# Visualize: Field data loading is forbidden on \[FieldName\]

**URL:** <https://discuss.elastic.co/t/visualize-field-data-loading-is-forbidden-on-fieldname/62980>\
**Category:** Kibana\
**Created:** [October 13, 2016, 6:35pm UTC](https://discuss.elastic.co/t/visualize-field-data-loading-is-forbidden-on-fieldname/62980 "2016-10-13T18:35:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![arque](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@arque](https://discuss.elastic.co/u/arque)\
**Post date:** [October 13, 2016, 6:35pm UTC](https://discuss.elastic.co/t/visualize-field-data-loading-is-forbidden-on-fieldname/62980/1 "2016-10-13T18:35:50Z")

</div>

Hi all,

I want to visualize the data in Kibana. But, I always get `Visualize: Field data loading is forbidden on [FieldName]` for all my fields. These are the first two lines of the `.csv` file I am trying to visualize:

```
"No","Time","Info","Source","Destination","Protocol","Length","Dst port","Hw Src Add","Hw Dst Add","Flag IP"
"1","2016-10-11 17:15:41.411052","M-SEARCH * HTTP/1.1 ","fe80::614f:c82a:7a35:6fd7","ff02::c","SSDP","208","1900","IntelCor_7a:83:c4","IPv6mcast_0c",""

```

I've read some solutions like converting the values of the fields, but that didnt work (I did `convert => { "No" => "integer" }` and got the same error for that field).  
I've also read about using `.raw`, but I am completely new to it, and couldn't get it done.

Can anyone help me (if possible, with an easy to follow step by step on how to solve it with `.raw`) or any other way to solve it?

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [October 13, 2016, 7:45pm UTC](https://discuss.elastic.co/t/visualize-field-data-loading-is-forbidden-on-fieldname/62980/2 "2016-10-13T19:45:05Z")

</div>

The Field Data message is coming from Elasticsearch, and basically prevents you from doing aggregations on analyzed fields. It does this because those operations are very expensive. You can enable it in Elasticsearch, but it's not recommended. As you note, you're better off using a `.raw` version of the field, which is a non-analyzed version of the same field. This is something Logstash does for you automatically, but it's easy to do yourself if you aren't using Logstash.

The easiest way to and able the `.raw` field is to use [Dynamic Templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-templates.html). You can do something like Logstash does, and just add a `.raw` field for any String types, or you can get fancier to meet your specific needs.

---

<div class="post-metadata">

**Author:** ![nagesh](https://avatars.discourse-cdn.com/v4/letter/n/7ba0ec/32.png) [@nagesh](https://discuss.elastic.co/u/nagesh)\
**Post date:** [October 19, 2016, 12:50pm UTC](https://discuss.elastic.co/t/visualize-field-data-loading-is-forbidden-on-fieldname/62980/3 "2016-10-19T12:50:32Z")

</div>

I think I have tried what you said Joe , as I am seeing same issue. Here I am attaching screenshot of discover screen of Kibana 5.1.

![](https://us1.discourse-cdn.com/elastic/original/2X/d/d8f94288cfcc1ad84b9b26acd0f83a806a7ecc1e.jpg)

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [October 19, 2016, 9:30pm UTC](https://discuss.elastic.co/t/visualize-field-data-loading-is-forbidden-on-fieldname/62980/4 "2016-10-19T21:30:36Z")

</div>

The `.raw` field won't actually show up in Discover that way. We treat them weird, so you will only see the `type` field in the list.

You should see it in Visualize though, when you define the aggregations for your visualization. This is a screenshot from 5.0, but it works the same in 4.x. The only difference is you will see both fields, `type` and `type.raw`.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/9/94ee708217bf9a68ed6435e5558c52912a818428.png)

You can also just query one of you records in Elasticsearch and ensure that you see the `.raw` version.

Note that you may need to update your field list in Kibana if you just added those fields. This can be done under Settings \> Indices

![](https://us1.discourse-cdn.com/elastic/original/2X/2/27a171056ac806beb8c0128492d35a66bcc2d472.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:36pm UTC](https://discuss.elastic.co/t/visualize-field-data-loading-is-forbidden-on-fieldname/62980/5 "2017-07-06T13:36:11Z")

</div>


