First, my 'query' field wasn't analysed.
Today I have deleted all my indices and reinstalled Kibana, ElasticSearch, and PacketBeat to the newest stable versions. And after this I have all new indices patterns with stars instead of "event times", like "packetbeat-*".
After reinstallation I have conflict mapping with the "client_location" field. Reindexing wasn't help. I have deleted all indices again and started from zero, but I still have the conflict mapping.
And in the MysqlDashboard I have the same problem with split queries. And yes, now the "query" field is real analysed.
- Kibana v. 4.6.1
- Packetbeat v.1.3.1
- ElasticSearch v.2.4.0
- Kibana Beats Dashboards v.1.3.1