# Kibana5.2 Error

**URL:** <https://discuss.elastic.co/t/kibana5-2-error/78069>\
**Category:** Kibana\
**Created:** [March 10, 2017, 1:01am UTC](https://discuss.elastic.co/t/kibana5-2-error/78069 "2017-03-10T01:01:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [March 10, 2017, 1:01am UTC](https://discuss.elastic.co/t/kibana5-2-error/78069/1 "2017-03-10T01:01:30Z")

</div>

Hi Experts,

I was exploring kibana5.2 , my index contains date field which is in EPOC so I converted it and I can see all the 52 fields in kibana .The problem is out of 52 only 10 fields are searchable , also kibana only shows value in discover tab if I configure Index pattern with @timestamp . If I configure index with any other date field I got an error in Kibana shown below .

 ![](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1a07d8c41f681d49d1275b2d6028256a5ee59ff9.png)

FYI , I have converted this field as below  
`date {match => ["rt","UNIX_MS"] target => "rt" }`  
As shown rt is a date field but it neither searchable nor aggregated whereas, sev is searchable as well as aggregated .

 ![](https://us1.discourse-cdn.com/elastic/original/3X/7/7/77ce1b4ddf1e2850ea6d41f0abbca7bbe5db5ee9.png)

The only noticeable difference I can see is @timestamp field is searchable but rt field is not . Can someone suggest what I am doing wrong ?

Regards  
VG

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [March 10, 2017, 7:11pm UTC](https://discuss.elastic.co/t/kibana5-2-error/78069/2 "2017-03-10T19:11:32Z")

</div>

It sounds like a mapping issue, could you share [your index mappings](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html)?

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [March 10, 2017, 8:05pm UTC](https://discuss.elastic.co/t/kibana5-2-error/78069/3 "2017-03-10T20:05:25Z")

</div>

Actually, I just saw this error too. In the case I saw, there was a mapping in the index, but no data. Do you have data in Elasticsearch?

EDIT: opened [https://github.com/elastic/kibana/issues/10748](https://github.com/elastic/kibana/issues/10748)

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [March 10, 2017, 11:21pm UTC](https://discuss.elastic.co/t/kibana5-2-error/78069/4 "2017-03-10T23:21:04Z")

</div>

Even I was thinking this could be a mapping issue but I guess this is not the case as I can see field type is getting changed as per mapping . Here is my Index mapping

```
{
      "order": 0,
      "template": "test-*",
      "settings": {
         "index": {
            "refresh_interval": "5s"
         }
      },
      "mappings": {
         "_default_": {
            "dynamic_templates": [
               {
                  "message_field": {
                     "path_match": "message",
                     "mapping": {
                        "norms": false,
                        "type": "text"
                     },
                     "match_mapping_type": "string"
                  }
               },
               {
                  "string_fields": {
                     "mapping": {
                        "norms": false,
                        "type": "text",
                        "fields": {
                           "keyword": {
                              "type": "keyword"
                           }
                        }
                     },
                     "match_mapping_type": "string",
                     "match": "*"
                  }
               }
            ],
            "_all": {
               "norms": false,
               "enabled": true
            },
            "properties": {
               "@timestamp": {
                  "include_in_all": false,
                  "type": "date"
               },
               "@version": {
                  "include_in_all": false,
                  "type": "keyword"
               },
    		   
"dvc": {"type": "ip"},
"src": {"type": "ip"},
"dst": {"type": "ip"},
"dpt": {"type": "integer"},
"agt": {"type": "ip"},
"severity": {"type": "integer"},
"dhost": {"type":"string"},
"shost": {"type":"string"},
"dstgeoip" : {"type" : "object","dynamic": true,"properties" : {"location" : { "type" : "geo_point" }}},
"srcgeoip" : {"type" : "object","dynamic": true,"properties" : {"location" : { "type" : "geo_point" }}},
"dstgeoip.city_name": {"type":"string"},
"dstgeoip.country_name" : {"type":"string"},
"srcgeoip.city_name": {"type":"string"},
"srcgeoip.country_name" : {"type":"string"},
"baseId": {"type": "string"}

            }
         }
      },
      "aliases": {}
}
```

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [March 10, 2017, 11:25pm UTC](https://discuss.elastic.co/t/kibana5-2-error/78069/5 "2017-03-10T23:25:31Z")

</div>

I do not understand this opened case , why I can see document with @timestamp but not with any other date field.  
Yes, I do have data/document in my index. I can see no of documents in an index = no of file lines.

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [March 11, 2017, 7:19pm UTC](https://discuss.elastic.co/t/kibana5-2-error/78069/6 "2017-03-11T19:19:59Z")

</div>

My guess is that you didn't have data in the index when you added it to Kibana, but now you do. The other date fields aren't defined correctly, because the data wasn't there when the mappings were being read. If you refresh your mappings, I'm guessing things will start working.

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [March 28, 2017, 5:42pm UTC](https://discuss.elastic.co/t/kibana5-2-error/78069/7 "2017-03-28T17:42:32Z")

</div>

Thanks Joe,

So you were right after refresh this were working fine . So the problem was with the mapping initially and on top of that LS was saying that data has been parsed but it was not actually sending data in the index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2017, 5:42pm UTC](https://discuss.elastic.co/t/kibana5-2-error/78069/8 "2017-04-25T17:42:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
