# "Saved field parameter is now invalid" error after installing logstash netflow

**URL:** <https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-error-after-installing-logstash-netflow/129876>\
**Category:** Kibana\
**Created:** [April 27, 2018, 7:18pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-error-after-installing-logstash-netflow/129876 "2018-04-27T19:18:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bbrendon](https://avatars.discourse-cdn.com/v4/letter/b/3e96dc/32.png) [@bbrendon](https://discuss.elastic.co/u/bbrendon)\
**Post date:** [April 27, 2018, 7:18pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-error-after-installing-logstash-netflow/129876/1 "2018-04-27T19:18:46Z")

</div>

I recently upgrade from ELK 5 to 6 and today I added the logstash netflow to my system. It looks like everything went okay (but isn't). Netflow docs are being stored in elastic and the dashboards and visualizations are listed.

The issue is that all of the dashboards and visualizations throw errors like below...  
[![](https://i.imgur.com/yD3jzTr.png) ](https://i.imgur.com/yD3jzTr.png)

Error : Saved "field" parameter is now invalid. Please select a new field.  
Visualize: "field" is a required parameter

I have a feeling this is happening because I have an upgraded system but I really have no idea as I'm not an ELK expert.

Looking at the specific visualization i'm having a problem with it shows the netflow.bytes is searchable and aggregatable.

Any ideas how to figure this out?

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [April 27, 2018, 7:33pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-error-after-installing-logstash-netflow/129876/2 "2018-04-27T19:33:09Z")

</div>

Is this a visualization that you exported/imported or is it one you created from scratch?

There's an open issue on GitHub about this error, and there are a few situations which can cause it, maybe something in that discussion will help: [https://github.com/elastic/kibana/issues/9571](https://github.com/elastic/kibana/issues/9571)

---

<div class="post-metadata">

**Author:** ![bbrendon](https://avatars.discourse-cdn.com/v4/letter/b/3e96dc/32.png) [@bbrendon](https://discuss.elastic.co/u/bbrendon)\
**Post date:** [April 27, 2018, 7:52pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-error-after-installing-logstash-netflow/129876/3 "2018-04-27T19:52:55Z")

</div>

These were created by logstash. Looking at that link do I edit the visualizations and everywhere I see "source\_name" and rename it to "source\_name.keyword" ?

If so, is there a script that can do it? This would take a very long time as there are 78 visualizations that have to be fixed.

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [May 1, 2018, 5:26pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-error-after-installing-logstash-netflow/129876/4 "2018-05-01T17:26:04Z")

</div>

Well one thing you could do is export everything, do a simple find/replace, and re-import.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2018, 5:26pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-error-after-installing-logstash-netflow/129876/5 "2018-05-29T17:26:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
