# Sorting rows in Kibana based on keyword field

**URL:** <https://discuss.elastic.co/t/sorting-rows-in-kibana-based-on-keyword-field/109968>\
**Category:** Kibana\
**Created:** [December 1, 2017, 5:35pm UTC](https://discuss.elastic.co/t/sorting-rows-in-kibana-based-on-keyword-field/109968 "2017-12-01T17:35:25Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [December 5, 2017, 10:51pm UTC](https://discuss.elastic.co/t/sorting-rows-in-kibana-based-on-keyword-field/109968/5 "2017-12-05T22:51:10Z")

</div>

Hi Marin,

This is a confusing topic even to me and I've been working on Kibana for over 2 years. But here's the issue.  
It's all about the mapping of the field. Strings can be loaded into Elasticsearch as 2 different types `text` and `keyword` and they are commonly stored both ways. For example, in filebeat you should have `beat.name` and it should be sortable;

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/c/9cd48ac2d603516c35b53a5832f49fd693c0a47d.png)

If we go to the Dev Console and do a GET on the filebeat index mapping we see that beat.name is  
`"type": "keyword"`. The fact that it's a keyword makes it sortable.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d28ce245119acc50d57a6867e97c7a5872b48c91.png)

But if I look at logstash `host` field, I see it's not sortable. So let's go look at that mapping.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f2b7ebc142652e12153ce4d2eb50909fe8183341.png)

Here we see that `host` is `"type": "text"` which is not sortable. But below that there is a "fields" section with keyword of type: keyword.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/a/aab4376a22b3ab44218c7249ae074c87b86b8165.png)

If we go back to Discover and click the little settings gear in the field list, we can uncheck `Hide missing fields`. Now we see the `host.keyword` field.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/f/cf861c2ce8dd9e73ff0f35212b8f374c5585dccb.png)

We can add it to the doc view, and we'll see the sort arrow, but there won't be any data in it ☹

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/7/b78d20cbbfb25684c1db746f327ea77b9a8ebe7c.png)

That's because the Discover tab in Kibana only shows data that is in the source. And since this field was initially a text type, and the keyword is a derived type it doesn't work in Discover.

So for cases where you need to be able to sort, you need that field to be created as a keyword, and it could potentially have a derived text type.

So this;

```auto
"address_full": {
        "type": "keyword",
        "fields": {
          "search": {
            "type": "text",
            "fielddata": true
          }
        }
      }

```

Instead of this:

```auto
"address_full": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      }

```

You might be able to change the mapping so that you have the keyword field first, and the text field (if needed) as a derived type. This might require a reindex of the data. Here's a blog post about doing that;  
[https://www.elastic.co/blog/changing-mapping-with-zero-downtime](https://www.elastic.co/blog/changing-mapping-with-zero-downtime)

---

_[View the full topic](https://discuss.elastic.co/t/sorting-rows-in-kibana-based-on-keyword-field/109968)._
