# Right IPv6 Field,Wrong Visualize Display In Kibana

**URL:** <https://discuss.elastic.co/t/right-ipv6-field-wrong-visualize-display-in-kibana/26625>\
**Category:** Kibana\
**Created:** [July 31, 2015, 9:00am UTC](https://discuss.elastic.co/t/right-ipv6-field-wrong-visualize-display-in-kibana/26625 "2015-07-31T09:00:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roger\_Hsu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roger_hsu/32/73142_2.png) [@Roger\_Hsu](https://discuss.elastic.co/u/Roger_Hsu)\
**Post date:** [July 31, 2015, 9:00am UTC](https://discuss.elastic.co/t/right-ipv6-field-wrong-visualize-display-in-kibana/26625/1 "2015-07-31T09:00:10Z")

</div>

Hi,

I'm newbie on ELK Stack and test it about a Month ago.  
Got a issue with IPv6 field with many colon(🙂 ,when visualize like this

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1635866fbe998110062fbc26e2ed936e9a4ad885.png)

But search this field is right  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/7/7a17dc42acd2234d2a3db8a73a3aacc0a7a822cd.png)

Display full IPv6 string,no separate by colon(🙂 in visualize will better!  
Have any idea fix it?  
Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 31, 2015, 9:02am UTC](https://discuss.elastic.co/t/right-ipv6-field-wrong-visualize-display-in-kibana/26625/2 "2015-07-31T09:02:48Z")

</div>

Use the `.raw` version of the field instead.

---

<div class="post-metadata">

**Author:** ![Roger\_Hsu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roger_hsu/32/73142_2.png) [@Roger\_Hsu](https://discuss.elastic.co/u/Roger_Hsu)\
**Post date:** [August 3, 2015, 3:02pm UTC](https://discuss.elastic.co/t/right-ipv6-field-wrong-visualize-display-in-kibana/26625/3 "2015-08-03T15:02:40Z")

</div>

Thank you,warkolm.  
Although I can't find .raw file and have not fix this issue,because the indices using bulk api and import from another application,bypass Logstash.  
But I know if I can change mapping index to not\_analyzed when bulk api not auto mapping. After "agg" the IPv6 format will display correctly.  
Final stats \> NOT FIX!

---

<div class="post-metadata">

**Author:** ![Roger\_Hsu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roger_hsu/32/73142_2.png) [@Roger\_Hsu](https://discuss.elastic.co/u/Roger_Hsu)\
**Post date:** [August 4, 2015, 5:14am UTC](https://discuss.elastic.co/t/right-ipv6-field-wrong-visualize-display-in-kibana/26625/4 "2015-08-04T05:14:55Z")

</div>

Problem resolved.  
Use [Default Mapping](https://www.elastic.co/guide/en/elasticsearch/guide/current/default-mapping.html) let the field into not\_analyzed!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:15pm UTC](https://discuss.elastic.co/t/right-ipv6-field-wrong-visualize-display-in-kibana/26625/5 "2017-07-06T14:15:25Z")

</div>


