# Kibana splitting up hostname as multiple fields in graphs

**URL:** <https://discuss.elastic.co/t/kibana-splitting-up-hostname-as-multiple-fields-in-graphs/122032>\
**Category:** Kibana\
**Created:** [March 1, 2018, 10:25am UTC](https://discuss.elastic.co/t/kibana-splitting-up-hostname-as-multiple-fields-in-graphs/122032 "2018-03-01T10:25:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ujjain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ujjain/32/27378_2.png) [@ujjain](https://discuss.elastic.co/u/ujjain)\
**Post date:** [March 1, 2018, 10:25am UTC](https://discuss.elastic.co/t/kibana-splitting-up-hostname-as-multiple-fields-in-graphs/122032/1 "2018-03-01T10:25:52Z")

</div>

I have a field called beat.hostname in my Metricbeat-index. Unfortunately the kibana dashboards show a seperate line in the graph for the domain name and subdomain part of beat.hostname.

There are no entries in the Metricbeat-index with nl.rs as beat.hostname and beat.hostname is always eublaf001.nl.rs

These are the beat.hostname fields:

 ![](https://i.imgur.com/FWZhSyj.png)

This is the beat.hostname mappings:

```
"beat": {
    "properties": {
        "hostname": {
            "ignore_above": 1024,
            "type": "keyword"
        },
        "name": {
            "ignore_above": 1024,
            "type": "keyword"
        },
        "version": {
            "ignore_above": 1024,
            "type": "keyword"
        }
    }
},

```

 ![](https://i.imgur.com/ZNAL8zqh.png)

As you see, in graphs it's splitting up the hostname in eublaf001.nl.rs in a seperate eublaf001 and nl.rs.

---

<div class="post-metadata">

**Author:** ![jbudz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbudz/32/45922_2.png) [@jbudz](https://discuss.elastic.co/u/jbudz)\
**Post date:** [March 1, 2018, 7:57pm UTC](https://discuss.elastic.co/t/kibana-splitting-up-hostname-as-multiple-fields-in-graphs/122032/2 "2018-03-01T19:57:32Z")

</div>

Can you double check the mapping for earlier metricbeat indices? I'm wondering if beat.hostname on an older timestamp wasn't using the beats template yet.

The results are behaving as if it's a text/string analyzed field. If this is the case, on the Kibana side after resolving this you'll have to click the refresh button on the index patterns page to update Kibana's version of the mapping.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2018, 7:57pm UTC](https://discuss.elastic.co/t/kibana-splitting-up-hostname-as-multiple-fields-in-graphs/122032/3 "2018-03-29T19:57:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
