# \[SOLVED\] Visualize and raw field

**URL:** <https://discuss.elastic.co/t/solved-visualize-and-raw-field/49530>\
**Category:** Kibana\
**Created:** [May 9, 2016, 9:27am UTC](https://discuss.elastic.co/t/solved-visualize-and-raw-field/49530 "2016-05-09T09:27:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![axelfelix](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@axelfelix](https://discuss.elastic.co/u/axelfelix)\
**Post date:** [May 9, 2016, 9:27am UTC](https://discuss.elastic.co/t/solved-visualize-and-raw-field/49530/1 "2016-05-09T09:27:29Z")

</div>

Hi all,

I have a mapping like below:

> ```
> "properties" : {
> "@source_host" : {
> "type" : "string",
> "analyzer" : "custom-analyzer",
> "fields" : {
> "raw" : {
> "type" : "string",
> "index" : "not_analyzed"
> }
> }
> }
> ...
> 
> ```

When I make a search like below, it works:

> ```
> curl -XGET localhost:9200/logstash-2016.05.09/_search?pretty -d'
> {
> "query": {
> "match": { "@source_host": "test-20.corp"}
> }
> }'
> {
> "took" : 22,
> "timed_out" : false,
> "_shards" : {
> "total" : 20,
> "successful" : 20,
> "failed" : 0
> },
> "hits" : {
> "total" : 13922,
> "max_score" : 2.8506393,
> "hits" : [ {
> "_index" : "logstash-2016.05.09",
> "_type" : "cisco_log",
> "_id" : "AVSUoghihtVrl161fIgd",
> "_score" : 2.8506393,
> "_source" : {
> "message" : "2016-05-09T10:21:05+02:00 10.126.14.209 notice 2016 May 9 10:21:05.189 CEST: %ETHPORT-5-SPEED: Interface port-channel1016, operational speed changed to 10 Gbps",
> "@version" : "1",
> "@timestamp" : "2016-05-09T08:21:05.189Z",
> "host" : "127.0.0.1:40990",
> "type" : "cisco-ios",
> "syslog_host_time" : "2016-05-09T10:21:05+02:00",
> "client" : "10.10.10.1",
> "severity" : "notice",
> "client_date" : "2016 May 9 10:21:05.189 CEST",
> "facility" : "ETHPORT",
> "int_severity" : "5",
> "mnemonic" : "SPEED",
> "short_message" : "Interface port-channel1016, operational speed changed to 10 Gbps",
> "tags" : ["cisco_ios"],
> "@source_host" : "test-20.corp"
> }
> 
> ```

With the raw field, it's work too:

> ```
> curl -XGET localhost:9200/logstash-2016.05.09/_search?pretty -d'
> {
> "query": {
> "match": { "@source_host.raw": "test-20.corp"}
> }
> }'
> {
> "took" : 5,
> "timed_out" : false,
> "_shards" : {
> "total" : 20,
> "successful" : 20,
> "failed" : 0
> },
> "hits" : {
> "total" : 1690,
> "max_score" : 5.078534,
> "hits" : [ {
> "_index" : "logstash-2016.05.09",
> "_type" : "test_log",
> "_id" : "AVSUoiExhtVrl161fI41",
> "_score" : 5.078534,
> "_source" : {
> "message" : "2016-05-09T10:22:37+02:00 10.126.14.209 notice 2016 May 9 10:22:37.296 CEST: %ETHPORT-5-IF_TX_FLOW_CONTROL: Interface Ethernet150/1/16, operational Transmit Flow Control state changed to on",
> "@version" : "1",
> "@timestamp" : "2016-05-09T08:22:37.296Z",
> "host" : "127.0.0.1:40990",
> "type" : "cisco-ios",
> "syslog_host_time" : "2016-05-09T10:22:37+02:00",
> "client" : "10.10.10.1",
> "severity" : "notice",
> "client_date" : "2016 May 9 10:22:37.296 CEST",
> "facility" : "ETHPORT",
> "int_severity" : "5",
> "mnemonic" : "IF_TX_FLOW_CONTROL",
> "short_message" : "Interface Ethernet150/1/16, operational Transmit Flow Control state changed to on",
> "tags" : ["test"],
> "@source_host" : "test-20.corp"
> }
> 
> ```

So I don't understand why I can't retrieve the **"@source\_host.raw field"** in Visualize on Kibana.

Do you have any idea ?

Thanks,  
Alex

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [May 9, 2016, 6:54pm UTC](https://discuss.elastic.co/t/solved-visualize-and-raw-field/49530/2 "2016-05-09T18:54:46Z")

</div>

Do you see the field in the settings for that index? If not, try refreshing the field list.

---

<div class="post-metadata">

**Author:** ![axelfelix](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@axelfelix](https://discuss.elastic.co/u/axelfelix)\
**Post date:** [May 10, 2016, 11:49am UTC](https://discuss.elastic.co/t/solved-visualize-and-raw-field/49530/3 "2016-05-10T11:49:09Z")

</div>

Thanks for your reply !

I had to re-configure the index pattern in Kibana settings. And now I can see the .raw field.

I have some mapping conflict now but I see my new field 😉

Thanks again,  
Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:53pm UTC](https://discuss.elastic.co/t/solved-visualize-and-raw-field/49530/4 "2017-07-06T13:53:50Z")

</div>


