# "Saved 'field' parameter is now invalid" for SSH login attempts

**URL:** <https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 27, 2018, 9:42pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423 "2018-11-27T21:42:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tuxedojoe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuxedojoe/32/38145_2.png) [@tuxedojoe](https://discuss.elastic.co/u/tuxedojoe)\
**Post date:** [November 27, 2018, 9:42pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423/1 "2018-11-27T21:42:10Z")

</div>

Hi,

I'm very new to ELK and followed this guide:

> **[How To Install Elasticsearch, Logstash, and Kibana (Elastic Stack) on Ubuntu...](https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-logstash-and-kibana-elastic-stack-on-ubuntu-18-04)**
>
> In this tutorial, we will go over the installation of the Elastic Stack on an Ubuntu 18.04 server. You will learn how to install all the components of the Elastic Stack (including Filebeat, a Beat used for forwarding and centralizing logs and files)...

It all went relatively smooth until I got the stack running. The imported dashboards is not working. I get the logs but all the preloaded dashboards give me a: "Saved 'field' parameter is now invalid" error.

The logs are there but the dashboards are not working. Have I imported a old versions of dashboards? How to remove and install new ones?

Or how do I proceed otherwise?

I've recently updated everything to the latest version. 6.5.1. Running on Ubuntu 18.04.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [November 30, 2018, 8:53am UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423/2 "2018-11-30T08:53:38Z")

</div>

There is an open issue with this problem: [Saved `field` parameter is now invalid. · Issue #6489 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/6489)

I have found a possible workaround on the forum:

> [@Saved "field" parameter is now invalid. Please select a new field. .... Visualize: "field" is a required parameter](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field-visualize-field-is-a-required-parameter/70034/21):
>
> Okay, I may have a solution to fix your dashboards. Try re-running the metricbeat import script, and this time do not refresh the field list. This should bypass the field\_stats api and hopefully preserve the correct information for the field.

---

<div class="post-metadata">

**Author:** ![tuxedojoe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuxedojoe/32/38145_2.png) [@tuxedojoe](https://discuss.elastic.co/u/tuxedojoe)\
**Post date:** [December 4, 2018, 7:14pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423/3 "2018-12-04T19:14:51Z")

</div>

Thanks. But I only have filebeat, not metricbeat. Can I do the same procedure for filebeat? And if so, how?

---

<div class="post-metadata">

**Author:** ![tuxedojoe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tuxedojoe/32/38145_2.png) [@tuxedojoe](https://discuss.elastic.co/u/tuxedojoe)\
**Post date:** [December 4, 2018, 7:41pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423/4 "2018-12-04T19:41:06Z")

</div>

I deleted the indexes from filebeat using curl -XDELETE [http://localhost:9200/\*](http://localhost:9200/*)

Then I loaded the template again:  
`sudo filebeat setup --template -E output.logstash.enabled=false -E 'output.elasticsearch.hosts=["localhost:9200"]'`

And then finally loaded dashboards again with  
`sudo filebeat setup -e -E output.logstash.enabled=false -E output.elasticsearch.hosts=['localhost:9200'] -E setup.kibana.host=localhost:5601`

That solved it. However, now I only get new logs (created after I created the new indexes. How do I fix that?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 1, 2019, 7:41pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423/5 "2019-01-01T19:41:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
