Multiple terms


(xx xxxxxx) #1

hello, I am a newbie with elasticstack .

I am working with filebeats, logstash and elasticsearch 5.5. after creating an index I found out that the terms are duplicated .
example user and user.keyword

2017-08-07 16_04_36-OSSIM Authentication Dashboard - Kibana

Any idea how to fix this thx.


(David Pilato) #2

If you don't want to do both fulltext search and aggregations on such fields, then you can remove one or the other in the mapping template.

  • user is used for fulltext search
  • user.keyword is used for aggregations

Have a look at https://www.elastic.co/guide/en/elasticsearch/reference/5.5/indices-templates.html


(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.