# What is excluded column in kibana index pattern?

**URL:** <https://discuss.elastic.co/t/what-is-excluded-column-in-kibana-index-pattern/252667>\
**Category:** Kibana\
**Created:** [October 20, 2020, 10:35am UTC](https://discuss.elastic.co/t/what-is-excluded-column-in-kibana-index-pattern/252667 "2020-10-20T10:35:56Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![llamskt](https://avatars.discourse-cdn.com/v4/letter/l/b5e925/32.png) [@llamskt](https://discuss.elastic.co/u/llamskt)\
**Post date:** [October 21, 2020, 5:10pm UTC](https://discuss.elastic.co/t/what-is-excluded-column-in-kibana-index-pattern/252667/10 "2020-10-21T17:10:21Z")

</div>

Steps to reproduce:

1. Create index pattern from filebeat-7.9.2 index (doesn't matter if I designate @timestamp as time-filter or not)
2. Wait about 5 minutes (index pattern will work during this time and not have source filter present or @timestamp field marked as excluded)
3. View index pattern in Discover tab, receive following error:  
 ![error1](https://us1.discourse-cdn.com/elastic/original/3X/0/1/01e61e623267fa5374c8ce05af718ab05cd2d929.png)

```auto
 FieldParamType/_this.deserialize@https://some.url.com/33984/bundles/plugin/data/data.plugin.js:9:345453
setParams/<@https://some.url.com/33984/bundles/plugin/data/data.plugin.js:9:362647
setParams@https://some.url.com/33984/bundles/plugin/data/data.plugin.js:9:362156
set@https://some.url.com/33984/bundles/plugin/data/data.plugin.js:9:368734
setType@https://some.url.com/33984/bundles/plugin/data/data.plugin.js:9:368146
AggConfig@https://some.url.com/33984/bundles/plugin/data/data.plugin.js:9:361885
AggConfigs/<@https://some.url.com/33984/bundles/plugin/data/data.plugin.js:9:375134
AggConfigs/<@https://some.url.com/33984/bundles/plugin/data/data.plugin.js:9:375555
AggConfigs@https://some.url.com/33984/bundles/plugin/data/data.plugin.js:9:375516
createAggConfigs@https://some.url.com/33984/bundles/plugin/data/data.plugin.js:14:318274
_callee2$@https://some.url.com/33984/bundles/plugin/visualizations/visualizations.plugin.js:9:304414
l@https://some.url.com/33984/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:368:155323
s/o._invoke</<@https://some.url.com/33984/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:368:155077
_/</e[t]@https://some.url.com/33984/bundles/kbn-ui-shared-deps/kbn-ui-shared-deps.js:368:155680
vis_asyncGeneratorStep@https://some.url.com/33984/bundles/plugin/visualizations/visualizations.plugin.js:9:300183
_next@https://some.url.com/33984/bundles/plugin/visualizations/visualizations.plugin.js:9:300519

```

1. Check index pattern and find @timestamp field is excluded and source filter has been created.  
 ![error2](https://us1.discourse-cdn.com/elastic/original/3X/8/0/803e0ff7e551c4847b0b0fcf30815f89f8e7ce20.png)

The issue has appeared around the time of upgrading filebeat elastic and kibana to 7.9.2. I have deleted the .kibana system index and optimize folders and restarted kibana as troubleshooting steps already. I have a separate filebeat instance running version 7.8 that is unaffected by this issue and is running fine. Both filebeat instances have similar configurations and the same ILM policy. I have also tried deleting the index itself and starting the filebeat service again with no luck. The only debug error I see from kibana is:

```auto
 {"type":"log","@timestamp":"2020-10-21T16:48:26Z","tags":["debug","plugins","usageCollection","collector-set"],"pid":2065,"message":"not sending [kibana_settings] monitoring document because [undefined] is null or invalid."}

```

Its also worth mentioning I'm using Wazuh's filebeat index template here. The wazuh-alerts index pattern works fine, here is my filebeat config for reference:

```auto
## Wazuh - Filebeat configuration file

filebeat.modules:
  - module: wazuh
    alerts:
      enabled: true
    archives:
      enabled: false
# OwlH Module
  - module: owlh
    events:
      enabled: true

filebeat.config.modules:
  enabled: true
  path: ${path.config}/modules.d/*.yml
## OWLH pipeline sync
filebeat.overwrite_pipelines: true

#setup.template:
# name: "filebeat"
# pattern: "filebeat-custom-*
# settings:
setup.template.settings.index.number_of_shards: 1
setup.template.settings.index.number_of_replicas: 0

setup.ilm.enabled: auto
setup.ilm.pattern: "{now/M{yyyy.MM}}-001"
setup.ilm.overwrite: false
setup.ilm.rollover_alias: "filebeat-%{[agent.version]}-custom"
setup.ilm.policy_name: "filebeat-custom"

```

---

_[View the full topic](https://discuss.elastic.co/t/what-is-excluded-column-in-kibana-index-pattern/252667)._
