# Not able to search on indexed fields in Kibana

**URL:** <https://discuss.elastic.co/t/not-able-to-search-on-indexed-fields-in-kibana/50432>\
**Category:** Kibana\
**Created:** [May 19, 2016, 12:24pm UTC](https://discuss.elastic.co/t/not-able-to-search-on-indexed-fields-in-kibana/50432 "2016-05-19T12:24:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![richag](https://avatars.discourse-cdn.com/v4/letter/r/7c8e57/32.png) [@richag](https://discuss.elastic.co/u/richag)\
**Post date:** [May 19, 2016, 12:24pm UTC](https://discuss.elastic.co/t/not-able-to-search-on-indexed-fields-in-kibana/50432/1 "2016-05-19T12:24:15Z")

</div>

Hi

I am using elasticsearch 2.1.2 version and Kibana 4.2.2 version.  
I had a index in ES using below:  
curl -XPUT [http://localhost:9200/abc/tbl/\_mapping](http://localhost:9200/abc/tbl/_mapping) -d'{  
"tbl": {  
"\_timestamp": {  
"enabled": true  
},  
"\_all": {  
"store": true  
},  
"properties": {  
"name": {  
"type": "string",  
"index": "not\_analyzed"  
},  
"num": {  
"type": "long"  
},  
"date": {  
"type": "date",  
"format": "yyyy-MM-dd"  
}  
}  
}  
}'

and it is having indexed data and also data is mapped to Kibana. Please see snapshot:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/dbd21a6000bb5c0e0ca65f3a08aec3f767a8a032.png)  
and when I scroll to Discover page it shows no indexed field to search..  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/dbf261b05ac774b1519190edd9e2736b05ee33a4.png)

Why? Am I doing something wrong? Help me.

---

<div class="post-metadata">

**Author:** ![dr\_rock](https://avatars.discourse-cdn.com/v4/letter/d/9de0a6/32.png) [@dr\_rock](https://discuss.elastic.co/u/dr_rock)\
**Post date:** [May 19, 2016, 12:41pm UTC](https://discuss.elastic.co/t/not-able-to-search-on-indexed-fields-in-kibana/50432/2 "2016-05-19T12:41:17Z")

</div>

What do you get when you run the following query ?

```
POST http://localhost:9200/abc*/_search 
{
  "query": {
    "range": {
      "@timestamp": {
        "gte": "now-1w/d",
        "lt": "now/d"
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![richag](https://avatars.discourse-cdn.com/v4/letter/r/7c8e57/32.png) [@richag](https://discuss.elastic.co/u/richag)\
**Post date:** [May 20, 2016, 3:35am UTC](https://discuss.elastic.co/t/not-able-to-search-on-indexed-fields-in-kibana/50432/3 "2016-05-20T03:35:39Z")

</div>

> [@dr\_rock](#):
>
> POST [http://localhost:9200/abc\*/\_search](http://localhost:9200/abc*/_search)  
> {  
> "query": {  
> "range": {  
> "@timestamp": {  
> "gte": "now-1w/d",  
> "lt": "now/d"  
> }  
> }  
> }  
> }

{  
"took" : 2,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 5,  
"successful" : 5,  
"failed" : 0  
},  
"hits" : {  
"total" : 7,  
"max\_score" : 1.0,  
"hits" : [ {  
"\_index" : "abc",  
"\_type" : "tbl",  
"\_id" : "573da47b9616b62160765597",  
"\_score" : 1.0,  
"\_timestamp" : 1463657777257,  
"\_source":{"num": 20.0, "name": "ankit"}  
},  
..........[other indexed data]  
, {  
"\_index" : "abc",  
"\_type" : "tbl",  
"\_id" : "573da4b59616b6216076559a",  
"\_score" : 1.0,  
"\_timestamp" : 1463657777257,  
"\_source":{"num": 20.0, "name": "praveen"}  
} ]  
}  
}  
curl: (3) [globbing] nested brace in column 15

---

<div class="post-metadata">

**Author:** ![dr\_rock](https://avatars.discourse-cdn.com/v4/letter/d/9de0a6/32.png) [@dr\_rock](https://discuss.elastic.co/u/dr_rock)\
**Post date:** [May 20, 2016, 12:14pm UTC](https://discuss.elastic.co/t/not-able-to-search-on-indexed-fields-in-kibana/50432/4 "2016-05-20T12:14:22Z")

</div>

Sorry for typo, the query was (date instead of @timestamp) :

