1

I am a newbie to ELK and just found the raw fields missing from Elasticsearch as showed in Kibana below,

kibana data fields

I checked Logstash data mapping as below,

Logstash mapping

and the simple Logstash configuration,

Logstash configuration

Could someone please shed a light on how to make both analysed and non analysed fields available?

Thanks, Sean

Sean Sun
  • 496
  • 1
  • 4
  • 14
  • solving the issue by change manage_template to true. see http://stackoverflow.com/questions/33979226/where-do-raw-fields-come-from-when-using-logstash-with-elasticsearch-output – Sean Sun Dec 01 '16 at 03:17

0 Answers0