monthnum" => "01",
      "monthday" => "06",
          "time" => "08:44:45.304",
         "Value" => 2.098389
}

```

Which version of Logstash are you running? Your reference to the `@host` field suggests that you're running something really ancient.

---

<div class="post-metadata">

**Author:** ![Raul\_Uria](https://avatars.discourse-cdn.com/v4/letter/r/76d3ee/32.png) [@Raul\_Uria](https://discuss.elastic.co/u/Raul_Uria)\
**Post date:** [August 10, 2015, 8:16am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/13 "2015-08-10T08:16:26Z")

</div>

> [@magnusbaeck](#):
>
> 2.0983

Hi @magnusbaeck, you´re showing logstash output here, but I think this is not the same as ES mapping.

Sometimes I saw the same behaviour, I think "data types" inside logstash´s pipeline are not related (almost directly) with "data types" in ES since logstash is not defining the mappings in a explicit way, am I right? ES has its own mechanisms for detecting types automatically.

Something like 2.098389 should be detected as float in ES, but this is not the case. Are you using templates? ( use this: [http://localhost:9200/\_template?pretty](http://localhost:9200/_template?pretty) )

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 10, 2015, 8:31am UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/14 "2015-08-10T08:31:59Z")

</div>

Indeed, if the OP is using an index template that maps the `Value` field as a string then that's indeed the problem, but I don't think that's the case. If the first `Value` field seen by ES for a given index is a float it will be mapped as a float.

Since the OP indicates that it works if a mutate filter that explicitly converts the field to a float then the problem seems to be on the Logstash side after all.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:15pm UTC](https://discuss.elastic.co/t/kibana-doesnt-show-the-numerical-tags-values/27053/15 "2017-07-06T14:15:07Z")

</div>


