# Shard failure. Fielddata disabled on text fields by default

**URL:** <https://discuss.elastic.co/t/shard-failure-fielddata-disabled-on-text-fields-by-default/89864>\
**Category:** Kibana\
**Created:** [June 18, 2017, 11:24pm UTC](https://discuss.elastic.co/t/shard-failure-fielddata-disabled-on-text-fields-by-default/89864 "2017-06-18T23:24:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![medelastic](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@medelastic](https://discuss.elastic.co/u/medelastic)\
**Post date:** [June 18, 2017, 11:24pm UTC](https://discuss.elastic.co/t/shard-failure-fielddata-disabled-on-text-fields-by-default/89864/1 "2017-06-18T23:24:17Z")

</div>

I am new to elastic stack. Aim is to visualize access logs data in kibana. I have taken a sample apache log from elastic stack documentation and used the following logstash configuration file:

input {

file {

```
path => "/tmp/access_log"

start_position => "beginning"

```

}

}

filter {

if [path] =~ "access" {

```
mutate { replace => { "type" => "apache_access" } }

grok {

  match => { "message" => "%{COMBINEDAPACHELOG}" }

}

```

}

date {

```
match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]

```

}

}

output {

elasticsearch { hosts =\> ["localhost:9200"]

user =\> username

password =\> password

index =\> "apache-access.log"

}

stdout { codec =\> rubydebug }

}

The script is working fine except for the part that some problem is with "timestamp" field.

Index: apache-access.log Shard: 0 Reason: {"type":"illegal\_argument\_exception","reason":"Fielddata is disabled on text fields by default. Set fielddata=true on [timestamp] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead."}

Plz help ASAP. Thank you

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 19, 2017, 12:16am UTC](https://discuss.elastic.co/t/shard-failure-fielddata-disabled-on-text-fields-by-default/89864/2 "2017-06-19T00:16:43Z")

</div>

Where does it say that exactly.

---

<div class="post-metadata">

**Author:** ![medelastic](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@medelastic](https://discuss.elastic.co/u/medelastic)\
**Post date:** [June 19, 2017, 1:18am UTC](https://discuss.elastic.co/t/shard-failure-fielddata-disabled-on-text-fields-by-default/89864/3 "2017-06-19T01:18:32Z")

</div>

In kibana "Discover" tab. When I search for the index I have saved this.

---

<div class="post-metadata">

**Author:** ![medelastic](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@medelastic](https://discuss.elastic.co/u/medelastic)\
**Post date:** [June 19, 2017, 11:31am UTC](https://discuss.elastic.co/t/shard-failure-fielddata-disabled-on-text-fields-by-default/89864/4 "2017-06-19T11:31:58Z")

</div>

@warkolm: On expanding a particular index in the discover tab. If I open any document of it then for **"tag"** it is showing **\_grokparsefailure**... However index is being created.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2017, 11:32am UTC](https://discuss.elastic.co/t/shard-failure-fielddata-disabled-on-text-fields-by-default/89864/5 "2017-07-17T11:32:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
