# \[Resolve\] Field from logstash not indexed

**URL:** <https://discuss.elastic.co/t/resolve-field-from-logstash-not-indexed/61144>\
**Category:** Elasticsearch\
**Created:** [September 21, 2016, 2:51pm UTC](https://discuss.elastic.co/t/resolve-field-from-logstash-not-indexed/61144 "2016-09-21T14:51:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rdesgrange](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@rdesgrange](https://discuss.elastic.co/u/rdesgrange)\
**Post date:** [September 21, 2016, 2:51pm UTC](https://discuss.elastic.co/t/resolve-field-from-logstash-not-indexed/61144/1 "2016-09-21T14:51:15Z")

</div>

Hi,

I have a setup where filebeat send log to logstash, that process it through grok parser and then send it to Elasticsearch. Classic.

I just add this line in my logstash configuration :

```auto
useragent {
   source => "http_user_agent"
   target => "useragent"
}

```

In Kibana I can see the data, but kibana say to me "This field is not indexed thus unavailable for visualisation and search"

I didn't have problem with other field ? with this field aren't indexed ? I have the geoip plugin and field are correctly indexed.

In advance thanks

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 21, 2016, 4:35pm UTC](https://discuss.elastic.co/t/resolve-field-from-logstash-not-indexed/61144/2 "2016-09-21T16:35:40Z")

</div>

Hey,

the `useragent` field usually contains some more sub fields. Is it possible that you havent specified a concrete one?

--Alex

---

<div class="post-metadata">

**Author:** ![rdesgrange](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@rdesgrange](https://discuss.elastic.co/u/rdesgrange)\
**Post date:** [September 22, 2016, 7:58am UTC](https://discuss.elastic.co/t/resolve-field-from-logstash-not-indexed/61144/3 "2016-09-22T07:58:51Z")

</div>

what do you mean by concreate one.

I have several sub fields, like `build`, `device`, etc... but where do I need to specify these field in order to index it ?

The thing I don't understand is why `geoip` is indexed normaly (without any configuration) and not useragent.

---

<div class="post-metadata">

**Author:** ![rdesgrange](https://avatars.discourse-cdn.com/v4/letter/r/a5b964/32.png) [@rdesgrange](https://discuss.elastic.co/u/rdesgrange)\
**Post date:** [September 22, 2016, 8:15am UTC](https://discuss.elastic.co/t/resolve-field-from-logstash-not-indexed/61144/4 "2016-09-22T08:15:56Z")

</div>

Ok I refresh the kibana index in Settings/Indices, and it's now indexed.

Sorry, I though that the field wasn't index in elasticsearch ☹

Thanks for the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:18pm UTC](https://discuss.elastic.co/t/resolve-field-from-logstash-not-indexed/61144/5 "2017-07-05T22:18:15Z")

</div>


