# Kibana not recognizing integer fields

**URL:** <https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387>\
**Category:** Kibana\
**Created:** [July 28, 2015, 6:42am UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387 "2015-07-28T06:42:23Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![foresightyj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/foresightyj/32/3666_2.png) [@foresightyj](https://discuss.elastic.co/u/foresightyj)\
**Post date:** [July 28, 2015, 6:42am UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/1 "2015-07-28T06:42:23Z")

</div>

My logstash index's mapping looks like this:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/7/70856a3c2ac3f0093b104eb95fb22842d3e5e6ad.png)

Clearly `time_taken` is an `long` integer field. But Kibana is not recognizing this field as a number field and throws me errors like **No Compatible Fields: The "logstash-\*" index pattern does not contain any of the following field types: number** in a `range` aggregration.

![](https://us1.discourse-cdn.com/elastic/original/2X/f/ffb50283ca120175589c9a979d257fe1286291ac.png)

If I choose a `terms` aggregation,

![](https://us1.discourse-cdn.com/elastic/original/2X/7/7a083d8100f34d2c71e85264131edd0d044e642f.png)  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/8/8864fa7ad33279b87e3118fc6ba33bb967de2a0c.png)

It will show that all fields except for `@time_stamp` is a `string` field.

---

<div class="post-metadata">

**Author:** ![RyanD1](https://avatars.discourse-cdn.com/v4/letter/r/c0e974/32.png) [@RyanD1](https://discuss.elastic.co/u/RyanD1)\
**Post date:** [July 29, 2015, 8:15pm UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/2 "2015-07-29T20:15:05Z")

</div>

I had the same issue before. The problem was that I set up the Kibana index with the wrong ElasticSearch mappings. Later when I changed the mappings in ES, Kibana remains wrong. I don't know if that could be your issue, but check in Kibana/Settings and see if the types from that index is correct.

---

<div class="post-metadata">

**Author:** ![Rubaiyat\_Islam\_Sadat](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@Rubaiyat\_Islam\_Sadat](https://discuss.elastic.co/u/Rubaiyat_Islam_Sadat)\
**Post date:** [July 30, 2015, 8:29am UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/3 "2015-07-30T08:29:08Z")

</div>

Hi I have the same problem as the main post. I also checked the Kibana/Settings and it seems that the long field is actually in conflict state. @RyanD1 would you please explain a bit what you did with mappings and Kibana remains wrong because I think I have hit the same problem

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [July 30, 2015, 2:09pm UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/4 "2015-07-30T14:09:35Z")

</div>

Refreshing the mappings in the index pattern using the "Refresh" should help. If not, maybe try to delete your index pattern and re-add it?

---

<div class="post-metadata">

**Author:** ![RyanD1](https://avatars.discourse-cdn.com/v4/letter/r/c0e974/32.png) [@RyanD1](https://discuss.elastic.co/u/RyanD1)\
**Post date:** [July 30, 2015, 2:19pm UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/5 "2015-07-30T14:19:36Z")

</div>

Yeah so when I first setup Kibana, the existing ES index mapping was wrong so Kibana read the wrong settings and copied them. Later I changed ES mapping, but Kibana wasn't "smart" enough to detect it and sync up. What I did was simply delete and re-add the index in Kibana so it will read the right mappings.

---

<div class="post-metadata">

**Author:** ![Rubaiyat\_Islam\_Sadat](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@Rubaiyat\_Islam\_Sadat](https://discuss.elastic.co/u/Rubaiyat_Islam_Sadat)\
**Post date:** [August 14, 2015, 1:10pm UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/6 "2015-08-14T13:10:25Z")

</div>

Thanks mate! Sorry for the late reply. Let me go through your workaround and will post my results

---

<div class="post-metadata">

**Author:** ![foresightyj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/foresightyj/32/3666_2.png) [@foresightyj](https://discuss.elastic.co/u/foresightyj)\
**Post date:** [August 20, 2015, 8:35am UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/7 "2015-08-20T08:35:47Z")

</div>

Yes. Clicking refresh has always worked for me since I tried. Thanks 😄

---

<div class="post-metadata">

**Author:** ![Rubaiyat\_Islam\_Sadat](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@Rubaiyat\_Islam\_Sadat](https://discuss.elastic.co/u/Rubaiyat_Islam_Sadat)\
**Post date:** [August 20, 2015, 9:15am UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/8 "2015-08-20T09:15:08Z")

</div>

I tried to simply delete and re-add the index in Kibana, but didn't work. I also tried to reload the fields (this is what is meant by "Refresh", right?), also didn't work. My situation is such:  
I have two fields, let's name them, "status" and "duration", and both of them are in conflict state. Both the fields should be integer, but instead they are in conflict state. Is there any possibility that the events that are flowing from the logstash-forwarders are actually having those fields in different value types (i.e. sometimes as string and sometimes integer)? Or is it a really related to mapping? I am a bit newbie and the mapping was done by some other guy who left.

