# Saved "field" parameter is now invalid. Please select a new field

**URL:** <https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/244886>\
**Category:** Beats\
**Created:** [August 13, 2020, 1:11pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/244886 "2020-08-13T13:11:28Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abdelhalim](https://avatars.discourse-cdn.com/v4/letter/a/838e76/32.png) [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Post date:** [August 13, 2020, 1:11pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/244886/1 "2020-08-13T13:11:28Z")

</div>

hello everybody,

I am setting up ILM and I am having an error in kibana dashboards: Saved "field" parameter is now invalid. Please select a new field.

here are the steps that I followed:

Create ILM policy:

```auto
PUT _ilm/policy/hot-warm-cold-delete-60days-policy
{
  "policy": {
    "phases": {
      "hot": {
        "actions": {
          "rollover": {
            "max_size":"20gb",
            "max_age":"30d"
          },
          "set_priority": {
            "priority": 50
          }
        }
      },
      "warm": {
        "actions": {
          "forcemerge": {
            "max_num_segments": 1
          },
          "shrink": {
            "number_of_shards": 1
          },
          "allocate": {
            "require": {
              "data": "warm"
            }
          },
          "set_priority": {
            "priority": 25
          }
        }
      },
      "cold": {
        "min_age": "30d",
        "actions": {
          "set_priority": {
            "priority": 0
          },
          "freeze": {},
          "allocate": {
            "require": {
              "data": "cold"
            }
          }
        }
      },
      "delete": {
        "min_age": "60d",
        "actions": {
          "delete": {}
        }
      }
    }
  }
}

```

Create a template:

```auto

PUT _template/winlogbeat
{
  "index_patterns": ["winlogbeat-*"], 
  "settings": {
    "number_of_shards": 40,
    "number_of_replicas": 1,
    "index.lifecycle.name": "hot-warm-cold-delete-60days-policy",  
    "index.lifecycle.rollover_alias": "winlogbeat"
  }
}

```

Bootstrap the first index:

```auto
PUT winlogbeat-000001
{
  "aliases": {
    "winlogbeat": {
      "is_write_index": true
    }
  }
}

```

Winlogbeat.yml configuration:

```auto
setup.ilm.enabled: auto
setup.ilm.rollover_alias: "winlogbeat"
setup.ilm.pattern: "000001"
setup.ilm.policy_name: "hot-warm-cold-delete-60days-policy"
setup.template.name: "winlogbeat"	
setup.template.pattern: "winlogbeat-*"
setup.template.overwrite: true
setup.template.settings:
  index.number_of_shards: 40
  index.number_of_replicas: 1

```

run Winlogbeat:

```auto
.\winlogbeat.exe setup -e
Start-Service winlogbeat

```

could someone tell me where is the mistake here please !!  
thanks !

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [August 13, 2020, 4:36pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/244886/2 "2020-08-13T16:36:09Z")

</div>

What does the following Elasticsearch API call return?

```auto
GET _cat/templates/win*

```

Shaunak

---

<div class="post-metadata">

**Author:** ![Abdelhalim](https://avatars.discourse-cdn.com/v4/letter/a/838e76/32.png) [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Post date:** [August 14, 2020, 6:57am UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/244886/3 "2020-08-14T06:57:58Z")

</div>

Thanks for your answer @shaunak,  
when I run:

```auto
GET _cat/templates/win*

```

I get this output :

```auto
winlogbeat [winlogbeat-*] 1  

```

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [August 14, 2020, 5:14pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/244886/4 "2020-08-14T17:14:55Z")

</div>

Great. Next, let's look at the contents of that index template:

```auto
GET _template/winlogbeat

```

Also, I forgot to ask before: what versions of Winlogbeat and Elasticsearch are you running?

Thanks,

Shaunak

---

<div class="post-metadata">

**Author:** ![Abdelhalim](https://avatars.discourse-cdn.com/v4/letter/a/838e76/32.png) [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Post date:** [August 17, 2020, 7:12am UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/244886/5 "2020-08-17T07:12:41Z")

</div>

Hello,  
I am using Elasticsearch from source code, so it's (8.0), with winlogbeat 7.8.0

when I run:

```auto
GET _template/winlogbeat

```

I get this output: (I AM sorry to use an image, cause The number of caracters is limited )

 ![Output](https://us1.discourse-cdn.com/elastic/original/3X/4/d/4def39ec87b25aebef9cc70dbb73642da3f50900.png)

---

<div class="post-metadata">

**Author:** ![Abdelhalim](https://avatars.discourse-cdn.com/v4/letter/a/838e76/32.png) [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Post date:** [August 17, 2020, 11:19am UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/244886/6 "2020-08-17T11:19:49Z")

</div>

I tried these steps:

**1- Re-index Data**

```auto
POST _reindex
{
  "source": {
    "index": "winlogbeat-000001"
  },
  "dest": {
    "index": "winlogbeat-000002"
  }
}

```

**2- Point the new index to the alias:**

```auto
POST _aliases
{
  "actions": [
    { "add": {
          "alias": "winlogbeat",
          "index": "winlogbeat-000002"
        }}
      ]
}

```

**3- Stop winlogbeat:** Stop-Service winlogbeat  
**4- setup again dashboard:**.\winlogbeat.exe setup --dashboards  
**5- Start winlogbeat** Start-Service winlogbeat  
**6- Refresh Winlogbeat index from kibana**

Now the dashboards are working still just have one error in one dashboard :

```auto
Could not locate that index-pattern-field (id: winlog.event_data.OldTargetUserName)

```

---

<div class="post-metadata">

**Author:** ![Abdelhalim](https://avatars.discourse-cdn.com/v4/letter/a/838e76/32.png) [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Post date:** [August 17, 2020, 1:15pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/244886/7 "2020-08-17T13:15:31Z")

</div>

I tried to use Winlogbeat 7.8.1 from code source, and I had the same issue, and when I try the same method that I used with winlogbeat 7.8.0 some dashboards don't work  
I have 2 errors:

```auto
Could not locate that index-pattern-field (id: winlog.logon.id)

```

and

```auto
Could not locate that index-pattern-field (id: winlog.event_data.OldTargetUserName)

```

Could someone help me with these errors please !

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2020, 1:15pm UTC](https://discuss.elastic.co/t/saved-field-parameter-is-now-invalid-please-select-a-new-field/244886/8 "2020-09-14T13:15:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
