# Adding .raw fields to existing data

**URL:** <https://discuss.elastic.co/t/adding-raw-fields-to-existing-data/47568>\
**Category:** Logstash\
**Created:** [April 16, 2016, 8:06pm UTC](https://discuss.elastic.co/t/adding-raw-fields-to-existing-data/47568 "2016-04-16T20:06:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tsegal](https://avatars.discourse-cdn.com/v4/letter/t/a6a055/32.png) [@tsegal](https://discuss.elastic.co/u/tsegal)\
**Post date:** [April 16, 2016, 8:06pm UTC](https://discuss.elastic.co/t/adding-raw-fields-to-existing-data/47568/1 "2016-04-16T20:06:15Z")

</div>

Hi all,

I created a cluster where I host my logs. I have around 8 index patterns and ~40 million documents currently. I noticed that my fields are being analyzed and broken down (so foo-bar is broken down to "foo" and "bar" in visualizations for example). So I wanted to solve it by adding .raw fields, like in the default logstash-\* pattern. I added to /\_template endpoint some templates which I copied from logstash-\* default template along with the necessary changes. Now to move forward, I want to make all my documents add the .raw fields (to all the strings) as well as future documents (currently my redis holds everything and I really want to get this over with so I don't lose data. I tried to reindex by stopping my logstash service and running manually with a configuration file but it's really slow and logstash crashes. Can anyone help? (the real ip was replaced with 1.1.1.1)

input  
{  
elasticsearch  
{  
hosts =\> ["1.1.1.1"]  
index =\> "\*"  
size =\> 2000  
scroll =\> "5m"  
docinfo =\> true  
}  
}

output {  
elasticsearch {  
hosts =\> ["1.1.1.1"]  
index =\> "r.%{[@metadata][\_index]}"  
document\_type =\> "%{[@metadata][\_type]}"  
document\_id =\> "%{[@metadata][\_id]}"  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 16, 2016, 8:15pm UTC](https://discuss.elastic.co/t/adding-raw-fields-to-existing-data/47568/2 "2016-04-16T20:15:25Z")

</div>

Which part do you want help on exactly?

That config looks fine.

---

<div class="post-metadata">

**Author:** ![tsegal](https://avatars.discourse-cdn.com/v4/letter/t/a6a055/32.png) [@tsegal](https://discuss.elastic.co/u/tsegal)\
**Post date:** [April 16, 2016, 8:31pm UTC](https://discuss.elastic.co/t/adding-raw-fields-to-existing-data/47568/3 "2016-04-16T20:31:36Z")

</div>

First, thanks for your reply! First questions is - is this the correct way? For example, is it not possible to just tell an index to reindex itself? for example something like: curl -XPUT 'localhost:9200/index/\_reindex'

Secondly, if I use this method, how can I speed it up? It's very slow. And thirdly, if I use this method and rename my indices, I then have to play them back to rename them again? Or can I just rename and index? Or should I use aliases?

I hope it's clearer now.

Thanks again!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 16, 2016, 8:34pm UTC](https://discuss.elastic.co/t/adding-raw-fields-to-existing-data/47568/4 "2016-04-16T20:34:45Z")

</div>

> [@tsegal](#):
>
> for example something like: curl -XPUT 'localhost:9200/index/\_reindex'

In 2.3, yes [Reindex API | Elasticsearch Guide [2.3] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/2.3/docs-reindex.html)

> [@tsegal](#):
>
> Secondly, if I use this method, how can I speed it up? It's very slow.

Add more resources to ES 🙂

> [@tsegal](#):
>
> And thirdly, if I use this method and rename my indices, I then have to play them back to rename them again? Or can I just rename and index? Or should I use aliases?

Use aliases, you cannot rename indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:01am UTC](https://discuss.elastic.co/t/adding-raw-fields-to-existing-data/47568/5 "2017-07-06T05:01:57Z")

</div>


