# Topbeat beat.hostname analyzed

**URL:** https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930
**Category:** Beats
**Created:** [December 10, 2015, 11:33pm UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930 "2015-12-10T23:33:38Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![jderieg](https://avatars.discourse-cdn.com/v4/letter/j/7c8e57/32.png) [@jderieg](https://discuss.elastic.co/u/jderieg)
#### Post date: [December 10, 2015, 11:33pm UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930/1 "2015-12-10T23:33:38Z")

</div>

Hi there,  
I noticed that after I load in the topbeat template, and create an index pattern for topbeat, the 'beat.hostname' field is analyzed. I'm kind of a noob with beats/elasticsearch... could someone help me to change that field to non\_analyzed? I've read through the Mapping docs, but i'm still unsure how to do it.  
Having this field analyzed causes problems with hostnames that have a dash (-) in them because it sees it as 2 separate entities. What's odd is that in filebeat, this same field is not analyzed.

Thanks!  
-James

---

<div class="post-metadata">

### Author: ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)
#### Post date: [December 11, 2015, 9:29am UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930/2 "2015-12-11T09:29:36Z")

</div>

Topbeat and Filebeat have similar templates and the result should be the same. I have tried it on my computer and it works fine for me.  
What version of Elasticsearch and Topbeat are you using?

---

<div class="post-metadata">

### Author: ![jderieg](https://avatars.discourse-cdn.com/v4/letter/j/7c8e57/32.png) [@jderieg](https://discuss.elastic.co/u/jderieg)
#### Post date: [December 11, 2015, 4:19pm UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930/3 "2015-12-11T16:19:30Z")

</div>

I had the topbeat 1.0.0-rc1 template installed, but I just updated the template to 1.0.0 yesterday to see if that would fix the problem, but it didn't.  
I'm using elasticsearch 2.0.0.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/7/710439b2516a3359d710c52e799951c346191522.png)

---

<div class="post-metadata">

### Author: ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)
#### Post date: [December 11, 2015, 4:56pm UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930/4 "2015-12-11T16:56:44Z")

</div>

How did you install the template? Did you follow the steps from: [https://www.elastic.co/guide/en/beats/topbeat/current/topbeat-getting-started.html#topbeat-template](https://www.elastic.co/guide/en/beats/topbeat/current/topbeat-getting-started.html#topbeat-template) ? Thanks!

---

<div class="post-metadata">

### Author: ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)
#### Post date: [December 11, 2015, 5:13pm UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930/5 "2015-12-11T17:13:55Z")

</div>

Can you please send me what you loaded already under the template?

```
curl -XGET 'http://127.0.0.1:9200/_template/topbeat?pretty'
```

where 127.0.0.1:9200 is the URL where Elasticsearch is available.

---

<div class="post-metadata">

### Author: ![jderieg](https://avatars.discourse-cdn.com/v4/letter/j/7c8e57/32.png) [@jderieg](https://discuss.elastic.co/u/jderieg)
#### Post date: [December 11, 2015, 5:44pm UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930/6 "2015-12-11T17:44:25Z")

</div>

Yup, I followed that doc exactly. Here's the output of that command:

{  
"topbeat" : {  
"order" : 0,  
"template" : "topbeat-_",  
"settings" : {  
"index" : {  
"refresh\_interval" : "5s"  
}  
},  
"mappings" : {  
"default" : {  
"dynamic\_templates" : [ {  
"template1" : {  
"mapping" : {  
"ignore\_above" : 1024,  
"index" : "not\_analyzed",  
"type" : "{dynamic\_type}",  
"doc\_values" : true  
},  
"match" : "_"  
}  
} ],  
"\_all" : {  
"norms" : {  
"enabled" : false  
},  
"enabled" : true  
},  
"properties" : {  
"proc" : {  
"properties" : {  
"mem" : {  
"properties" : {  
"rss\_p" : {  
"type" : "float",  
"doc\_values" : "true"  
}  
}  
},  
"cpu" : {  
"properties" : {  
"user\_p" : {  
"type" : "float",  
"doc\_values" : "true"  
}  
}  
}  
}  
},  
"@timestamp" : {  
"type" : "date"  
},  
"load" : {  
"properties" : {  
"load5" : {  
"type" : "float",  
"doc\_values" : "true"  
},  
"load1" : {  
"type" : "float",  
"doc\_values" : "true"  
},  
"load15" : {  
"type" : "float",  
"doc\_values" : "true"  
}  
}  
},  
"mem" : {  
"properties" : {  
"used\_p" : {  
"type" : "float",  
"doc\_values" : "true"  
},  
"actual\_used\_p" : {  
"type" : "float",  
"doc\_values" : "true"  
}  
}  
},  
"swap" : {  
"properties" : {  
"used\_p" : {  
"type" : "float",  
"doc\_values" : "true"  
},  
"actual\_used\_p" : {  
"type" : "float",  
"doc\_values" : "true"  
}  
}  
},  
"cpu" : {  
"properties" : {  
"user\_p" : {  
"type" : "float",  
"doc\_values" : "true"  
},  
"system\_p" : {  
"type" : "float",  
"doc\_values" : "true"  
}  
}  
},  
"fs" : {  
"properties" : {  
"used\_p" : {  
"type" : "float",  
"doc\_values" : "true"  
}  
}  
}  
}  
}  
},  
"aliases" : { }  
}  
}

