# Kibana splitting fields with dots or spaces in them

**URL:** <https://discuss.elastic.co/t/kibana-splitting-fields-with-dots-or-spaces-in-them/61298>\
**Category:** Kibana\
**Created:** [September 22, 2016, 5:17pm UTC](https://discuss.elastic.co/t/kibana-splitting-fields-with-dots-or-spaces-in-them/61298 "2016-09-22T17:17:26Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [September 22, 2016, 5:43pm UTC](https://discuss.elastic.co/t/kibana-splitting-fields-with-dots-or-spaces-in-them/61298/2 "2016-09-22T17:43:20Z")

</div>

Per the Analyzed Field tooltip:

> Careful! The field selected contains analyzed strings. Analyzed strings are highly unique and can use a lot of memory to visualize. Values such as foo-bar will be broken into foo and bar. See Mapping Types for more information on setting this field as not\_analyzed

You'll have to change your mappings to not analyzed for that field. Check:

[Create template](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/9)  
and here  
[Reindexing](https://discuss.elastic.co/t/a-couple-howto-questions/60725/5)

Here was my process after installing the Sense plugin:

> ```
> PUT /_template/bro_template
> {
> "template": "bro-*",
> "order": 1,
> "mappings": {
> "_default_": {
> "dynamic_templates": [
> {
> "strings": { 
> "match_mapping_type": "string",
> "mapping": {
> "type": "string",
> "index": "not_analyzed"
> }
> }
> }
> ]
> },
> "bro_ts": {
> "properties": {
> "ts": {
> "type": "date",
> "format": "epoch_millis"
> }
> }
> },  
> "bro_orig_h": {
> "properties": {
> "id.orig_h": {
> "type": "ip"
> }
> }
> },
> "bro_resp_h": {
> "properties": {
> "id.resp_h": {
> "type": "ip"
> }
> }
> },
> "bro_assigned_ip": {
> "properties": {
> "assigned_ip": {
> "type": "ip"
> }
> }
> }
> }
> }
> 
> ```

after creating the index you have to create a new index and copy the data from the old index into it, which will pickup the new template when you do it:

```
PUT /bro-201609140900-1
POST /_reindex
{
  "source": {
    "index": "bro-201609140900"
  },
  "dest": {
    "index": "bro-201609140900-1"
  }
}
DELETE /bro-201609140900

```

If you're matching by pattern in your index setup, like I am with bro-\*, then it really doesn't matter if you keep exact same name of the index or not. Hope that helps.

Note to devs: The above information took me almost two days to figure out. Maybe I'm just daft, but I HIGHLY recommend a FAQ or "Common Operations" section somewhere here:

[Definitive Guide](https://www.elastic.co/guide/en/elasticsearch/guide/current/index.html)

Topics could include the **process** of creating a template, reindexing, etc. Maybe even a section on common things that people run into, like the above how to fix analyzed string fields and whatnot.

---

_[View the full topic](https://discuss.elastic.co/t/kibana-splitting-fields-with-dots-or-spaces-in-them/61298)._
