# Case Insensitive aggregation not working

**URL:** <https://discuss.elastic.co/t/case-insensitive-aggregation-not-working/354633>\
**Category:** Elasticsearch\
**Created:** [March 4, 2024, 12:05pm UTC](https://discuss.elastic.co/t/case-insensitive-aggregation-not-working/354633 "2024-03-04T12:05:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![raanup](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raanup/32/134722_2.png) [@raanup](https://discuss.elastic.co/u/raanup)\
**Post date:** [March 4, 2024, 12:05pm UTC](https://discuss.elastic.co/t/case-insensitive-aggregation-not-working/354633/1 "2024-03-04T12:05:42Z")

</div>

ES version - **7.17.7**

I've an index for which I' running an aggregation to get all field matching certain regex. This should be case-insensitive i.e.

```auto
new york should match New York and NEW YORK and New YORK

```

Have added a `lowercase_normaliser` to index so that documents are indexed with lowercase name. This doesn't solve the issue though.  
Now I've to pass the regex in lowercase, else it doesn't return correct results.

I've created an index named **blah** with following mapping

```auto
{
  "blah": {
    "mappings": {
      "properties": {
        "name": {
          "type": "text",
          "fields": {
            "raw": {
              "type": "keyword",
              "normalizer": "lowercase_normalizer"
            }
          }
        }
      }
    }
  }
}

```

Index settings -

```auto
{
  "blah": {
    "settings": {
      "index": {
        "max_ngram_diff": "20",
        "analysis": {
          "normalizer": {
            "lowercase_normalizer": {
              "filter": [
                "lowercase"
              ],
              "type": "custom"
            }
          }
        }
      }
    }
  }
}

```

Documents inserted:

**POST blah/\_doc/1**

```auto
{
  "name": "NEW YORK"
}

```

**POST blah/\_doc/2**

```auto
{
  "name": "New Orleans"
}

```

**POST blah/\_doc/3**

```auto
{
  "name": "New Hampshire"
}

```

Following aggregation query doesn't return expected results -  
**Query**

```auto
{
  "aggregations": {
    "autoComplete": {
      "terms": {
        "field": "name.raw",
        "include": "New.*",
        "order": [
          {
            "_term": "asc"
          }
        ]
      }
    }
  },
  "size": 0
}

```

**Output**

```auto
  "aggregations": {
    "autoComplete": {
      "doc_count_error_upper_bound": 0,
      "sum_other_doc_count": 0,
      "buckets": [

      ]
    }
  }

```

Another downside is that if I use aggregation after running `.lowecase` on `inlcude` value, results are also normalised. Is it possible to have original value being returned?

**EDIT**  
is there another way to get all possible values of a field, in this case, `name` other than aggregation?

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [March 5, 2024, 11:43am UTC](https://discuss.elastic.co/t/case-insensitive-aggregation-not-working/354633/2 "2024-03-05T11:43:09Z")

</div>

Hi @raanup

You are using keyword type. Try search with term applying lowecase like this:

> [@raanup](#):
>
> `"include": "new.*",`

---

<div class="post-metadata">

**Author:** ![raanup](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raanup/32/134722_2.png) [@raanup](https://discuss.elastic.co/u/raanup)\
**Post date:** [March 5, 2024, 1:46pm UTC](https://discuss.elastic.co/t/case-insensitive-aggregation-not-working/354633/3 "2024-03-05T13:46:08Z")

</div>

I understand that. Apologies, haven't updated it. I'm actually using  
`"include": "new.*"`  
and I do get the hits but all of them are normalized.

---

<div class="post-metadata">

**Author:** ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)\
**Post date:** [March 5, 2024, 1:56pm UTC](https://discuss.elastic.co/t/case-insensitive-aggregation-not-working/354633/4 "2024-03-05T13:56:59Z")

</div>

I noticed that you want to do an autocomplete. Have you already researched other options like [search\_as\_you\_type](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-as-you-type.html) or completion suggester?

---

<div class="post-metadata">

**Author:** ![raanup](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raanup/32/134722_2.png) [@raanup](https://discuss.elastic.co/u/raanup)\
**Post date:** [March 11, 2024, 4:56pm UTC](https://discuss.elastic.co/t/case-insensitive-aggregation-not-working/354633/5 "2024-03-11T16:56:34Z")

</div>

Thanks @RabBit_BR . Will try this and let you know

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 8, 2024, 4:57pm UTC](https://discuss.elastic.co/t/case-insensitive-aggregation-not-working/354633/6 "2024-04-08T16:57:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
