# Case Sensitive Query for Text fields in Elasticsearch

**URL:** https://discuss.elastic.co/t/case-sensitive-query-for-text-fields-in-elasticsearch/264015
**Category:** Elasticsearch
**Created:** [February 11, 2021, 12:40pm UTC](https://discuss.elastic.co/t/case-sensitive-query-for-text-fields-in-elasticsearch/264015 "2021-02-11T12:40:42Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![pathfinder225](https://avatars.discourse-cdn.com/v4/letter/p/bbe5ce/32.png) [@pathfinder225](https://discuss.elastic.co/u/pathfinder225)
#### Post date: [February 11, 2021, 12:40pm UTC](https://discuss.elastic.co/t/case-sensitive-query-for-text-fields-in-elasticsearch/264015/1 "2021-02-11T12:40:42Z")

</div>

I have a requirement of case sensitive search where I need to search for particular word(case sensitive ) in message field which is of type text. I am using Java Rest High level client.

My search word is ERROR , query matches lower case words as well i.e error, Error etc etc where i want documents matching exactly ERROR,. I understand this to do something with analyzers but couldnt quite understand how to go about it . your help is much apppreciated.

Below is the query and mappings

```auto
	    "message": {
    					"type": "text",
    					"fields": {
    						"keyword": {
    							"type": "keyword",
    							"ignore_above": 256
    						}
    					}
    				}

```

```auto
    GET filebeat-7.9.1-2021.02.11*/_search
    {
    	"query": {
    		"bool": {
    			"filter": [{
    				"range": {
    					"@timestamp": {
    						"gte": "now-50m"
    					}
    				}
    			}, {
    				"bool": {
    					"must": [{
    						"match": {
    							"host.name": "ocp1110231"
    						}
    					}, {
    						"match": {
    							"input.type": "log"
    						}
    					}, {
    						"match": {
    							"log.file.path": "/home/app/platform.log"
    						}
    					}, {
    						"query_string": {
    							    "default_field": "message",
    								"query": "ERROR",
    								"default_operator":"AND"

    						}
    					}]
    				}
    			}]

    		}
    	},
    } 

```

---

<div class="post-metadata">

### Author: ![pathfinder225](https://avatars.discourse-cdn.com/v4/letter/p/bbe5ce/32.png) [@pathfinder225](https://discuss.elastic.co/u/pathfinder225)
#### Post date: [February 17, 2021, 2:56am UTC](https://discuss.elastic.co/t/case-sensitive-query-for-text-fields-in-elasticsearch/264015/2 "2021-02-17T02:56:26Z")

</div>

Any help is much appreciated please.

---

<div class="post-metadata">

### Author: ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)
#### Post date: [February 17, 2021, 11:27am UTC](https://discuss.elastic.co/t/case-sensitive-query-for-text-fields-in-elasticsearch/264015/3 "2021-02-17T11:27:45Z")

</div>

Here's an example based on using a custom case-sensitive synonym.

```auto
DELETE test

PUT /test
{
  "settings": {
    "index": {
      "analysis": {
        "analyzer": {
          "synonym": {
            "tokenizer": "standard",
            "filter": ["synonym", "lowercase"]
          }
        },
        "filter": {
          "synonym": {
            "type": "synonym",
            "lenient": true,
            "ignore_case":false,
            "synonyms": ["ERROR => syn_error"]
          }
        }
      }
    }
  },
  "mappings": {
    "properties": {
      "text":{
        "type": "text",
        "analyzer": "synonym"
      }
    }
  }
}
POST test/_analyze
{
  "field": "text",
  "text": ["ERROR"]
}
POST test/_analyze
{
  "field": "text",
  "text": ["syn_error"]
}

```

Note we pick a replacement token `syn_error` that we don't expect to see in the original text.  
Let's add example docs:

```auto
PUT test/_doc/1
{
  "text":"this is not a real error"
}
PUT test/_doc/2
{
  "text":"ERROR this is real"
}

```

Now this search will only match all-uppercase ERROR

```auto
GET test/_search
{
  "query": {
    "match": {
      "text": "ERROR"
    }
  }
}

```

While this query will match documents with any case variation of `error` apart from all-uppercase

```auto
GET test/_search
{
  "query": {
    "match": {
      "text": "Error"
    }
  }
}

```

Case insensitive matches on all other text work OK.

```auto
GET test/_search
{
  "query": {
    "match": {
      "text": "REAL"
    }
  }
}
```

---

<div class="post-metadata">

### Author: ![pathfinder225](https://avatars.discourse-cdn.com/v4/letter/p/bbe5ce/32.png) [@pathfinder225](https://discuss.elastic.co/u/pathfinder225)
#### Post date: [February 19, 2021, 8:05am UTC](https://discuss.elastic.co/t/case-sensitive-query-for-text-fields-in-elasticsearch/264015/4 "2021-02-19T08:05:32Z")

</div>

@Mark_Harwood Thank you so much for the response.

So its all about creating mapping.

We are using filebeat to crawl some log files and sends to logstash , which will create new index daily, with date appended to index name.

I'm not using any explicit mapping it's all default(default filebeat template). Now how do i deal with this scenario.

So for every new index how can i update the mapping with analyzer.

---

<div class="post-metadata">

### Author: ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)
#### Post date: [February 19, 2021, 9:42am UTC](https://discuss.elastic.co/t/case-sensitive-query-for-text-fields-in-elasticsearch/264015/5 "2021-02-19T09:42:46Z")

</div>

> [@pathfinder225](#):
>
> So for every new index how can i update the mapping with analyzer.

See [index templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-templates.html)

---

<div class="post-metadata">

### Author: ![pathfinder225](https://avatars.discourse-cdn.com/v4/letter/p/bbe5ce/32.png) [@pathfinder225](https://discuss.elastic.co/u/pathfinder225)
#### Post date: [February 21, 2021, 6:09pm UTC](https://discuss.elastic.co/t/case-sensitive-query-for-text-fields-in-elasticsearch/264015/6 "2021-02-21T18:09:42Z")

</div>

@Mark_Harwood

Thanks a ton 🙂 Solved my issue.  
I created a custom index template and changed filebeat.yml to use the template and it works great.

Will test this more and explore best practices. If you can suggest some that will be great.

---

<div class="post-metadata">

### Author: ![Mark\_Harwood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_harwood/32/10538_2.png) [@Mark\_Harwood](https://discuss.elastic.co/u/Mark_Harwood)
#### Post date: [February 21, 2021, 9:01pm UTC](https://discuss.elastic.co/t/case-sensitive-query-for-text-fields-in-elasticsearch/264015/7 "2021-02-21T21:01:44Z")

</div>

> [@pathfinder225](#):
>
> Will test this more and explore best practices. If you can suggest some that will be great.

Glad to know you got it working.  
One suggestion is to try extract structured keyword fields from the text using regex patterns - either in custom code, Logstash configurations or ingest pipelines. They allow you to do things like aggregations on your data. The new runtime fields allow you to define similar expressions that get evaluated at query time to do queries or aggregations but will not be as fast as an index with the fields pre-extracted

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 21, 2021, 9:02pm UTC](https://discuss.elastic.co/t/case-sensitive-query-for-text-fields-in-elasticsearch/264015/8 "2021-03-21T21:02:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
