String field shows up in Discovery but not in Visualize


(Jon Slusher) #1

I started indexing our elasticsearch slowlogs to our ELK stack and I'm seeing some strange behavior with the es_source field, which I'm trying to use in a visualization.

On the Discover page in kibana, I have a saved search with several hits that all contain a string field I named es_source. In that field are the values from the source section of the ES slowlogs. On the Visualize page however, if I create any visualization and try to use the es_source.raw field in terms, it only shows 4 results. The only difference I can see is that the 4 results that show up are a lot smaller than the results that don't show up. I set the source limit in elasticsearch at the default 1000 characters. Is there something in Kibana that would limit the Visualization results? Has anyone seen something like this before?


(Lee Drengenberg) #2

When you say;

I'm assuming it's more than 4 hits?

If the default source limit in elasticsearch is 1000 characters (I'm not sure), why would you explicitly set that? I know I've done tests with string fields over 4000 characters long. Maybe 8000.

See See Field maxlength?

Regards,
Lee


(system) #3