# Kibana text field in discover but missing in lens table

**URL:** <https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393>\
**Category:** Kibana\
**Created:** [February 28, 2024, 10:44pm UTC](https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393 "2024-02-28T22:44:26Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![chowpay](https://avatars.discourse-cdn.com/v4/letter/c/ee7513/32.png) [@chowpay](https://discuss.elastic.co/u/chowpay)\
**Post date:** [February 28, 2024, 10:44pm UTC](https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393/1 "2024-02-28T22:44:26Z")

</div>

I'm on Kibana 7.16

When I'm in discover I can see this text field:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/8/788a7d5d86732d2cb8a897081f37ffeb1173ff34.png)

I want the field inside of a table, but when I go to lens to try and create the table it shows up in an empty field:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/c/0c949f8913c4ee7ee4fa30c81dcfb143c5ddc1b7.png)

In discover his is the field type:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/d/3d439e9b21e6b75e9cb65379093a56fb32db34a9.png)  
The time and index is correct. Is it because its a multi line field?

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [February 29, 2024, 8:17am UTC](https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393/2 "2024-02-29T08:17:36Z")

</div>

Hi @chowpay ,

I would suggest to check `ignore_above` value in the mapping for `content-head.keyword` field. If the configured value is currently lower than any of `content-head` values then increasing `ignore_above` and reindexing should populate `content-head.keyword` with data.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 29, 2024, 9:33am UTC](https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393/3 "2024-02-29T09:33:25Z")

</div>

Hi @chowpay

What version are you on?

Even though it says it's empty, did you try to drag the `.keyword` (`text` field won't work) into a Lens table? Say rows?

Also, is the time picker correct or do you have any other filters in lens?

Can you show a bigger / whole screenshot?

---

<div class="post-metadata">

**Author:** ![chowpay](https://avatars.discourse-cdn.com/v4/letter/c/ee7513/32.png) [@chowpay](https://discuss.elastic.co/u/chowpay)\
**Post date:** [February 29, 2024, 5:11pm UTC](https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393/5 "2024-02-29T17:11:52Z")

</div>

Hi @stephenb  
7.16

Yes I've tried dragging it over and its empty.  
There is no non-keyword option

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c9ce53458e1bcd6636e2d002c151adc7a08c08e8.png)

ive tried dragging it in columns or rows all the same  
time picker is correct beacuse I can see the field in discover just fine

Full screen shot:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/b/cba2d91536a0fffb962c95f43632327c0c261c25.png)

Discover shows the field data

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4c07d93b646f879e9052407d5a34f887944034ba.jpeg)

---

<div class="post-metadata">

**Author:** ![chowpay](https://avatars.discourse-cdn.com/v4/letter/c/ee7513/32.png) [@chowpay](https://discuss.elastic.co/u/chowpay)\
**Post date:** [February 29, 2024, 5:30pm UTC](https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393/6 "2024-02-29T17:30:07Z")

</div>

Ah I found it:

```auto
        "content-head": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        },

```

I have many indexes broken up by time

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/6/86ab0e490f2a09f93b57f845a18530d43829f792.png)

How would I adjust the mapping for all my indexes? and is this where I should be doing it?

I took 1 of the fields:

```auto
#EXTM3U
#EXT-X-VERSION:5
#EXT-X-MEDIA-SEQUENCE:52437
#EXT-X-TARGETDURATION:8
#EXT-X-DISCONTINUITY-SEQUENCE:5859
#UPLYNK-SEGMENT: 48f6499fce4a4a44954cfd70dc8bad7b,00000000,ad
#UPLYNK-KEY:https://content-ausw1.uplynk.com/check?b=48f6499fce4a4a44954cfd70dc8bad7b&c=3324f2467c414329b3b0cc5cd987b6be&pbs=f4d8f31702a7438f87f05cdd98051deb
#EXT-X-DISCONTINUITY
#EXT-X-PROGRAM-DATE-TIME:2024-02-29T17:20:47.271000+00:00
#EXT-X-KEY:METHOD=AES-128,URI="https://content-ausw1.uplynk.com/check2?b=48f6499fce4a4a44954cfd70dc8bad7b&v=3324f2467c414329b3b0cc5cd987b6be&r=f&c=3324f2467c414329b3b0cc5cd987b6be&pbs=f4d8f31702a7438f87f05cdd98051deb",IV=0x00000000000000000000000000000000
#EXTINF:4.0960,
https://x-default-stgec.uplynk.com/ause/slices/48f/a4e18e29d9624114a7eac2829aac559e/48f6499fce4a4a44954cfd70dc8bad7b/F00000000.ts?pbs=f4d8f31702a7438f87f05cdd98051deb&_jt=l&chid=3324f2467c414329b3b0cc5cd987b6be&cloud=aws&cdn=eci&si=1&d=4.096

```

Then did a character count:  
Total characters (without spaces) 912

I'm guessing "Ignore\_above" count is per character?

Thanks!

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [March 1, 2024, 12:53pm UTC](https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393/7 "2024-03-01T12:53:14Z")

</div>

Here are some documentation pages which can help with updating mappings:

> **[ignore\_above | Elasticsearch Guide \[8.12\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/ignore-above.html)**

> **[Update mapping API | Elasticsearch Guide \[8.12\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html)**

This will also require reindexing the data.

The second option is to create a new runtime field with `keyword` type which would be a copy of `content-head` text field.

---

<div class="post-metadata">

**Author:** ![chowpay](https://avatars.discourse-cdn.com/v4/letter/c/ee7513/32.png) [@chowpay](https://discuss.elastic.co/u/chowpay)\
**Post date:** [March 1, 2024, 6:01pm UTC](https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393/8 "2024-03-01T18:01:41Z")

</div>

I tried the 2nd option since in reality I would need to join 2 fields , using this as one of the fields. The runtime is very simple:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/0/e0d990c19c388082bfd563461e3039f607694a92.png)

It works with other keyword fields, but when trying to access this specific one I get this error. "class \_cast\_exception" . Am I doing my emit incorrectly? Thanks

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [March 1, 2024, 6:24pm UTC](https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393/9 "2024-03-01T18:24:11Z")

</div>

It's most probably undefined. Try adding checks like `if (doc["<field name>"].size() > 0) { ... }` or `if (doc.containsKey('<field name>')) { ... }`.

---

<div class="post-metadata">

**Author:** ![chowpay](https://avatars.discourse-cdn.com/v4/letter/c/ee7513/32.png) [@chowpay](https://discuss.elastic.co/u/chowpay)\
**Post date:** [March 2, 2024, 12:42am UTC](https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393/10 "2024-03-02T00:42:58Z")

</div>

I tried both but maybe its my syntax:

```auto
if(doc['content-head.keyword'].size()>0) {emit(doc['content-head.keyword'])}

```

When I do this and go to discover the field doesn't appear

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [March 2, 2024, 8:39am UTC](https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393/11 "2024-03-02T08:39:44Z")

</div>

If `ignore_above` stays the same in the mapping and data is not reindexed, then `content-head.keyword` would be still empty for documents with long `content-head`.

Using `content-head.keyword` inside a runtime field script would not help. But you can use other populated fields like `content-head`. So start with `if (doc['content-head'].size()>0) { emit(doc['content-head'].value) }`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2024, 8:39am UTC](https://discuss.elastic.co/t/kibana-text-field-in-discover-but-missing-in-lens-table/354393/12 "2024-03-30T08:39:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
