# Change mapping

**URL:** https://discuss.elastic.co/t/change-mapping/138345
**Category:** Elasticsearch
**Created:** [July 3, 2018, 9:55am UTC](https://discuss.elastic.co/t/change-mapping/138345 "2018-07-03T09:55:48Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![hgpit](https://avatars.discourse-cdn.com/v4/letter/h/f1d935/32.png) [@hgpit](https://discuss.elastic.co/u/hgpit)
#### Post date: [July 3, 2018, 9:55am UTC](https://discuss.elastic.co/t/change-mapping/138345/1 "2018-07-03T09:55:48Z")

</div>

Hi,

I am really struggling to edit my existing index, in order to exclude certain fields from being searchable.  
I've tried so many suggestions that I'm just about to go insane.

My ES index is **idx-wsa\_access\_logs** and the field I want to exclude is **http\_method**.

(I'm really new to ES by the way)

**I've tried:**

PUT idx-wsa\_access\_logs/\_mapping/\_doc  
{  
"properties": {  
"http\_method": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256,  
"enabled": false  
}  
}  
}  
}  
}

**Results in:**

{  
"error": {  
"root\_cause": [  
{  
"type": "mapper\_parsing\_exception",  
"reason": "Mapping definition for [fields] has unsupported parameters: [enabled : false]"  
}  
],  
"type": "mapper\_parsing\_exception",  
"reason": "Mapping definition for [fields] has unsupported parameters: [enabled : false]"  
},  
"status": 400  
}

**I tried:**

PUT idx-wsa\_access\_logs  
{  
"mappings": {  
"doc": {  
"properties": {  
"http\_method": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"enabled": false,  
"ignore\_above": 256  
}  
}  
}  
}  
}   
}  
}

**Results in:**  
{  
"error": {  
"root\_cause": [  
{  
"type": "resource\_already\_exists\_exception",  
"reason": "index [idx-wsa\_access\_logs/2yAaQwn2S-uwpZ\_CuwPZLA] already exists",  
"index\_uuid": "2yAaQwn2S-uwpZ\_CuwPZLA",  
"index": "idx-wsa\_access\_logs"  
}  
],  
"type": "resource\_already\_exists\_exception",  
"reason": "index [idx-wsa\_access\_logs/2yAaQwn2S-uwpZ\_CuwPZLA] already exists",  
"index\_uuid": "2yAaQwn2S-uwpZ\_CuwPZLA",  
"index": "idx-wsa\_access\_logs"  
},  
"status": 400  
}

Please can someone advise what I need to pass in order to achieve my goal?

Thank you!

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [July 3, 2018, 10:34am UTC](https://discuss.elastic.co/t/change-mapping/138345/2 "2018-07-03T10:34:06Z")

</div>

You can't change the mapping of an index that already exists, you need to delete it and recreate the data, or reindex into a new index with the new mapping.

However if you want a field to be stored but not searched, then look at [https://www.elastic.co/guide/en/elasticsearch/reference/6.3/mapping-index.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/mapping-index.html)

---

<div class="post-metadata">

### Author: ![hgpit](https://avatars.discourse-cdn.com/v4/letter/h/f1d935/32.png) [@hgpit](https://discuss.elastic.co/u/hgpit)
#### Post date: [July 3, 2018, 10:48am UTC](https://discuss.elastic.co/t/change-mapping/138345/3 "2018-07-03T10:48:35Z")

</div>

> [@hgpit](#):
>
> PUT idx-wsa\_access\_logs/\_mapping/\_doc  
> {  
> "properties": {  
> "http\_method": {  
> "type": "text",  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256,  
> "enabled": false  
> }  
> }  
> }  
> }  
> }

Hi warkolm,

Okay, in that case, I deleted my index and tried the following:

PUT idx-wsa\_access\_logs  
{}

PUT idx-wsa\_access\_logs/\_mapping/doc  
{  
"properties": {  
"http\_method": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"enabled": false,  
"ignore\_above": 256  
}  
}  
}  
}  
}

but I get:

{  
"error": {  
"root\_cause": [  
{  
"type": "mapper\_parsing\_exception",  
"reason": "Mapping definition for [fields] has unsupported parameters: [enabled : false]"  
}  
],  
"type": "mapper\_parsing\_exception",  
"reason": "Mapping definition for [fields] has unsupported parameters: [enabled : false]"  
},  
"status": 400  
}

Is '[enabled : false]' no longer supported?

Thank you

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [July 3, 2018, 10:14pm UTC](https://discuss.elastic.co/t/change-mapping/138345/4 "2018-07-03T22:14:48Z")

</div>

Nope, it just doesn't apply to that field type - [https://www.elastic.co/guide/en/elasticsearch/reference/6.3/enabled.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/enabled.html)

Did you try setting `"index": false`?

---

<div class="post-metadata">

### Author: ![hgpit](https://avatars.discourse-cdn.com/v4/letter/h/f1d935/32.png) [@hgpit](https://discuss.elastic.co/u/hgpit)
#### Post date: [July 4, 2018, 8:53am UTC](https://discuss.elastic.co/t/change-mapping/138345/5 "2018-07-04T08:53:32Z")

</div>

Yes, I tried "index": false but it did not do what I am trying to achieve.

Kibana's 'index pattern creator' shows my field as non-searchable and under the 'discover' area it shows it as an available field on the left.  
I don't want ES or Kibana know anything about this field, other than it being in the original message.

How can I do this?

Thank you

---

<div class="post-metadata">

### Author: ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)
#### Post date: [July 4, 2018, 8:03pm UTC](https://discuss.elastic.co/t/change-mapping/138345/6 "2018-07-04T20:03:17Z")

</div>

Instead of

```auto
PUT idx-wsa_access_logs/_mapping/doc
{
    "properties": {
        "http_method": {
            "type": "text",
            "fields": {
                "keyword": {
                    "type": "keyword",
                    "enabled": false,
                    "ignore_above": 256
                }
            }
        }
    }
}

```

simply use

```auto
PUT idx-wsa_access_logs/_mapping/doc
{
    "properties": {
        "http_method": {
            "enabled": false
    }
}

```

As the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/enabled.html) states:

> The `enabled` setting, which can be applied only to the mapping type and to `object` fields, causes Elasticsearch to skip parsing of the contents of the field entirely. The JSON can still be retrieved from the `_source field`, but it is not searchable or stored in any other way

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 1, 2018, 8:03pm UTC](https://discuss.elastic.co/t/change-mapping/138345/7 "2018-08-01T20:03:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
