# \_size pluging not creating field 6.2.4

**URL:** <https://discuss.elastic.co/t/size-pluging-not-creating-field-6-2-4/132169>\
**Category:** Elasticsearch\
**Created:** [May 16, 2018, 3:52pm UTC](https://discuss.elastic.co/t/size-pluging-not-creating-field-6-2-4/132169 "2018-05-16T15:52:57Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)\
**Post date:** [May 16, 2018, 3:52pm UTC](https://discuss.elastic.co/t/size-pluging-not-creating-field-6-2-4/132169/1 "2018-05-16T15:52:57Z")

</div>

Hey everyone,  
I'm trying to get the \_size plugin to work and am kind of stuck here. I installed it on every node in my cluster via a rolling restart. I think added the \_size enabled to my mapping template and rolled over the index. Yet when I search on the new index there is no \_size field. Any directions would be helpful.

Beginning of Mapping:

```
{
  "x-2018.05.16-1": {
    "mappings": {
      "doc": {
        "_size": {
          "enabled": true
        },
        "properties": {
          "@timestamp": {
            "type": "date"
          },

```

Query against the index:

```
  {
    "_index": "x-2018.05.16-1",
    "_type": "doc",
    "_id": "rOuhaWMBQY84VxJFIVU_",
    "_score": 1,
    "_source": {
      "prospector": {},
      "pid": "10163",
      "source": "/var/log/xt/api-gateway.log",
      "program": "api-gateway",
      "message": "gateway.plugin.httpproxy.transport elapsed=22.060988ms",
      "error": "x Go Pipeline",
      "tags": [
        "Engineering-api-gateway"
      ],
      "hostname": "ip-10-10-41-38",
      "@timestamp": "2018-05-16T15:45:16.540Z",
      "beat": {
        "hostname": "ip-10-10-41-38"
      },
      "Level": "INFO",
      "fields": {
        "app_name": "api-gateway",
        "class": "x"
      }
    }
  }
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 16, 2018, 4:06pm UTC](https://discuss.elastic.co/t/size-pluging-not-creating-field-6-2-4/132169/2 "2018-05-16T16:06:49Z")

</div>

If you expect to see it you're wrong IMO.  
Elasticsearch does not modify the \_source.

But you can probably query it or if it's stored ask to get back this field explicitly instead of (or in addition to) default \_source field.

---

<div class="post-metadata">

**Author:** ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)\
**Post date:** [May 16, 2018, 4:19pm UTC](https://discuss.elastic.co/t/size-pluging-not-creating-field-6-2-4/132169/3 "2018-05-16T16:19:06Z")

</div>

Isn't that the point of this ES plugin though? And shouldn't I see it as a field when queried? Maybe this page is a bit misleading then? [https://www.elastic.co/guide/en/elasticsearch/plugins/current/mapper-size.html](https://www.elastic.co/guide/en/elasticsearch/plugins/current/mapper-size.html)

---

<div class="post-metadata">

**Author:** ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)\
**Post date:** [May 16, 2018, 4:34pm UTC](https://discuss.elastic.co/t/size-pluging-not-creating-field-6-2-4/132169/4 "2018-05-16T16:34:07Z")

</div>

Ahh ok interesting, so this can only be queried as a scripted field. Any thoughts on adding this field to a document and if this is a bad idea and destined to cause a performance hit on high volume clusters?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 16, 2018, 4:34pm UTC](https://discuss.elastic.co/t/size-pluging-not-creating-field-6-2-4/132169/5 "2018-05-16T16:34:09Z")

</div>

I think this page is clear though: [https://www.elastic.co/guide/en/elasticsearch/plugins/current/mapper-size-usage.html](https://www.elastic.co/guide/en/elasticsearch/plugins/current/mapper-size-usage.html)

---

<div class="post-metadata">

**Author:** ![djtecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djtecha/32/54011_2.png) [@djtecha](https://discuss.elastic.co/u/djtecha)\
**Post date:** [May 16, 2018, 4:47pm UTC](https://discuss.elastic.co/t/size-pluging-not-creating-field-6-2-4/132169/6 "2018-05-16T16:47:36Z")

</div>

Any idea on if this can be a scripted field in Kibana? trying things like doc['\_size'].value but no luck

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 16, 2018, 4:59pm UTC](https://discuss.elastic.co/t/size-pluging-not-creating-field-6-2-4/132169/7 "2018-05-16T16:59:41Z")

</div>

I think you can do it in index management.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 13, 2018, 4:59pm UTC](https://discuss.elastic.co/t/size-pluging-not-creating-field-6-2-4/132169/8 "2018-06-13T16:59:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
