# Searching logs by host name

**URL:** <https://discuss.elastic.co/t/searching-logs-by-host-name/316388>\
**Category:** Kibana\
**Tags:** ecs-elastic-common-schema\
**Created:** [October 12, 2022, 12:16am UTC](https://discuss.elastic.co/t/searching-logs-by-host-name/316388 "2022-10-12T00:16:13Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![rsk0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsk0/32/124810_2.png) [@rsk0](https://discuss.elastic.co/u/rsk0)\
**Post date:** [October 19, 2022, 2:38am UTC](https://discuss.elastic.co/t/searching-logs-by-host-name/316388/5 "2022-10-19T02:38:26Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/3/239edeb7a1d6b25fae04dcd168596881c592fffe.png)

I can see for some fields Kibana recognizes them as multi-fields, but when I add a `host.name.text` multi-field, its parent `host.name` doesn't show up as having a multi-field.

I don't see any real difference in the index mappings:

```auto
"process": {
  "properties": {
    "executable": {
      "type": "text",
      "fields": {
        "keyword": {
          "type": "keyword",
          "ignore_above": 256

```

v.

```auto
"host": {
  "properties": {
    "name": {
      "type": "keyword",
      "fields": {
        "text": {
          "type": "text"

```

---

_[View the full topic](https://discuss.elastic.co/t/searching-logs-by-host-name/316388)._
