# "Saved 'field' parameter is now invalid" for SSH login attempts

**URL:** https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423
**Category:** Beats
**Tags:** filebeat
**Created:** [November 27, 2018, 9:42pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423 "2018-11-27T21:42:10Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)
#### Post date: [November 30, 2018, 8:53am UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423/2 "2018-11-30T08:53:38Z")

</div>

There is an open issue with this problem: [Saved `field` parameter is now invalid. · Issue #6489 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/6489)

I have found a possible workaround on the forum:

> [@Saved "field" parameter is now invalid. Please select a new field. .... Visualize: "field" is a required parameter](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field-visualize-field-is-a-required-parameter/70034/21):
>
> Okay, I may have a solution to fix your dashboards. Try re-running the metricbeat import script, and this time do not refresh the field list. This should bypass the field\_stats api and hopefully preserve the correct information for the field.

---

_[View the full topic](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-for-ssh-login-attempts/158423)._
