Strange Logstash index fields


#1

Good morning or afternoon, folks.

I hope I present my issue understandably, and in the right forum.

I'm running Elastic Stack 5.6, and most things are working well. However, when I try to create a Logstash-based visualization in Kibana, and use "Terms" or "Significant Terms" for aggregation, I'm presented with fields in the pick list, which are strange to me. They look like this:

AccountType.keyword
Action.keyword
ActivityID.keyword

So, ".keyword" seems to be appended to all of the fields. I see the same fields in the "Index Patterns" in Kibana, and they list as "Aggregatable". But, they don't seem to be.

What am I doing wrong?

Thanks.


#2

Oh, my config files: https://pastebin.com/9cmeXGEU


(Nachiket) #3

There is absolutely nothing wrong that you are doing.
This question should ideally fall under kibana or elasticsearch. The keyword that you see appended is because of something called as analyzers.

https://www.elastic.co/guide/en/elasticsearch/reference/current/keyword.html

Regards,
N


#4

Thanks, NerdSec. I'll try in another forum.


(system) #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.