# Template fields are missing fields on Kibana

**URL:** <https://discuss.elastic.co/t/template-fields-are-missing-fields-on-kibana/23842>\
**Category:** Elasticsearch\
**Created:** [June 17, 2015, 1:35pm UTC](https://discuss.elastic.co/t/template-fields-are-missing-fields-on-kibana/23842 "2015-06-17T13:35:39Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Beatriz\_Mano](https://avatars.discourse-cdn.com/v4/letter/b/dc4da7/32.png) [@Beatriz\_Mano](https://discuss.elastic.co/u/Beatriz_Mano)\
**Post date:** [June 17, 2015, 1:35pm UTC](https://discuss.elastic.co/t/template-fields-are-missing-fields-on-kibana/23842/1 "2015-06-17T13:35:39Z")

</div>

Hi,  
I am new on Elasticsearch and I am having some troubles with accessing certain fields, in Kibana(4.1.0).  
(Therefore, my problem might be being caused by an obvious mistake.)  
I am using logstash (1.5.0) to load logs into elasticsearch(1.6.0). I am also using a template to do so. [template in the end of this post]

## Considering templates are applied to new data, I would expect my logs to get loaded using it. And I think they are. The problem is when I access Kibana, even though all fields appear on the settings, in the Discover tab, when I try to see some of them, they are considered "missing fields" and thus I cannot access them. Could the problem be on my template? Am I doing something absurdly wrong? I have searched online for similar issues, but I couldn't find anything, so I would really appreciate some help.

## template: curl -XPUT '[http://localhost:9200/\_template/billing](http://localhost:9200/_template/billing)' -d ' { "order":0, "template":"dcache-billing-_", "settings":{ "index.refresh\_interval":"5s" }, "mappings":{ "default":{ "dynamic\_templates":[{ "string\_fields":{ "mapping":{ "index":"analyzed", "omit\_norms":true, "type":"string", "fields":{ "raw":{ "index":"not\_analyzed", "ignore\_above":256, "type":"string" } } }, "match\_mapping\_type":"string", "match":"_" } }], "properties":{ "geoip":{ "dynamic":true, "path":"full", "properties":{ "location":{ "type":"geo\_point" } }, "type":"object" }, "@version":{ "index":"not\_analyzed", "type":"string" }, "pool\_name.raw":{ "index":"not\_analyzed", "type":"string" }, "sunit.raw":{ "index":"not\_analyzed", "type":"string" } }, "\_all":{ "enabled":true } } } } '

logstash config file  
input {  
file {  
path =\> "/nethome/beatriz/Downloads/small/billing-\*"  
#sincedb\_path =\> "/var/tmp/sincedb-dcache"  
# uncomment next line if you want to import existing data  
start\_position =\> beginning  
type =\> "dcache-billing"  
}  
}

filter {

if "RemoveFiles=" in [message] {

# Because RemoveFiles= is the only(source needed) non-conforming event.

```
grok {
  patterns_dir => "/etc/logstash/patterns"
  match => ["message", "%{REMOVE_ON_POOL}"]
  named_captures_only => true
  tag_on_failure => ["_parse_dcache_failure10"]
} # End of grok
mutate {
  split => ["pnfsids", ","]
  add_tag => ["dcache_billing_removed"]
} # End of Mutate to make a real list of the entries in pnfsids

```

} else {

grok {  
patterns\_dir =\> "/etc/logstash/patterns"  
match =\> ["message", "%{TRANSFER\_CLASSIC}"]  
match =\> ["message", "%{STORE\_CLASSIC}"]  
match =\> ["message", "%{RESTORE\_CLASSIC}"]  
match =\> ["message", "%{REQUEST\_CLASSIC}"]  
match =\> ["message", "%{REQUEST\_DCAP}"]  
match =\> ["message", "%{REMOVE\_CLASSIC}"]  
match =\> ["message", "%{REMOVE\_SRM}"]  
named\_captures\_only =\> true  
remove\_field =\> ["message"]  
tag\_on\_failure =\> ["\_parse\_dcache\_failure00"]  
}

} # End of if else

date {  
match =\> ["billing\_time", "MM.dd HH:mm:ss"]  
timezone =\> "CET"  
remove\_field =\> ["billing\_time"]  
}

alter {  
condrewrite =\> [  
"is\_write", "true", "write",  
"is\_write", "false", "read"  
]  
}  
}

output {  
elasticsearch {  
host =\> localhost  
index =\> "dcache-billing-%{+YYYY.MM.dd}"  
template\_name =\> "billing"  
protocol =\> "http"  
}  
}

* * *

Thanks in advance,  
Beatriz Mano

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 18, 2015, 2:53am UTC](https://discuss.elastic.co/t/template-fields-are-missing-fields-on-kibana/23842/2 "2015-06-18T02:53:31Z")

</div>

Have you changed the mapping since you added the indices into KB? If so you may need to refresh the field information that it loads.

---

<div class="post-metadata">

**Author:** ![Beatriz\_Mano](https://avatars.discourse-cdn.com/v4/letter/b/dc4da7/32.png) [@Beatriz\_Mano](https://discuss.elastic.co/u/Beatriz_Mano)\
**Post date:** [June 18, 2015, 6:42am UTC](https://discuss.elastic.co/t/template-fields-are-missing-fields-on-kibana/23842/3 "2015-06-18T06:42:11Z")

</div>

No, I have not. Should I change the mapping?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 18, 2015, 6:43am UTC](https://discuss.elastic.co/t/template-fields-are-missing-fields-on-kibana/23842/4 "2015-06-18T06:43:35Z")

</div>

Sorry I may have misunderstood you.

In KB4 under Settings, find the index you setup and refresh the field list and see if that helps.

---

<div class="post-metadata">

**Author:** ![Beatriz\_Mano](https://avatars.discourse-cdn.com/v4/letter/b/dc4da7/32.png) [@Beatriz\_Mano](https://discuss.elastic.co/u/Beatriz_Mano)\
**Post date:** [June 18, 2015, 6:51am UTC](https://discuss.elastic.co/t/template-fields-are-missing-fields-on-kibana/23842/5 "2015-06-18T06:51:13Z")

</div>

I have tried it. it does not work. Do you have any idea what could I being doing wrong?

---

<div class="post-metadata">

**Author:** ![simonrisberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simonrisberg/32/3513_2.png) [@simonrisberg](https://discuss.elastic.co/u/simonrisberg)\
**Post date:** [July 1, 2015, 12:20pm UTC](https://discuss.elastic.co/t/template-fields-are-missing-fields-on-kibana/23842/6 "2015-07-01T12:20:47Z")

</div>

In what kind of file to you write this and where is it located?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:04am UTC](https://discuss.elastic.co/t/template-fields-are-missing-fields-on-kibana/23842/7 "2017-07-06T00:04:16Z")

</div>


