# Kibana splitting fields with dots or spaces in them

**URL:** <https://discuss.elastic.co/t/kibana-splitting-fields-with-dots-or-spaces-in-them/61298>\
**Category:** Kibana\
**Created:** [September 22, 2016, 5:17pm UTC](https://discuss.elastic.co/t/kibana-splitting-fields-with-dots-or-spaces-in-them/61298 "2016-09-22T17:17:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sacasumo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sacasumo/32/40384_2.png) [@sacasumo](https://discuss.elastic.co/u/sacasumo)\
**Post date:** [September 22, 2016, 5:17pm UTC](https://discuss.elastic.co/t/kibana-splitting-fields-with-dots-or-spaces-in-them/61298/1 "2016-09-22T17:17:26Z")

</div>

I'm stuck with an issue in the vizualisation page, where Kibana is splitting fileds which have a space or a dot between them. For example with a source hostname such as server.domain.local I get a count for server, another for domain and another for local. Not exactly sure why or how this is happening. The same goes for countries such as united states or united kingdom.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/8/873b27aff2f203c2c046a5f07c3e72c505bc7951.png)

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [September 22, 2016, 5:43pm UTC](https://discuss.elastic.co/t/kibana-splitting-fields-with-dots-or-spaces-in-them/61298/2 "2016-09-22T17:43:20Z")

</div>

Per the Analyzed Field tooltip:

> Careful! The field selected contains analyzed strings. Analyzed strings are highly unique and can use a lot of memory to visualize. Values such as foo-bar will be broken into foo and bar. See Mapping Types for more information on setting this field as not\_analyzed

You'll have to change your mappings to not analyzed for that field. Check:

[Create template](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/9)  
and here  
[Reindexing](https://discuss.elastic.co/t/a-couple-howto-questions/60725/5)

Here was my process after installing the Sense plugin:

> ```
> PUT /_template/bro_template
> {
> "template": "bro-*",
> "order": 1,
> "mappings": {
> "_default_": {
> "dynamic_templates": [
> {
> "strings": { 
> "match_mapping_type": "string",
> "mapping": {
> "type": "string",
> "index": "not_analyzed"
> }
> }
> }
> ]
> },
> "bro_ts": {
> "properties": {
> "ts": {
> "type": "date",
> "format": "epoch_millis"
> }
> }
> },  
> "bro_orig_h": {
> "properties": {
> "id.orig_h": {
> "type": "ip"
> }
> }
> },
> "bro_resp_h": {
> "properties": {
> "id.resp_h": {
> "type": "ip"
> }
> }
> },
> "bro_assigned_ip": {
> "properties": {
> "assigned_ip": {
> "type": "ip"
> }
> }
> }
> }
> }
> 
> ```

after creating the index you have to create a new index and copy the data from the old index into it, which will pickup the new template when you do it:

```
PUT /bro-201609140900-1
POST /_reindex
{
  "source": {
    "index": "bro-201609140900"
  },
  "dest": {
    "index": "bro-201609140900-1"
  }
}
DELETE /bro-201609140900

```

If you're matching by pattern in your index setup, like I am with bro-\*, then it really doesn't matter if you keep exact same name of the index or not. Hope that helps.

Note to devs: The above information took me almost two days to figure out. Maybe I'm just daft, but I HIGHLY recommend a FAQ or "Common Operations" section somewhere here:

[Definitive Guide](https://www.elastic.co/guide/en/elasticsearch/guide/current/index.html)

Topics could include the **process** of creating a template, reindexing, etc. Maybe even a section on common things that people run into, like the above how to fix analyzed string fields and whatnot.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:38pm UTC](https://discuss.elastic.co/t/kibana-splitting-fields-with-dots-or-spaces-in-them/61298/3 "2017-07-06T13:38:24Z")

</div>


