# Why index\_patterns add join datatype, but show string in kibana

**URL:** <https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642>\
**Category:** Elasticsearch\
**Created:** [January 10, 2019, 2:15am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642 "2019-01-10T02:15:13Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [January 10, 2019, 2:15am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/1 "2019-01-10T02:15:13Z")

</div>

I add a join datatype for parent-child relationship  
{  
"mappings" : {  
"test\_data" : {  
"properties" : {  
"levelStatus" : {  
"type" : "join",  
"relations" : {  
"user" : "unique",  
"unique" : "report"  
}  
}

My point is that user has child unique, while unique also has his child report.  
Then I used logstash mutate to add this join field:  
mutate {  
add\_field =\> {  
"levelStatus" =\> "user"  
}  
}

mutate {  
add\_field =\> {  
"[levelStatus][name]" =\> "unique"  
"[levelStatus][parent]" =\> "hbouser-%{[usageReports][userID]}"  
}  
}

And first I post parent to elasticsearch , seems all fine.  
But when I post child to it, it fails to index to ealsticsearch:  
"reason"=\>"failed to parse field [levelStatus] of type [text]"

So I went to kibana and found that the "levelStatus" field which I expected it as a join datatype actually is a string type.

Is there andthing wrong with my index\_patterns or mutate scripts?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3fed2aa3bc471bc6a54b698e43532fa8bb6d2d28.png)

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [January 10, 2019, 2:58am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/2 "2019-01-10T02:58:02Z")

</div>

hmm. seems elasticsearch take “type” as a common field...

"levelStatus" : {  
"properties" : {  
"relations" : {  
"properties" : {  
"unique" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
},  
"user" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
}  
}  
},  
"type" : {  
"type" : "text",  
"fields" : {  
"keyword" : {  
"type" : "keyword",  
"ignore\_above" : 256  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [January 10, 2019, 3:02am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/3 "2019-01-10T03:02:06Z")

</div>

my sent request is "Post index\_patterns/my\_index-\*"

while the docment is "put my\_index"

does it matter?

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [January 10, 2019, 3:51am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/4 "2019-01-10T03:51:16Z")

</div>

Yes..  
It work fine when "put my\_index", but doesn't work when "post index\_patterns/my\_index-\*"

How I can make it avaiable to all my indeieswhen my indeies looks like: my\_index-yyyy.mm.dd ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 10, 2019, 6:04am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/5 "2019-01-10T06:04:19Z")

</div>

You probably want this: [https://www.elastic.co/guide/en/elasticsearch/reference/6.5/indices-templates.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.5/indices-templates.html)

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [January 10, 2019, 6:06am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/6 "2019-01-10T06:06:41Z")

</div>

Hi, You means I should post to "\_template/my\_index-\*"?  
As I though, index\_patterns and template are the same meaning.  
Just as the \_template will be remove in the furture,  
Am I right?

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [January 10, 2019, 6:20am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/7 "2019-01-10T06:20:08Z")

</div>

Hi, thanks a lot.I had tried \_template and it finally success.  
But I still get confused with it..

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 10, 2019, 8:03am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/8 "2019-01-10T08:03:00Z")

</div>

A template is applied when you create a new index.  
It helps to define which settings/mappings you would like to apply automatically when an index name matches the template.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 10, 2019, 8:34am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/9 "2019-01-10T08:34:41Z")

</div>

I do not see parent-child relations used together with time-based indices very often as all documents related too each other must be located in the same shard (which is why routing is used). What is the rationale behind using parent-child here instead of e.g. flattening the model through denormalisation?

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [January 10, 2019, 8:52am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/10 "2019-01-10T08:52:01Z")

</div>

thanks for reply.  
So what's diffrence with template(get \_template/) and index\_patterns(get index\_patterns)?  
I was though they are the same. Seems it is not.

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [January 10, 2019, 8:57am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/11 "2019-01-10T08:57:52Z")

</div>

Just like a usermanagement.  
the top level will save userinfo, it is also the parent of the second level  
the second level will save the devices did this user login. it is also the partent of the last level  
the last level will record everthing the user had did in the devices.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 10, 2019, 9:04am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/12 "2019-01-10T09:04:29Z")

</div>

How often are the different types of data updated?

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [January 10, 2019, 9:30am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/13 "2019-01-10T09:30:58Z")

</div>

The top level will update when user change the userinfo or new register.  
the second level will update when action login disappeared  
the lastest level will update more often, as the device will keep sending message to elastic.

So the docs inside top level and second level may will not update often, while docs of the latest level will increase fast(every message sended will treat as a new doc).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 10, 2019, 10:04am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/14 "2019-01-10T10:04:11Z")

</div>

I've never heard about

```
GET index_patterns

```

Where did you see that?

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [January 10, 2019, 10:16am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/15 "2019-01-10T10:16:00Z")

</div>

My elasticsearch version is 6.5.4

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/5/959f53ee1b7f86b30c47fb9b166500ac4b9a84a0.png)

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [January 10, 2019, 10:20am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/16 "2019-01-10T10:20:45Z")

</div>

I once using "\_template" , and elasticsearch noted me that "\_template" will will no more use in the further version , and "index\_patterns" will take the place of it?  
I am not good at english, maybe I had make some understand mistake...

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 10, 2019, 10:29am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/17 "2019-01-10T10:29:35Z")

</div>

That's an index which name is `index_patterns`.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 10, 2019, 10:30am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/18 "2019-01-10T10:30:37Z")

</div>

This message was related to the parameters not to the API name.

---

<div class="post-metadata">

**Author:** ![cythwell](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cythwell](https://discuss.elastic.co/u/cythwell)\
**Post date:** [January 10, 2019, 10:31am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/19 "2019-01-10T10:31:26Z")

</div>

Ar I see. You are right...  
Haha, So stupid I am...  
thanks a lots

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2019, 10:31am UTC](https://discuss.elastic.co/t/why-index-patterns-add-join-datatype-but-show-string-in-kibana/163642/20 "2019-02-07T10:31:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
