# Why is the value in the field on kibana repeated?

**URL:** <https://discuss.elastic.co/t/why-is-the-value-in-the-field-on-kibana-repeated/275420>\
**Category:** Logstash\
**Created:** [June 9, 2021, 10:17am UTC](https://discuss.elastic.co/t/why-is-the-value-in-the-field-on-kibana-repeated/275420 "2021-06-09T10:17:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cong\_To](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cong_to/32/90046_2.png) [@Cong\_To](https://discuss.elastic.co/u/Cong_To)\
**Post date:** [June 9, 2021, 10:17am UTC](https://discuss.elastic.co/t/why-is-the-value-in-the-field-on-kibana-repeated/275420/1 "2021-06-09T10:17:30Z")

</div>

Update: _I found the cause, the error was because I had two configuration files in the logstash folder and they had the same grok._

_Thank you for following._

Hi

I use ELK version 7.13.1 on Ubuntu 18.04. I tried reading the log from the file `https://s3.amazonaws.com/logzio-elk/apache-daily-access.log`.  
After creating the index and going back to the discovery tab on kibana, I see some fields with values ​​repeated twice. Raw log files are not duplicated.

I have checked in ELK 7.12.1 on CentOS7 & ELK 7.13.1 on CentOS 7 and I don't have this problem.

Picture

 ![Screenshot_5](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a0e1d791358181c4824bf5b4c893df09643ba159.png)

My file logstash:

```auto
input {
  file {
    path => "/var/log/apache-daily-access.log"
    start_position => "beginning"
    sincedb_path => "/dev/null"
  }
}
filter {
  grok {
    match => { "message" => "%{COMBINEDAPACHELOG}" }
  }
  date {
    match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
  }
  geoip {
    source => "clientip"
  }
}
output {
  elasticsearch {
    hosts => ["192.168.20.8:9200"]
  }
}

```

Please explain to me and guide how to solve this problem.

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 9, 2021, 3:57pm UTC](https://discuss.elastic.co/t/why-is-the-value-in-the-field-on-kibana-repeated/275420/2 "2021-06-09T15:57:10Z")

</div>

This is really an elasticsearch question. See [this](https://www.elastic.co/blog/strings-are-dead-long-live-strings) blog post.

---

<div class="post-metadata">

**Author:** ![Cong\_To](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cong_to/32/90046_2.png) [@Cong\_To](https://discuss.elastic.co/u/Cong_To)\
**Post date:** [June 9, 2021, 4:03pm UTC](https://discuss.elastic.co/t/why-is-the-value-in-the-field-on-kibana-repeated/275420/3 "2021-06-09T16:03:32Z")

</div>

Hi

I found the cause, the error was because I had two configuration files in the logstash folder and they had the same grok.

Thank you for following.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2021, 4:04pm UTC](https://discuss.elastic.co/t/why-is-the-value-in-the-field-on-kibana-repeated/275420/4 "2021-07-07T16:04:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
