# Strange Logstash index fields in visualization

**URL:** <https://discuss.elastic.co/t/strange-logstash-index-fields-in-visualization/101023>\
**Category:** Kibana\
**Created:** [September 19, 2017, 1:09pm UTC](https://discuss.elastic.co/t/strange-logstash-index-fields-in-visualization/101023 "2017-09-19T13:09:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [September 19, 2017, 1:09pm UTC](https://discuss.elastic.co/t/strange-logstash-index-fields-in-visualization/101023/1 "2017-09-19T13:09:18Z")

</div>

Hello, all.

I previously posted this in the Logstash forum, but was advised that this may be a better location. I hope I present my issue understandably.

I'm running Elastic Stack 5.6, and most things are working well. However, when I try to create a Logstash-based visualization in Kibana, and use "Terms" or "Significant Terms" for aggregation, I'm presented with fields in the pick list, which are strange to me. They look like this:

AccountType.keyword  
Action.keyword  
ActivityID.keyword

So, ".keyword" seems to be appended to all of the fields. I see the same fields in the "Index Patterns" in Kibana, and they list as "Aggregatable". But, they don't seem to be.

What am I doing wrong?

Thanks.

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [September 19, 2017, 4:45pm UTC](https://discuss.elastic.co/t/strange-logstash-index-fields-in-visualization/101023/2 "2017-09-19T16:45:43Z")

</div>

the `.keyword` fields are [multi-fields](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-fields.html) that are created for your fields mapped as `text`. When fields are mapped as `text`, they are tokenized by the analyzer so what is actually stored in Elasticsearch is a collection of tokens. So, although you _could_ aggregate on that field, the result probably wouldn't be what you are expecting.

The `.keyword` field is a non-tokenized copy of the text, and therefore should be aggregatable.

When you say:

> I see the same fields in the "Index Patterns" in Kibana, and they list as "Aggregatable". But, they don't seem to be.

What do you mean?

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [September 20, 2017, 1:14pm UTC](https://discuss.elastic.co/t/strange-logstash-index-fields-in-visualization/101023/3 "2017-09-20T13:14:04Z")

</div>

Thanks for the reply, BigFunger.

Well, OK, never mind about this: "I see the same fields in the "Index Patterns" in Kibana, and they list as "Aggregatable". But, they don't seem to be." But, are the .keyword fields the "usual" ones I should see, or should they be something else. I see the .keyword fields when I try to do a visualization when I try to use the logstash index. In fact, most of the fields available are of the .keyword variety. Would it be helpful for me to post my config files?

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [September 20, 2017, 3:47pm UTC](https://discuss.elastic.co/t/strange-logstash-index-fields-in-visualization/101023/4 "2017-09-20T15:47:26Z")

</div>

The `.keyword` fields are added because `text` fields are not really aggregatible in a meaningful way. If you have fields in your documents that you really want to be able to aggregate on the verbatim values, make sure you define them in your mapping as `keyword` type instead of `text`. If you are relying on the mappings created automatically by Elasticsearch (which in production, you shouldn't be) then string values are automatically mapped as a `text` field with a `keyword` multi-field.

ie:

```auto
# NOTE: text-test index does not exist.
POST text-test/doc/1
{
  "name": "jim unger"
}

GET text-test/_mapping

```

returns this:

```auto
{
  "text-test": {
    "mappings": {
      "doc": {
        "properties": {
          "name": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
        }
      }
    }
  }
}

```

Here is a blog post with more information:

> **[Elasticsearch replaces string type with two new types text and keyword.](https://www.elastic.co/blog/strings-are-dead-long-live-strings)**
>
> On using text types for full text search and keyword type for keyword search in Elasticsearch 5.0.

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [September 20, 2017, 5:01pm UTC](https://discuss.elastic.co/t/strange-logstash-index-fields-in-visualization/101023/5 "2017-09-20T17:01:02Z")

</div>

Thanks for the explanation. Alas, I'm not good at what I'll call "Elastic programming", so I don't know how to create/define mappings. I did run "GET filebeat-2017.09.20/\_mapping", and have posted it here ( [https://pastebin.com/RrgDSNUb](https://pastebin.com/RrgDSNUb) ), in case you're kind enough to take a look and, maybe, show me how I can change the mapping, if necessary.

Again, thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2017, 5:01pm UTC](https://discuss.elastic.co/t/strange-logstash-index-fields-in-visualization/101023/6 "2017-10-18T17:01:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