---

<div class="post-metadata">

**Author:** ![foresightyj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/foresightyj/32/3666_2.png) [@foresightyj](https://discuss.elastic.co/u/foresightyj)\
**Post date:** [August 21, 2015, 12:59am UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/9 "2015-08-21T00:59:49Z")

</div>

You can check the actual mapping of the index to check actual types of your fields.

```
GET YOUR_IP:YOUR_PORT/logstash-xxx/_mapping
```

---

<div class="post-metadata">

**Author:** ![Rubaiyat\_Islam\_Sadat](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@Rubaiyat\_Islam\_Sadat](https://discuss.elastic.co/u/Rubaiyat_Islam_Sadat)\
**Post date:** [August 21, 2015, 7:50am UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/10 "2015-08-21T07:50:24Z")

</div>

Thanks mate! the curling told me that the fields are of type "long"

---

<div class="post-metadata">

**Author:** ![James\_Dickens](https://avatars.discourse-cdn.com/v4/letter/j/51bf81/32.png) [@James\_Dickens](https://discuss.elastic.co/u/James_Dickens)\
**Post date:** [November 11, 2015, 5:32am UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/11 "2015-11-11T05:32:34Z")

</div>

facing same issue, removed all indexes, verified that all files and traces of the files are gone.

here is my mapping

{"my-stuff":{"mappings":{"filedetails":{"properties":{"atime":{"type":"double"},"ctime":{"type":"double"},"gid":{"type":"long"},"mode":{"type":"long"},"mtime":{"type":"double"},"name":{"type":"string"},"size":{"type":"long"},"uid":{"type":"long"}}}}}}

is some other index that is part of logstash effecting this?

I have been unable to force mappings on this, yes i'm a noob.

here is the code generating the json, in python

def insert\_record(js):  
global es  
rec=dict()  
doc = json.dumps(js, ensure\_ascii=True)  
res = es.index(index=INDEX, doc\_type='filedetails', body=doc)

def store\_file(f):  
mode=os.stat(f).st\_mode  
#nlink=os.stat(f).st\_nlink  
uid=os.stat(f).st\_uid  
gid=os.stat(f).st\_gid  
size=os.stat(f).st\_size  
atime=os.stat(f).st\_atime  
mtime=os.stat(f).st\_mtime  
ctime=os.stat(f).st\_ctime  
js = {  
'name' : f,  
'mode' : mode,  
'uid' : uid,  
'gid' : gid,  
'size' : size,  
'atime' : atime,  
'mtime' : mtime,  
'ctime' : ctime  
}  
insert\_record(js)

any feedback about how to get this working? or a working index creation json would be welcome. Not sure why something this simple is causing the issue, long isn't exactly a foreign variable type these days?

---

<div class="post-metadata">

**Author:** ![bonatakis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bonatakis/32/6164_2.png) [@bonatakis](https://discuss.elastic.co/u/bonatakis)\
**Post date:** [November 25, 2015, 1:39pm UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/12 "2015-11-25T13:39:56Z")

</div>

I would like to know if Kibana keeps the old fields after refresh? it seems it does and this causes a conflict in my indices. Any idea how to handle this?

---

<div class="post-metadata">

**Author:** ![toddiuszho](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/toddiuszho/32/5471_2.png) [@toddiuszho](https://discuss.elastic.co/u/toddiuszho)\
**Post date:** [December 23, 2015, 12:15am UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/13 "2015-12-23T00:15:18Z")

</div>

Does the integer have to be indexed to be be aggregated in Kibana? My integer property has index: no.

---

<div class="post-metadata">

**Author:** ![Rubaiyat\_Islam\_Sadat](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@Rubaiyat\_Islam\_Sadat](https://discuss.elastic.co/u/Rubaiyat_Islam_Sadat)\
**Post date:** [March 9, 2016, 7:27am UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/14 "2016-03-09T07:27:45Z")

</div>

As far as I understand, the conflict occurs when the same field has different types across all the documents. So even if you refresh the fields in Kibana, the field will be in conflict state. Kibana does NOT keep old fields after refresh, it's all by elasticsearch. Only way to deal with it I have found so far is to reindex ☹

---

<div class="post-metadata">

**Author:** ![Rubaiyat\_Islam\_Sadat](https://avatars.discourse-cdn.com/v4/letter/r/958977/32.png) [@Rubaiyat\_Islam\_Sadat](https://discuss.elastic.co/u/Rubaiyat_Islam_Sadat)\
**Post date:** [March 9, 2016, 7:28am UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/15 "2016-03-09T07:28:21Z")

</div>

yes, to be aggregated

---

<div class="post-metadata">

**Author:** ![kadishmal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kadishmal/32/12307_2.png) [@kadishmal](https://discuss.elastic.co/u/kadishmal)\
**Post date:** [October 5, 2016, 2:34pm UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/16 "2016-10-05T14:34:50Z")

</div>

Why does a numeric field need to be indexed in order to be aggregated in Kibana? When storing metrics, we don't need to index numeric fields since the only way we access them is via aggregations which don't care about numeric fields being indexed or not.

Here is a related issue [https://github.com/elastic/kibana/issues/3650](https://github.com/elastic/kibana/issues/3650).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:37pm UTC](https://discuss.elastic.co/t/kibana-not-recognizing-integer-fields/26387/17 "2017-07-06T13:37:32Z")

</div>


