# Kibana search pattern help

**URL:** https://discuss.elastic.co/t/kibana-search-pattern-help/151067
**Category:** Kibana
**Created:** [October 4, 2018, 2:55pm UTC](https://discuss.elastic.co/t/kibana-search-pattern-help/151067 "2018-10-04T14:55:31Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![pradeepbill7](https://avatars.discourse-cdn.com/v4/letter/p/94ad74/32.png) [@pradeepbill7](https://discuss.elastic.co/u/pradeepbill7)
#### Post date: [October 4, 2018, 2:55pm UTC](https://discuss.elastic.co/t/kibana-search-pattern-help/151067/1 "2018-10-04T14:55:31Z")

</div>

Hello there, I am using ELK6.4 stack, I have data like the attached picture, and the search works only if I give like this "headers.direction:external" , but i need it to work when i give "direction:external", I am searching from Kibana.Please advice.

Thanks  
Pradeep! ![Untitled%206](https://us1.discourse-cdn.com/elastic/original/3X/3/2/32d3f18e9ec3729a2549143c0eca2bea796774a2.png)

---

<div class="post-metadata">

### Author: ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)
#### Post date: [October 5, 2018, 2:24pm UTC](https://discuss.elastic.co/t/kibana-search-pattern-help/151067/2 "2018-10-05T14:24:47Z")

</div>

hi @pradeepbill7

The search looks at the field name. so it seems you like to change the `headers.direction` field to be renamed as `direction`. You'll likely want to index your documents with the correct fieldname `direction`.

---

<div class="post-metadata">

### Author: ![pradeepbill7](https://avatars.discourse-cdn.com/v4/letter/p/94ad74/32.png) [@pradeepbill7](https://discuss.elastic.co/u/pradeepbill7)
#### Post date: [October 5, 2018, 2:59pm UTC](https://discuss.elastic.co/t/kibana-search-pattern-help/151067/3 "2018-10-05T14:59:54Z")

</div>

thanks thomas, I can not upate the index, as it is being used by many other applications, Can I update the elastic template to somehow search direction:value , when headers.direction:value is used ?, like a pattern saying , when headers.\* is searched , either strip "headers" from the query, or go look under headers.

---

<div class="post-metadata">

### Author: ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)
#### Post date: [October 6, 2018, 6:50pm UTC](https://discuss.elastic.co/t/kibana-search-pattern-help/151067/4 "2018-10-06T18:50:59Z")

</div>

hi @pradeepbill7,

If you cannot reindex, I would look at adding a field alias to your index. [https://www.elastic.co/guide/en/elasticsearch/reference/master/alias.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/alias.html). You can add one for the fields you would like to rename.

---

<div class="post-metadata">

### Author: ![pradeepbill7](https://avatars.discourse-cdn.com/v4/letter/p/94ad74/32.png) [@pradeepbill7](https://discuss.elastic.co/u/pradeepbill7)
#### Post date: [October 7, 2018, 3:29pm UTC](https://discuss.elastic.co/t/kibana-search-pattern-help/151067/5 "2018-10-07T15:29:24Z")

</div>

thanks Thomas, we are using elastic 6.3 , I tried the example at [https://www.elastic.co/guide/en/elasticsearch/reference/master/alias.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/alias.html) , and it throws error like below, is there something I have to enable to get the field level aliases to work ?

{

· "error": {

o "root\_cause": [

§ {

§ "type": "mapper\_parsing\_exception",

§ "reason": "No handler for type [alias] declared on field [route\_length\_miles]"

}

o ],

o "type": "mapper\_parsing\_exception",

o "reason": "Failed to parse mapping [\_doc]: No handler for type [alias] declared on field [route\_length\_miles]",

o "caused\_by": {

§ "type": "mapper\_parsing\_exception",

§ "reason": "No handler for type [alias] declared on field [route\_length\_miles]"

}

· },

· "status": 400

}

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 4, 2018, 3:29pm UTC](https://discuss.elastic.co/t/kibana-search-pattern-help/151067/6 "2018-11-04T15:29:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
