SearchParseException[Unknown key for a VALUE_STRING

Hi all,

I am running Kibana 4.1.3 and ES 2.1.0 and feeding logs into ES with logstash. Everything was working fine till I upgraded yesterday.

I removed the .kibana index and when configued the index pattern in the setting tab with out any issue. Now when I click on Disover I get a red bar with "Discover: An error occurred with your request. Reset your inputs and try again." I can find how one would do this.

The elastic logs show this. Any help would be appreciated

2015-12-02 11:59:03,019][DEBUG][action.search.type ] [oak] All shards failed for phase: [query]
RemoteTransportException[[ash][10.44.1.241:9300][indices:data/read/search[phase/query]]]; nested: SearchParseException[failed to parse search source [{"size":500,"sort":[{"@timestamp":{"order":"desc","unmapped_type":"boolean"}}],"highlight":{"pre_tags":["@kibana-highlighted-field@"],"post_tags":["@/kibana-highlighted-field@"],"fields":{"":{}},"fragment_size":2147483647},"aggs":{"2":{"date_histogram":{"field":"@timestamp","interval":"30s","pre_zone":"+00:00","pre_zone_adjust_large_interval":true,"min_doc_count":0,"extended_bounds":{"min":1449056642901,"max":1449057542901}}}},"query":{"filtered":{"query":{"match_all":{}},"filter":{"bool":{"must":[{"range":{"@timestamp":{"gte":1449056642902,"lte":1449057542902}}}],"must_not":[]}}}},"fields":["","_source"],"script_fields":{},"fielddata_fields":["@timestamp"]}]]; nested: SearchParseException[Unknown key for a VALUE_STRING in [2]: [pre_zone].];
Caused by: SearchParseException[failed to parse search source [{"size":500,"sort":[{"@timestamp":{"order":"desc","unmapped_type":"boolean"}}],"highlight":{"pre_tags":["@kibana-highlighted-field@"],"post_tags":["@/kibana-highlighted-field@"],"fields":{"":{}},"fragment_size":2147483647},"aggs":{"2":{"date_histogram":{"field":"@timestamp","interval":"30s","pre_zone":"+00:00","pre_zone_adjust_large_interval":true,"min_doc_count":0,"extended_bounds":{"min":1449056642901,"max":1449057542901}}}},"query":{"filtered":{"query":{"match_all":{}},"filter":{"bool":{"must":[{"range":{"@timestamp":{"gte":1449056642902,"lte":1449057542902}}}],"must_not":[]}}}},"fields":["","_source"],"script_fields":{},"fielddata_fields":["@timestamp"]}]]; nested: SearchParseException[Unknown key for a VALUE_STRING in [2]: [pre_zone].];
at org.elasticsearch.search.SearchService.parseSource(SearchService.java:848)
at org.elasticsearch.search.SearchService.createContext(SearchService.java:651)
at org.elasticsearch.search.SearchService.createAndPutContext(SearchService.java:617)
at org.elasticsearch.search.SearchService.executeQueryPhase(SearchService.java:368)
at org.elasticsearch.search.action.SearchServiceTransportAction$SearchQueryTransportHandler.messageReceived(SearchServiceTransportAction.java:368)
at org.elasticsearch.search.action.SearchServiceTransportAction$SearchQueryTransportHandler.messageReceived(SearchServiceTransportAction.java:365)
at org.elasticsearch.transport.netty.MessageChannelHandler$RequestHandler.doRun(MessageChannelHandler.java:299)
at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
at java.lang.Thread.run(Thread.java:745)
Caused by: SearchParseException[Unknown key for a VALUE_STRING in [2]: [pre_zone].]
at org.elasticsearch.search.aggregations.bucket.histogram.DateHistogramParser.parse(DateHistogramParser.java:105)
at org.elasticsearch.search.aggregations.AggregatorParsers.parseAggregators(AggregatorParsers.java:198)
at org.elasticsearch.search.aggregations.AggregatorParsers.parseAggregators(AggregatorParsers.java:103)
at org.elasticsearch.search.aggregations.AggregationParseElement.parse(AggregationParseElement.java:60)
at org.elasticsearch.search.SearchService.parseSource(SearchService.java:831)
... 10 more

You need Kibana 4.2 or above to work with ES 2.0 and above

/facepalm

How very stupid of me. Thanks Pieter.