# Winlogbeat v5 Dashboard Error (Fielddata is disabled on text fields)

**URL:** <https://discuss.elastic.co/t/winlogbeat-v5-dashboard-error-fielddata-is-disabled-on-text-fields/64342>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [October 29, 2016, 3:09pm UTC](https://discuss.elastic.co/t/winlogbeat-v5-dashboard-error-fielddata-is-disabled-on-text-fields/64342 "2016-10-29T15:09:46Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![somerandomguy](https://avatars.discourse-cdn.com/v4/letter/s/e19b73/32.png) [@somerandomguy](https://discuss.elastic.co/u/somerandomguy)\
**Post date:** [October 29, 2016, 3:09pm UTC](https://discuss.elastic.co/t/winlogbeat-v5-dashboard-error-fielddata-is-disabled-on-text-fields/64342/1 "2016-10-29T15:09:46Z")

</div>

Hi. Just setup my windows 2012 server to send eventlogs to ES (via winlogbeat and LS).  
I also uploaded the dashboard as per document here -

[https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-sample-dashboards.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-sample-dashboards.html)

Now from within Kibana when I go to the winlogbeat dashboard I see this message on the top and the main window doesn't show as much info as I am use to in the past with previous versions.

**"Visualize: Fielddata is disabled on text fields by default. Set fielddata=true on [log\_name] in order to load fielddata in memory by uninverting the inverted index. Note that this can however use significant memory."**

Not sure if this is related but I believe I need to load the template manually if I am using LS (which I am)

[https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html#load-template-manually](https://www.elastic.co/guide/en/beats/winlogbeat/current/winlogbeat-template.html#load-template-manually)

But it looks like it's missing some info?

Any assistance that anybody can give will be appreciated. TIA.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 29, 2016, 3:37pm UTC](https://discuss.elastic.co/t/winlogbeat-v5-dashboard-error-fielddata-is-disabled-on-text-fields/64342/2 "2016-10-29T15:37:30Z")

</div>

Yes, that error would occur if the template is not loaded. So follow the instructions from that link to load the template

You should probably stop Winlogbeat first, delete the registry file (`C:/ProgramData/winlogbeat/registry` IIRC), delete the `winlobeat-*` indices from ES, install the template, restart Winlogbeat.

---

<div class="post-metadata">

**Author:** ![somerandomguy](https://avatars.discourse-cdn.com/v4/letter/s/e19b73/32.png) [@somerandomguy](https://discuss.elastic.co/u/somerandomguy)\
**Post date:** [October 29, 2016, 11:34pm UTC](https://discuss.elastic.co/t/winlogbeat-v5-dashboard-error-fielddata-is-disabled-on-text-fields/64342/3 "2016-10-29T23:34:10Z")

</div>

Yes thanks.  
I ran this command from within powershell and then deleted index winlogbeat\* and also stopped winlogbeat service and then .winlogbeat.yml file and then started service and now its working thanks.

Just 1 more Q, I heard that winlogbeat dashboard in v5.x was much better than those supplied in 2.x but they look the same to me?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [October 31, 2016, 3:53pm UTC](https://discuss.elastic.co/t/winlogbeat-v5-dashboard-error-fielddata-is-disabled-on-text-fields/64342/4 "2016-10-31T15:53:02Z")

</div>

> [@somerandomguy](#):
>
> Just 1 more Q, I heard that winlogbeat dashboard in v5.x was much better than those supplied in 2.x but they look the same to me?

The example dashboard is the same, but the underlying data provided by Winlogbeat 5 is more rich which can enable you to create some great dashboards or alerts yourself. The data from v5 contains the raw parameters used by the application when it created the event log record. This data is found in `event_data.*`. Previously in v1, you would have had to grok the `message` field to extract this data before you could make use of it.

Here's an example I created for logons (dashboard is linked at the end): [Monitoring Windows Logons with Winlogbeat](https://www.elastic.co/blog/monitoring-windows-logons-with-winlogbeat)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2016, 3:53pm UTC](https://discuss.elastic.co/t/winlogbeat-v5-dashboard-error-fielddata-is-disabled-on-text-fields/64342/5 "2016-11-21T15:53:15Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
