# Mapping error: Please use a keyword field instead

**URL:** <https://discuss.elastic.co/t/mapping-error-please-use-a-keyword-field-instead/299240>\
**Category:** Elasticsearch\
**Created:** [March 9, 2022, 4:12pm UTC](https://discuss.elastic.co/t/mapping-error-please-use-a-keyword-field-instead/299240 "2022-03-09T16:12:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [March 9, 2022, 4:12pm UTC](https://discuss.elastic.co/t/mapping-error-please-use-a-keyword-field-instead/299240/1 "2022-03-09T16:12:37Z")

</div>

Hi, Im getting data from Azure with metricbeat, and also getting additional data from event hub.

the data from metricbeat and Event Hub is shown in the same dashboard.

In order to filter with a control visualization in a dashboard with data from both sources, I added a field in common with metricbeat mapping called: `azure.resource.name`, and called the indices with data from Event Hub: ` metricbeat-client-name%{+YYYY.MM}` so they are included in the index pattern: `metricbeat-*`

But every time I load the dashboard i got the this error: `13 of 17 shards failed The data you are seeing might be incomplete or wrong.`

Error reason:  
Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [azure.resource.name] in order to load field data by uninverting the inverted index. Note that this can use significant memory.

All those 13 shards that fail are the ones with data from event hub named like this:

example:  
metricbeat-client-name1  
metricbeat-client-name2  
metricbeat-client-name3

And when I get the mapping for that field from all those individual indices I get this:

```auto
{
  "metricbeat-client-name1-2022.03" : {
    "mappings" : {
      "azure.resource.name" : {
        "full_name" : "azure.resource.name",
        "mapping" : {
          "name" : {
            "type" : "text",
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          }
        }
      }
    }
  }

```

So what can I do to solve those errors?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 9, 2022, 9:47pm UTC](https://discuss.elastic.co/t/mapping-error-please-use-a-keyword-field-instead/299240/2 "2022-03-09T21:47:00Z")

</div>

Try using `azure.resource.name.keyword` instead?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2022, 9:47pm UTC](https://discuss.elastic.co/t/mapping-error-please-use-a-keyword-field-instead/299240/3 "2022-04-06T21:47:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
