# Raw field disappear

**URL:** <https://discuss.elastic.co/t/raw-field-disappear/51805>\
**Category:** Elasticsearch\
**Created:** [June 3, 2016, 2:50pm UTC](https://discuss.elastic.co/t/raw-field-disappear/51805 "2016-06-03T14:50:06Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Post date:** [June 3, 2016, 2:50pm UTC](https://discuss.elastic.co/t/raw-field-disappear/51805/1 "2016-06-03T14:50:06Z")

</div>

I have my ELK installed and use a logstash file to configure the log txt files. However, when I open kibana, I could not see the **.raw** field data. How can I see that?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 3, 2016, 2:51pm UTC](https://discuss.elastic.co/t/raw-field-disappear/51805/2 "2016-06-03T14:51:09Z")

</div>

What's the name of the index with your logs?

---

<div class="post-metadata">

**Author:** ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Post date:** [June 5, 2016, 2:58am UTC](https://discuss.elastic.co/t/raw-field-disappear/51805/3 "2016-06-05T02:58:32Z")

</div>

I didnt include any index field in my conf file.

---

<div class="post-metadata">

**Author:** ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Post date:** [June 6, 2016, 9:10am UTC](https://discuss.elastic.co/t/raw-field-disappear/51805/4 "2016-06-06T09:10:50Z")

</div>

I have written a logstash conf filefor reading logs. If I use the default index, that is logstash-\*, I could see .raw field in kibana. However, if I create a new index in conf file in logstash like

output{  
elasticsearch {  
hosts =\> "localhost"  
index =\> "batchjob-\*"}  
}  
Then the new index cant configure .raw field. Is there any resolve ways to solve it? Great Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 9, 2016, 7:58pm UTC](https://discuss.elastic.co/t/raw-field-disappear/51805/5 "2016-06-09T19:58:30Z")

</div>

Logstash's default index template only applies to indexes whose name matches logstash-\*. If you want to name your indexes differently you'll have to modify the index template.

---

<div class="post-metadata">

**Author:** ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Post date:** [June 10, 2016, 1:44am UTC](https://discuss.elastic.co/t/raw-field-disappear/51805/6 "2016-06-10T01:44:34Z")

</div>

Yes. Thanks for guidance. I have managed to create raw fields again now.  
Great thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:44pm UTC](https://discuss.elastic.co/t/raw-field-disappear/51805/7 "2017-07-05T22:44:54Z")

</div>


