# \_default\_ string to keyword but fields still using text

**URL:** <https://discuss.elastic.co/t/-default--string-to-keyword-but-fields-still-using-text/78179>\
**Category:** Elasticsearch\
**Created:** [March 10, 2017, 7:30pm UTC](https://discuss.elastic.co/t/-default--string-to-keyword-but-fields-still-using-text/78179 "2017-03-10T19:30:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Oscar\_Cpl](https://avatars.discourse-cdn.com/v4/letter/o/3ec8ea/32.png) [@Oscar\_Cpl](https://discuss.elastic.co/u/Oscar_Cpl)\
**Post date:** [March 10, 2017, 7:30pm UTC](https://discuss.elastic.co/t/-default--string-to-keyword-but-fields-still-using-text/78179/1 "2017-03-10T19:30:28Z")

</div>

Hello,

I did set a dynamic template to make sure all the string are mapped as keyword but I still see fields stored as text, any hints?

```
{
"app-security-2017-03-10": {
	"mappings": {
		"_default_": {
			"_all": {
				"enabled": true,
				"norms": false
			},
			"dynamic_templates": [
				{
					"omit_norms": {
						"match_mapping_type": "*",
						"mapping": {
							"norms": {
								"enabled": false
							}
						}
					}
				},
				{
					"strings_as_keyword": {
						"match_mapping_type": "string",
						"mapping": {
							"include_in_all": true,
							"index": "not_analyzed",
							"type": "keyword"
						}
					}
				}
			]
		},
		"app-security-logs": {
			"_all": {
				"enabled": true,
				"norms": false
			},
			"dynamic_templates": [
				{
					"omit_norms": {
						"match_mapping_type": "*",
						"mapping": {
							"norms": {
								"enabled": false
							}
						}
					}
				},
				{
					"strings_as_keyword": {
						"match_mapping_type": "string",
						"mapping": {
							"include_in_all": true,
							"index": "not_analyzed",
							"type": "keyword"
						}
					}
				}
			],
			"properties": {
				"eventType": {
					"type": "text",
					"norms": false
				},
				"httpMethod": {
					"type": "text",
					"norms": false
				},
				"httpStatus": {
					"type": "long"
				},
				"method": {
					"type": "text",
					"norms": false
				},
				"nucleus-personaId": {
					"type": "text",
					"norms": false
				},
				"nucleus-pid": {
					"type": "text",
					"norms": false
				},
				"app-cluster": {
					"type": "text",
					"norms": false
				},
				"app-instigator": {
					"type": "text",
					"norms": false
				},
				"app-platform": {
					"type": "text",
					"norms": false
				},
				"app-sid": {
					"type": "text",
					"norms": false
				},
				"app-title": {
					"type": "text",
					"norms": false
				},
				"app-traceId": {
					"type": "text",
					"norms": false
				},
				"request": {
					"type": "text",
					"norms": false
				},
				"requestHeaders": {
					"properties": {
						"Accept": {
							"type": "text",
							"norms": false
						},
						"Accept-Encoding": {
							"type": "text",
							"norms": false
						},
						"Accept-Language": {
							"type": "text",
							"norms": false
						},
						"Cache-Control": {
							"type": "text",
							"norms": false
						},
						"Connection": {
							"type": "text",
							"norms": false
						},
						"Content-Length": {
							"type": "text",
							"norms": false
						},
						"Content-Type": {
							"type": "text",
							"norms": false
						},
						"Cookie": {
							"type": "text",
							"norms": false
						},
						"Host": {
							"type": "text",
							"norms": false
						},
						"Origin": {
							"type": "text",
							"norms": false
						},
						"Postman-Token": {
							"type": "text",
							"norms": false
						},
						"Referer": {
							"type": "text",
							"norms": false
						},
						"User-Agent": {
							"type": "text",
							"norms": false
						},
						"X-BOS-Instigator": {
							"type": "text",
							"norms": false
						},
						"X-BOS-Trace-Id": {
							"type": "text",
							"norms": false
						},
						"X-Forwarded-For": {
							"type": "text",
							"norms": false
						},
						"X-Forwarded-Port": {
							"type": "text",
							"norms": false
						},
						"X-Forwarded-Proto": {
							"type": "text",
							"norms": false
						},
						"X-app-SID": {
							"type": "text",
							"norms": false
						},
						"X-app-Tool-Requestor": {
							"type": "text",
							"norms": false
						},
						"X-app-Version": {
							"type": "text",
							"norms": false
						},
						"X-Requested-With": {
							"type": "text",
							"norms": false
						}
					}
				},
				"response": {
					"type": "text",
					"norms": false
				},
				"responseHeaders": {
					"properties": {
						"Access-Control-Allow-Credentials": {
							"type": "text",
							"norms": false
						},
						"Access-Control-Allow-Headers": {
							"type": "text",
							"norms": false
						},
						"Access-Control-Allow-Methods": {
							"type": "text",
							"norms": false
						},
						"Access-Control-Allow-Origin": {
							"type": "text",
							"norms": false
						},
						"Access-Control-Max-Age": {
							"type": "text",
							"norms": false
						},
						"Content-Type": {
							"type": "text",
							"norms": false
						},
						"X-app-SID": {
							"type": "text",
							"norms": false
						}
					}
				},
				"responseLength": {
					"type": "long"
				},
				"restCall": {
					"type": "text",
					"norms": false
				},
				"restHost": {
					"type": "text",
					"norms": false
				},
				"time": {
					"type": "date"
				},
				"timeMs": {
					"type": "float"
				},
				"timestampEnd": {
					"type": "long"
				},
				"timestampStart": {
					"type": "long"
				},
				"to": {
					"type": "text",
					"norms": false
				},
				"uri": {
					"type": "text",
					"norms": false
				}
			}
		}
	}
}

```

}

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [March 13, 2017, 9:34pm UTC](https://discuss.elastic.co/t/-default--string-to-keyword-but-fields-still-using-text/78179/2 "2017-03-13T21:34:25Z")

</div>

Hey,

can you please provide a fully reproducible example, including index creation/mapping and a document that contains an unwanted field?

--Alex

---

<div class="post-metadata">

**Author:** ![Oscar\_Cpl](https://avatars.discourse-cdn.com/v4/letter/o/3ec8ea/32.png) [@Oscar\_Cpl](https://discuss.elastic.co/u/Oscar_Cpl)\
**Post date:** [March 14, 2017, 3:21pm UTC](https://discuss.elastic.co/t/-default--string-to-keyword-but-fields-still-using-text/78179/3 "2017-03-14T15:21:07Z")

</div>

Hmm well index are created automatically, but I might be missing something here, I just don't understand why:

"strings\_as\_keyword": {  
"match\_mapping\_type": "string",  
"mapping": {  
"include\_in\_all": true,  
"index": "not\_analyzed",  
"type": "keyword"  
}

is not picked up on any string fields? Do you see something wrong in the template?

Thank you,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2017, 3:21pm UTC](https://discuss.elastic.co/t/-default--string-to-keyword-but-fields-still-using-text/78179/4 "2017-04-11T15:21:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
