# No histogram in Discover

**URL:** <https://discuss.elastic.co/t/no-histogram-in-discover/155308>\
**Category:** Kibana\
**Created:** [November 4, 2018, 4:45pm UTC](https://discuss.elastic.co/t/no-histogram-in-discover/155308 "2018-11-04T16:45:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![danielkhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielkhan/32/37266_2.png) [@danielkhan](https://discuss.elastic.co/u/danielkhan)\
**Post date:** [November 4, 2018, 4:45pm UTC](https://discuss.elastic.co/t/no-histogram-in-discover/155308/1 "2018-11-04T16:45:05Z")

</div>

Hello,

I am using kibana to browse data from syslog.  
I previous setups I always got a histogram on the Discover tab. For unknown reasons, it does not show up in my latest deployment. I have a time field in my log messages and it is also indexed.

Thank you

Daniel

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [November 5, 2018, 2:01am UTC](https://discuss.elastic.co/t/no-histogram-in-discover/155308/2 "2018-11-05T02:01:01Z")

</div>

Did you set the "Time filter field name" when setting up your index pattern in Kibana?

![05%20PM](https://us1.discourse-cdn.com/elastic/original/3X/c/c/cc872da30c63929e580dc68a054afe9eb6e25f5e.png)

One way to verify the index pattern time field has been set is to view the index pattern under management and see if any time fields have the "clock" symbol next to their name.

![41%20PM](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a99aa53abb6bd5880a26a1608d6df8af476b5ba4.png)

---

<div class="post-metadata">

**Author:** ![danielkhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielkhan/32/37266_2.png) [@danielkhan](https://discuss.elastic.co/u/danielkhan)\
**Post date:** [November 5, 2018, 8:51am UTC](https://discuss.elastic.co/t/no-histogram-in-discover/155308/3 "2018-11-05T08:51:20Z")

</div>

Strangely, this option does not exist on my version (6.4.2)

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [November 5, 2018, 2:13pm UTC](https://discuss.elastic.co/t/no-histogram-in-discover/155308/4 "2018-11-05T14:13:21Z")

</div>

What does the mapping look like for your elastic search index? [https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html)

Is the time field index as a date type? [https://www.elastic.co/guide/en/elasticsearch/reference/current/date.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/date.html)

---

<div class="post-metadata">

**Author:** ![danielkhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielkhan/32/37266_2.png) [@danielkhan](https://discuss.elastic.co/u/danielkhan)\
**Post date:** [November 5, 2018, 2:36pm UTC](https://discuss.elastic.co/t/no-histogram-in-discover/155308/5 "2018-11-05T14:36:05Z")

</div>

No, it's a text field right now.  
I assume that the type is autodetected because it worked in other cases. The data is coming from fluentd.  
The field value is right now something like '04/Nov/2018:16:38:58 +0000' which looks like a valid date format.

---

<div class="post-metadata">

**Author:** ![xeraa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xeraa/32/48181_2.png) [@xeraa](https://discuss.elastic.co/u/xeraa)\
**Post date:** [November 5, 2018, 7:13pm UTC](https://discuss.elastic.co/t/no-histogram-in-discover/155308/6 "2018-11-05T19:13:25Z")

</div>

You'll need to customize the mapping of that field to be recognized as a date format. The link above with the date format details that the default formats are `"strict_date_optional_time||epoch_millis"` (which looks like [https://www.joda.org/joda-time/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateOptionalTimeParser](https://www.joda.org/joda-time/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateOptionalTimeParser)).

If you have a daily index, create an index pattern with the right field and it will work for tomorrow's data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2018, 7:13pm UTC](https://discuss.elastic.co/t/no-histogram-in-discover/155308/7 "2018-12-03T19:13:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
