# SIEM does not show data

**URL:** <https://discuss.elastic.co/t/siem-does-not-show-data/229010>\
**Category:** SIEM\
**Created:** [April 21, 2020, 9:47am UTC](https://discuss.elastic.co/t/siem-does-not-show-data/229010 "2020-04-21T09:47:32Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [April 21, 2020, 2:29pm UTC](https://discuss.elastic.co/t/siem-does-not-show-data/229010/3 "2020-04-21T14:29:05Z")

</div>

@Minh_Ti_n_Tr_n,

It looks like you haven't pushed a set of mappings and that's why it is giving you this message below. Although this advice it is giving you looks "good" on the surface it really isn't and is _not_ what you want to do to fix your mapping issues.

> Fielddata is disabled on text fields by default. Set fielddata=true on [source.ip] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory. Alternatively use a keyword field instead

^ Avoid doing this in favor of using correct mappings. This has serious consequences and not what you want.

What you want to do is to "push" your filebeat template mappings and ILM poloicies if your beats have access to your Elasticsearch cluster like so:

> **[Load the Elasticsearch index template | Filebeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html)**

You might have to overwrite your current mappings that you have for filebeat and you might have to reindex your data as well once completed. I can't make assumptions about how sensitive or the volume of your data so I can only recommend you back up anything important first through [snapshots](https://www.elastic.co/guide/en/elasticsearch/reference/current/backup-cluster-data.html) and then perform any and all steps to get a valid mapping.

Here are earlier threads that go into more detail about it that others have encountered when they accidentally do not set their mappings below. In a nutshell when your templates and mappings are not setup what is happening is that all your data is "auto creating mappings" for its data types such as "source.ip" being mapped to a "text field" when in reality it should be a field type of "ip".

> [@SIEM doesn't show any Winlogbeat events, despite ES receiving them](https://discuss.elastic.co/t/siem-doesnt-show-any-winlogbeat-events-despite-es-receiving-them/224008/10):
>
> @Aura, ahhh, I think I might see what's going on. I bet when you first setup winlog beat you accidentally forgot to push your templates which control the mapping? [https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html) You can check your mapping in your dev tools: [Screen Shot 2020-04-10 at 7.47.05 AM] like so....To see the entire mapping of your winlog beats: GET winlogbeat-7.6.0/\_mapping If you want to just concentrate on…

---

_[View the full topic](https://discuss.elastic.co/t/siem-does-not-show-data/229010)._
