# Kibana shows fields are not searchable and aggregatable

**URL:** <https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148>\
**Category:** Kibana\
**Created:** [June 13, 2017, 7:20am UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148 "2017-06-13T07:20:09Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![CaptainFeng](https://avatars.discourse-cdn.com/v4/letter/c/e79b87/32.png) [@CaptainFeng](https://discuss.elastic.co/u/CaptainFeng)\
**Post date:** [June 13, 2017, 7:20am UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/1 "2017-06-13T07:20:10Z")

</div>

Hi All

After upgrading from 2.x, all my fields(including raw) are not searchable and aggregatable.

Please help me to figure out why this happens?

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88c8636e30d665ca5d767b1169eaf6d725447e7d.png)

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 13, 2017, 12:22pm UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/2 "2017-06-13T12:22:18Z")

</div>

@CaptainFeng which version of Kibana and Elasticsearch are you running now? Did you try refreshing the index pattern by click the "Refresh field list" button highlighted below in the red rectangle?

 ![](https://us1.discourse-cdn.com/elastic/original/3X/b/e/be17a01d2070eff3317e94b3549a17372d7f53d1.png)

---

<div class="post-metadata">

**Author:** ![CaptainFeng](https://avatars.discourse-cdn.com/v4/letter/c/e79b87/32.png) [@CaptainFeng](https://discuss.elastic.co/u/CaptainFeng)\
**Post date:** [June 13, 2017, 12:40pm UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/3 "2017-06-13T12:40:09Z")

</div>

Hi Brandon

The versions of Kibana and Elasticsearch are same as 5.4.0.

I tried to refresh or delete index pattern and rebuild it. But it didn't work for me.

And though these field look unsearchable and unaggregatable, I still can query them by Dev Tool in Kibana.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 13, 2017, 4:36pm UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/4 "2017-06-13T16:36:00Z")

</div>

@CaptainFeng when you refresh your index pattern, do you see the following warning at the top of your screen?

 ![](https://us1.discourse-cdn.com/elastic/original/3X/6/7/677717d1e9651f2a20f44b6e868806aedf4efc0f.png)

---

<div class="post-metadata">

**Author:** ![CaptainFeng](https://avatars.discourse-cdn.com/v4/letter/c/e79b87/32.png) [@CaptainFeng](https://discuss.elastic.co/u/CaptainFeng)\
**Post date:** [June 14, 2017, 1:55am UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/5 "2017-06-14T01:55:36Z")

</div>

@Brandon_Kobel  
No. There is no warning.

And it seems that mappings of old indices changed.

```
          "8103": {
        "type": "string",
        "norms": false,
        "fields": {
          "raw": {
            "type": "string",
            "index": "not_analyzed",
            "ignore_above": 256,
            "fielddata": false
          }
        }
      },

```

Did this will make 8103.raw field not searchable and unaggregatable?

---

<div class="post-metadata">

**Author:** ![whoami](https://avatars.discourse-cdn.com/v4/letter/w/a9a28c/32.png) [@whoami](https://discuss.elastic.co/u/whoami)\
**Post date:** [June 14, 2017, 2:20am UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/6 "2017-06-14T02:20:33Z")

</div>

by the way, what kind of field type is searchable or aggregatable? or is 'searchable and aggregatable' related to field type?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 14, 2017, 1:10pm UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/7 "2017-06-14T13:10:35Z")

</div>

@CaptainFeng we use the mappings in Elasticsearch to figure out the types of the fields, and whether they're analyzed. However, we use the [Field Capabilities API](https://www.elastic.co/guide/en/elasticsearch/reference/5.4/search-field-caps.html) to determine whether fields are searchable/aggregatable.

Would you mind executing a CURL request similar to the following against Elasticsearch and posting the raw response here? `curl http://localhost:9200/logstash-*/_field_caps?fields=* -u elastic:changeme`. You'll want to replace `logstash-*` with your index pattern and the elasticsearch URL and username/password will likely need to change.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 14, 2017, 1:12pm UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/8 "2017-06-14T13:12:14Z")

</div>

@whoami searchable/aggregatable are directly tied to the [field capabilities](https://www.elastic.co/guide/en/elasticsearch/reference/5.4/search-field-caps.html) as specified by Elasticsearch

---

<div class="post-metadata">

**Author:** ![CaptainFeng](https://avatars.discourse-cdn.com/v4/letter/c/e79b87/32.png) [@CaptainFeng](https://discuss.elastic.co/u/CaptainFeng)\
**Post date:** [June 14, 2017, 1:50pm UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/9 "2017-06-14T13:50:03Z")

</div>

@Brandon_Kobel I executed field capabilities api.

```
    "8103": {
      "string": {
        "type": "string",
        "searchable": true,
        "aggregatable": true,
        "indices": [
            ...
          "logstash-2017.05.28",
          "logstash-2017.05.29",
          "logstash-2017.05.30",
          "logstash-2017.05.31",
          "logstash-2017.06.01"
        ]
      },
      "text": {
        "type": "text",
        "searchable": true,
        "aggregatable": false,
        "indices": [
          "logstash-2017.06.02",
          "logstash-2017.06.03",
          "logstash-2017.06.04",
          "logstash-2017.06.06",
          "logstash-2017.06.07"
        ]
      }
    }

    "8103.raw": {
  "string": {
    "type": "string",
    "searchable": true,
    "aggregatable": true
  }
}

    "8103.keyword": {
  "keyword": {
    "type": "keyword",
    "searchable": true,
    "aggregatable": true
  }
},

```

There are four different parts. It seems strange. I upgrade ES in 2017.06.01.

Thanks!

---

<div class="post-metadata">

**Author:** ![whoami](https://avatars.discourse-cdn.com/v4/letter/w/a9a28c/32.png) [@whoami](https://discuss.elastic.co/u/whoami)\
**Post date:** [June 15, 2017, 6:11am UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/10 "2017-06-15T06:11:14Z")

</div>

yes, but how the "field capabilities api " know which field is searchable or aggregatable? or can we user control it by mapping?

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 15, 2017, 4:33pm UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/11 "2017-06-15T16:33:43Z")

</div>

@whoami they're derived from the mappings.

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [June 15, 2017, 4:35pm UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/12 "2017-06-15T16:35:33Z")

</div>

@CaptainFeng Sorry, I'm not following the "four different parts", are you referring to us having 8103, 8103.raw and 8103.keyword?

---

<div class="post-metadata">

**Author:** ![whoami](https://avatars.discourse-cdn.com/v4/letter/w/a9a28c/32.png) [@whoami](https://discuss.elastic.co/u/whoami)\
**Post date:** [June 16, 2017, 1:19am UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/13 "2017-06-16T01:19:27Z")

</div>

thx, would you mind to give a example?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2017, 1:19am UTC](https://discuss.elastic.co/t/kibana-shows-fields-are-not-searchable-and-aggregatable/89148/14 "2017-07-14T01:19:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
