# Visualization - field not available for selection

**URL:** <https://discuss.elastic.co/t/visualization-field-not-available-for-selection/103703>\
**Category:** Kibana\
**Created:** [October 12, 2017, 11:17am UTC](https://discuss.elastic.co/t/visualization-field-not-available-for-selection/103703 "2017-10-12T11:17:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rvarttinen](https://avatars.discourse-cdn.com/v4/letter/r/41988e/32.png) [@rvarttinen](https://discuss.elastic.co/u/rvarttinen)\
**Post date:** [October 12, 2017, 11:17am UTC](https://discuss.elastic.co/t/visualization-field-not-available-for-selection/103703/1 "2017-10-12T11:17:40Z")

</div>

Being a newbie with Kibana I might be asking about something that is already answered. So, my apologies on beforehand. Anyhow, I cannot find any appropriate entries, so any pointer will be appreciated.

My problem is centrered around the fact that I do have a number of fields with interesting data, extracted from log files produced by the Jetty webserver. Everything looks nice until I attempt to create a line chart; the only fields seemingly available for aggregation are those whose type is 'number', i.e. 'geoip.latitude' and geoip.longitude'.

After scrutinizing the data I found that e.g. the 'duration' field (one of those fields I'd like to chart) to be a string, eventhough the LogStash config tells it to be a number. Also tried INT, but to no avail.

Could you please advise on what I am missing. Checked some of the examples and responses I did find and they all seem to have things like 'Repsonse Time' and 'Duration' available as fields for aggregation ...

My aplogies as I am probably inquiring about something obvious, and thanks in advance.

P.S. did Management -\> "Index Patterns" and Refresh and all fields are visible with their types, etc. I can see that there is both a 'duration' and a 'duration.keyword' field - both are strings but the '.keyword' one is aggregatable. How can I force it to be of type 'number' or 'int'? Would that solve the problem?

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [October 12, 2017, 11:36am UTC](https://discuss.elastic.co/t/visualization-field-not-available-for-selection/103703/2 "2017-10-12T11:36:55Z")

</div>

Hi Robert,

you done pretty well debugging this already. As you mentioned the main issue is, that these fields, even though you expect them to be numeric, are actually strings. So Elasticsearch has a wrong mapping for your index. This could perhaps indicate an error in your Logstash config, that it actually doesn't generate the right mapping.  
Could you paste your Logstash config?

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![rvarttinen](https://avatars.discourse-cdn.com/v4/letter/r/41988e/32.png) [@rvarttinen](https://discuss.elastic.co/u/rvarttinen)\
**Post date:** [October 12, 2017, 11:53am UTC](https://discuss.elastic.co/t/visualization-field-not-available-for-selection/103703/3 "2017-10-12T11:53:59Z")

</div>

Tim,  
Thank you for your swift repsonse. Sure, here is my Logstash config file:

```
input { 
  file {
    type => "log_file_jetty"
    path => "C:/tmp/logs/*.log"
  }
}
filter {
  if [type] == "log_file_jetty" {
    grok {
        match => { "message" => "%{IPORHOST:remote_addr} - - \[%{HTTPDATE:time_local}\] %{QS:request} %{INT:status} %{INT:body_bytes_sent} %{QS:http_referer} %{QS:http_user_agent} %{INT:duration}" }
    }
  }  
  date {
    match => ["time_local", "dd/MMM/yyyy:HH:mm:ss Z"]
  }
}
output {
  stdout {
   codec => "rubydebug"
  }
  elasticsearch { hosts => ["localhost:9200"] }
}
```

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [October 12, 2017, 12:12pm UTC](https://discuss.elastic.co/t/visualization-field-not-available-for-selection/103703/4 "2017-10-12T12:12:00Z")

</div>

Using `%{NUMBER:x}` will only detect numbers, but not use a numeric data type. You should use `%{NUMBER:duration:int}` instead to also cast it to an integer.

This is also shortly outlines in the [grok docs](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#_grok_basics).

Could you try fixing the config like that and see whether that solves the problem?

Cheers,  
Tim

---

<div class="post-metadata">

**Author:** ![rvarttinen](https://avatars.discourse-cdn.com/v4/letter/r/41988e/32.png) [@rvarttinen](https://discuss.elastic.co/u/rvarttinen)\
**Post date:** [October 12, 2017, 12:27pm UTC](https://discuss.elastic.co/t/visualization-field-not-available-for-selection/103703/5 "2017-10-12T12:27:57Z")

</div>

Tim,  
Thanks! Great! It seems to work now - i do get the field 'duration' to be a 'number' and selectable for aggregation. It was pretty obvious, just me not finding my way in the documentation yet ...

//Robert

---

<div class="post-metadata">

**Author:** ![timroes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timroes/32/19712_2.png) [@timroes](https://discuss.elastic.co/u/timroes)\
**Post date:** [October 12, 2017, 12:36pm UTC](https://discuss.elastic.co/t/visualization-field-not-available-for-selection/103703/6 "2017-10-12T12:36:48Z")

</div>

Glad I could help 👍

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2017, 12:36pm UTC](https://discuss.elastic.co/t/visualization-field-not-available-for-selection/103703/7 "2017-11-09T12:36:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
