# \[SOLVED\] Visualization shortens beats.name

**URL:** https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561
**Category:** Beats
**Created:** [February 11, 2016, 11:02pm UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561 "2016-02-11T23:02:19Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)
#### Post date: [February 11, 2016, 11:02pm UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561/1 "2016-02-11T23:02:19Z")

</div>

I've loaded the example beats dashboards/searches/visualizations into Kibana. They are definitely working. Except that a lot of [beat.name](http://beat.name) data is truncated/abbreviated.

This is only the Topbeat dashboard/etc. since I only have it and Filebeat running.

As in, `pre-prod-example-01.example.tld` becomes just `example` or `pre` or `01`.

I see this in the legends of the System Load and Process Status visualizations. It also occurs in the [beats.name](http://beats.name) column of the Servers visualization.

Is there a way to prevent that form happening? 01 is hardly useful when you multiple servers ending in -01. I'd rather have it wrap or something than what it is doing.

Thanks!

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [February 12, 2016, 12:59pm UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561/2 "2016-02-12T12:59:22Z")

</div>

Have you loaded applied the indexes to elasticsearch before installing the dashboards and before indexing data via beats?

---

<div class="post-metadata">

### Author: ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)
#### Post date: [February 12, 2016, 4:55pm UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561/3 "2016-02-12T16:55:01Z")

</div>

I'm not entirely sure what you mean. I was indexing data from filebeat and topbeat before I installed the example dashboards.

I checked out the dashboard project, modified it to use my index name instead of topbeat, and then ran the [load.sh](http://load.sh) script.

What does "applied the indexes" mean? I thought an index was similar to a database in sql.

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [February 16, 2016, 4:29pm UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561/4 "2016-02-16T16:29:16Z")

</div>

sorry, typo. I meant to write: have you applied the index templates as described in getting started guide before indexing any data?

---

<div class="post-metadata">

### Author: ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)
#### Post date: [February 16, 2016, 5:25pm UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561/5 "2016-02-16T17:25:15Z")

</div>

I may have made a bad assumption. Topbeat is sending to Logstash, so I assumed Logstash would deal with the template aspect. Plus, since I'm not using an index of "topbeat", I didn't think those templates would apply.

I have read the elasticsearch docs on templates, but maybe I missed something...

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [February 17, 2016, 6:55am UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561/6 "2016-02-17T06:55:08Z")

</div>

Having a template is not mandatory in elasticsearch/logstash. If data is processed by logstash, you have to take care of the mappings in the generated index. Problem is the strings (which is default) are analyzed if not disabled by mapping. Templates can be used to specify a mapping to be used with newly created indexes.

---

<div class="post-metadata">

### Author: ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)
#### Post date: [February 17, 2016, 4:46pm UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561/7 "2016-02-17T16:46:17Z")

</div>

Ah, so I need to take the topbeat template, and the logstash template, and merge them together.

Thanks for the help!

---

<div class="post-metadata">

### Author: ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)
#### Post date: [February 18, 2016, 12:47am UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561/8 "2016-02-18T00:47:37Z")

</div>

And, after the index rolled over to the next day, it appears it is working the way I wanted. Thanks again!

For reference, this is the template I'm using on my 2.2.0 logstash indexer:

> <https://gist.github.com/jerrac/c6b2ade878a2e1ffe4c9>

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [February 18, 2016, 4:49pm UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561/9 "2016-02-18T16:49:55Z")

</div>

Glad to hear it worked. The template cannot be changed on existing indices but will be applied to new ones. That explains why it worked on the next day.

---

<div class="post-metadata">

### Author: ![jerrac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jerrac/32/52980_2.png) [@jerrac](https://discuss.elastic.co/u/jerrac)
#### Post date: [February 18, 2016, 5:09pm UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561/10 "2016-02-18T17:09:39Z")

</div>

> [@ruflin](#):
>
> The template cannot be changed on existing indices but will be applied to new ones. That explains why it worked on the next day.

Yep, the docs are pretty clear on that.

Does discourse have a "mark solved" button, or should I just edit the title of my initial post?

---

<div class="post-metadata">

### Author: ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)
#### Post date: [February 18, 2016, 5:28pm UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561/11 "2016-02-18T17:28:43Z")

</div>

I don't think so. There is a close option but I don't think that is what we want to do in case someone wants to comment in the future. Editing title is definitively an option.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 9:55pm UTC](https://discuss.elastic.co/t/solved-visualization-shortens-beats-name/41561/12 "2017-07-05T21:55:34Z")

</div>


