# Uknown fields

**URL:** <https://discuss.elastic.co/t/uknown-fields/265254>\
**Category:** Kibana\
**Created:** [February 23, 2021, 8:58pm UTC](https://discuss.elastic.co/t/uknown-fields/265254 "2021-02-23T20:58:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [February 23, 2021, 8:58pm UTC](https://discuss.elastic.co/t/uknown-fields/265254/1 "2021-02-23T20:58:19Z")

</div>

In newest ELK stack, how I should deal with unknown fields? Before this version it was just about refresh index pattern. What should I do now? Removing and adding pattern will lead to lost my edits made in this pattern like display values etc.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 24, 2021, 12:31am UTC](https://discuss.elastic.co/t/uknown-fields/265254/2 "2021-02-24T00:31:14Z")

</div>

Kibana now auto-refreshes, so you shouldn't need to do anything.

---

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [February 28, 2021, 10:25am UTC](https://discuss.elastic.co/t/uknown-fields/265254/3 "2021-02-28T10:25:02Z")

</div>

Looks like it work that way, but can I somehow predefine fields? I am goting errors on dashboards in ELK instance without data (yet). Can I for example export this information (mapping?) from one ES to another? If yes, how can I achieve this most easy way? I can do it manually because I will need it one time per new instance, thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 28, 2021, 9:57pm UTC](https://discuss.elastic.co/t/uknown-fields/265254/4 "2021-02-28T21:57:50Z")

</div>

You can use `GET $INDEXNAME/_mapping` and then copy the json and `PUT` it to another cluster.

---

<div class="post-metadata">

**Author:** ![cyberzlo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyberzlo/32/65490_2.png) [@cyberzlo](https://discuss.elastic.co/u/cyberzlo)\
**Post date:** [February 28, 2021, 10:51pm UTC](https://discuss.elastic.co/t/uknown-fields/265254/5 "2021-02-28T22:51:30Z")

</div>

Thanks, but when I have index pattern with `xyz-*` (indexes have `xyz-YYYY-MM-DD`) and I do `GET xyz-*/_mapping` then probably I am goting only first index, and my fields are dynamic added to pattern. Is this possible to copy such index pattern or mapping for all indexes matching this pattern?  
Problem is that before system will generate data I am goting errors on dashboards created on other instance, and I guess some field can be auto created other way that in my main kibana - mainly I am afraid this, that some field will have other type etc due automatic creation of pattern, and my dashboards will not work correct.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2021, 10:52pm UTC](https://discuss.elastic.co/t/uknown-fields/265254/6 "2021-03-28T22:52:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