---

<div class="post-metadata">

### Author: ![monica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monica/32/3696_2.png) [@monica](https://discuss.elastic.co/u/monica)
#### Post date: [December 11, 2015, 5:52pm UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930/7 "2015-12-11T17:52:17Z")

</div>

Can you please delete the old topbeat indices to make sure the "not\_analyzed" is coming from the new indices created after you applied the template?

```
curl -XDELETE 'http://127.0.0.1:9200/topbeat-*'
```

After that you can refresh the topbeat index pattern in Kibana (from the Settings page) to see if it's set to "not\_analyzed".

---

<div class="post-metadata">

### Author: ![jderieg](https://avatars.discourse-cdn.com/v4/letter/j/7c8e57/32.png) [@jderieg](https://discuss.elastic.co/u/jderieg)
#### Post date: [December 11, 2015, 6:00pm UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930/8 "2015-12-11T18:00:58Z")

</div>

Ah, that did it! Thanks for your help. So was it just holding onto the settings from the rc1 implementation?

---

<div class="post-metadata">

### Author: ![plonka2000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/plonka2000/32/5077_2.png) [@plonka2000](https://discuss.elastic.co/u/plonka2000)
#### Post date: [February 12, 2016, 1:40pm UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930/9 "2016-02-12T13:40:51Z")

</div>

> [@monica](#):
>
> Can you please delete the old topbeat indices to make sure the "not\_analyzed" is coming from the new indices created after you applied the template?
> 
> curl -XDELETE '[http://127.0.0.1:9200/topbeat-](http://127.0.0.1:9200/topbeat-)\*'
> 
> After that you can refresh the topbeat index pattern in Kibana (from the Settings page) to see if it's set to "not\_analyzed".

Hi @monica ,

I've been noticing the same problem, and I'm using `topbeat-dashboards-1.1.0`.

I'm trying to understand the issue a little better, I'm hoping you might be able to provide some advice.

**I have a few questions:**  
-The import template sets the `analyzed` flag?  
-Is deleting all the indices the only method to remove the `analyzed` flag on the field?  
-If I'm clear on this, your advice above is to:  
**1)** delete all `topbeat-*` indices,  
**2)** import the template from the `load.sh`/`load.ps1` script and  
**3)** refresh the `topbeat-*` index pattern in Kibana before loading more topbeat data?

---

<div class="post-metadata">

### Author: ![plonka2000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/plonka2000/32/5077_2.png) [@plonka2000](https://discuss.elastic.co/u/plonka2000)
#### Post date: [February 12, 2016, 1:58pm UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930/10 "2016-02-12T13:58:28Z")

</div>

**_I'm not sure if I should start a new thread on this subject:_**

I've managed to refresh the `topbeat-*` index pattern by deleting the pattern and importing via the `load.ps1` script.

Is there some way I can update the existing indices to match the updated index pattern without deleting the data?

_UPDATE: Started a new thread in ES forum [here](https://discuss.elastic.co/t/new-index-pattern-to-current-index-topbeat/41627)_

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [February 13, 2016, 1:41am UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930/11 "2016-02-13T01:41:12Z")

</div>

@plonka2000 You would need to re-index your existing data. It takes a bit of work and the way you accomplish the task varies by your technology. Basically you read the data out of ES then re-write it to a new index. See the links below.

[https://www.elastic.co/guide/en/elasticsearch/guide/current/reindex.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/reindex.html)  
[http://david.pilato.fr/blog/2015/05/20/reindex-elasticsearch-with-logstash/](http://david.pilato.fr/blog/2015/05/20/reindex-elasticsearch-with-logstash/)

In the future this will be easier to do: [https://github.com/elastic/elasticsearch/issues/15201](https://github.com/elastic/elasticsearch/issues/15201)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 9:55pm UTC](https://discuss.elastic.co/t/topbeat-beat-hostname-analyzed/36930/12 "2017-07-05T21:55:44Z")

</div>


