I have a problem using a raw field for term aggregation in a data table visualization. Whenever I try to view the data for a specific raw field used in a search through the visualization, I get no results. However, if I use the same search in Discover, I get back a result with entries and the raw field that I wanted to show in the visualization is populated correctly.
Any ideas to why the raw field data isn't showing up in the visualization?
Can you post a screenshot of your visualization configuration /query ?
I'm assuming you mean you have a .raw not_analyzed mapping that you are using in your datatable ?
And this shows no results ?
You are linking this visualization to a saved search that Does yield results ?
That is rather befalling... the only reason I can think of , is that there is some kind of disconnect between your raw and analyzed field (that you are seeing in Discover page). Maybe a mapping error ?
On Discover; In the left pane , click in the settings (gear) next to Available Fields and uncheck the "Hide Missing Fields".
Now find your detailedLogMessage.raw and click on it.
It will display something like
This field is present in your elasticsearch mapping but not in any documents in the search results. You may still be able to visualize or search on it.
Click on the Visualize button just below the warning. Do you get any results back for that ?
Yes, that seems to be the case. I initially thought ignore_above ignores the bits of text longer than specified value (i.e. truncates down to the specified length) - but in reality (and according to the docs) the value is completely ignored if above that length.
If the mapping specifies ignore_above then there's not much you can do afterwards to rectify the situation.
Kibana only displays whats already indexed by elasticsearch.
Unfortunately I have no experience with logstash (I index my documents directly from my own c++ program) - but I'm sure you should be able to change the way logstash maps the index... maybe ask the question in the logstash group ?
How "norms" and "fields" show up in yours and not mine. I push my logs to ES using logstash only. Why my mapping looks different. because of this I am not able to follow some posts. Are you using some other endpoint ?
any help appreciated.