```
POST http://localhost:9200/abc*/_search 
{
  "query": {
    "range": {
      "date": {
        "gte": "now-1w/d",
        "lt": "now/d"
      }
    }
  }
}

```

Anyway, according to your answer, it seems that :

- you are using **\_timestamp** field which is deprecated
- your data does not contain any **date** field

When you added your index in kibana, what were the date fields that were proposed to you?

---

<div class="post-metadata">

**Author:** ![richag](https://avatars.discourse-cdn.com/v4/letter/r/7c8e57/32.png) [@richag](https://discuss.elastic.co/u/richag)\
**Post date:** [May 24, 2016, 5:00am UTC](https://discuss.elastic.co/t/not-able-to-search-on-indexed-fields-in-kibana/50432/5 "2016-05-24T05:00:58Z")

</div>

I had a date field (as name and num) but there is no data in it. Now I added some data and following your query output is:  
{  
"took" : 3,  
"timed\_out" : false,  
"\_shards" : {  
"total" : 5,  
"successful" : 5,  
"failed" : 0  
},  
"hits" : {  
"total" : 5,  
"max\_score" : 1.0,  
"hits" : [ {  
"\_index" : "abc",  
"\_type" : "tbl",  
"\_id" : "5743dd5087675117e31d9529",  
"\_score" : 1.0,  
"\_timestamp" : 1464065500396,  
"\_source":{"date": "2016-01-17", "num": 25.0, "name": "xyz"}  
}, {  
"\_index" : "abc",  
"\_type" : "tbl",  
"\_id" : "5743dd8887675117e31d952c",  
"\_score" : 1.0,  
"\_timestamp" : 1464065500396,  
"\_source":{"date": "2016-03-04", "num": 23.0, "name": "abc"}  
} ]  
}  
}

- In kibana I used _date_ as date field and it is shown in screenshot shared previously.
- Also I know \_timestamp field is depricated but using ES mapping I forced it to have a value which is shown in ouput.

---

<div class="post-metadata">

**Author:** ![richag](https://avatars.discourse-cdn.com/v4/letter/r/7c8e57/32.png) [@richag](https://discuss.elastic.co/u/richag)\
**Post date:** [May 26, 2016, 4:12am UTC](https://discuss.elastic.co/t/not-able-to-search-on-indexed-fields-in-kibana/50432/6 "2016-05-26T04:12:23Z")

</div>

Waiting for response..

---

<div class="post-metadata">

**Author:** ![dr\_rock](https://avatars.discourse-cdn.com/v4/letter/d/9de0a6/32.png) [@dr\_rock](https://discuss.elastic.co/u/dr_rock)\
**Post date:** [May 27, 2016, 9:54pm UTC](https://discuss.elastic.co/t/not-able-to-search-on-indexed-fields-in-kibana/50432/7 "2016-05-27T21:54:39Z")

</div>

Are you sure that you have executed the exact query below?

```
POST http://localhost:9200/abc*/_search 
{
  "query": {
    "range": {
      "date": {
        "gte": "now-1w/d",
        "lt": "now/d"
      }
    }
  }
}

```

It is quite surprising to get result with date value 2016-01-17 with this query...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:52pm UTC](https://discuss.elastic.co/t/not-able-to-search-on-indexed-fields-in-kibana/50432/8 "2017-07-06T13:52:07Z")

</div>


