# Changed Mapping but field is still Analyzed?

**URL:** <https://discuss.elastic.co/t/changed-mapping-but-field-is-still-analyzed/44960>\
**Category:** Elasticsearch\
**Created:** [March 21, 2016, 8:31am UTC](https://discuss.elastic.co/t/changed-mapping-but-field-is-still-analyzed/44960 "2016-03-21T08:31:26Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [March 21, 2016, 8:31am UTC](https://discuss.elastic.co/t/changed-mapping-but-field-is-still-analyzed/44960/1 "2016-03-21T08:31:26Z")

</div>

Hi Experts ,  
Please clear my doubt , I had an index and "alertmsg" field had following mapping

"alertmsg": {"type": "string","analyzer":"analyzer\_keyword"}

I was not happy the way kibana showing it in table as the whole string was separated into words, so I changed my mapping back to  
"alertmsg": {"type":"string","index" : "not\_analyzed","doc\_values" : true}

I can still see this field as analyzed field not sure why , do I need re-indexing in this case . As per my understanding since i have changed mapping from analyzed to not\_analyzed , so from now on this field will act as not\_analyzed field and for old data it will remain analyzed ? Please correct me if I am wrong , because if this is the case it should implement , or I may be missing something ?

Thank  
VG

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [March 21, 2016, 8:36am UTC](https://discuss.elastic.co/t/changed-mapping-but-field-is-still-analyzed/44960/2 "2016-03-21T08:36:30Z")

</div>

ok , So I got this in the ES documents

```
We can update a mapping to add a new field, but we can’t change an existing field from analyzed to not_analyzed.

```

So I guess in my case solution is only re indexing ?

Thank  
VG

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 21, 2016, 9:13am UTC](https://discuss.elastic.co/t/changed-mapping-but-field-is-still-analyzed/44960/3 "2016-03-21T09:13:49Z")

</div>

You can also add a sub field named `raw` for example which is `not_analyzed`.

```auto
"title": {
    "type": "string",
    "fields": {
        "raw": { "type": "string", "index": "not_analyzed" }
    }
}

```

New documents or updated documents will have this field. But older won't.  
So probably reindexing is better here.

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [March 21, 2016, 9:23am UTC](https://discuss.elastic.co/t/changed-mapping-but-field-is-still-analyzed/44960/4 "2016-03-21T09:23:27Z")

</div>

@dadoonet

Thanks for the quick response , I have another query . Is it possible to make a field full text search wih not\_analyzed . Why I am asking this is when I create a field analyzed with standard tokenizer it cuts the whole string into words and that's look ugly in kibana table .  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/01a669f2110bcb7f36c63c200f8c508af8847da0.png)  
What I want is to show a complete sting \*\*"malicious ips"\*_in the table row but full text search should be enable on that string so that I can search it like alertmsg:malicious_.

Sorry to ask this in the same thread .

Thanks  
VG

---

<div class="post-metadata">

**Author:** ![talk2cshah](https://avatars.discourse-cdn.com/v4/letter/t/8e7dd6/32.png) [@talk2cshah](https://discuss.elastic.co/u/talk2cshah)\
**Post date:** [March 21, 2016, 9:28am UTC](https://discuss.elastic.co/t/changed-mapping-but-field-is-still-analyzed/44960/5 "2016-03-21T09:28:43Z")

</div>

@vikas_gopal you can copy the field in other field and mark it analyzed and so you can search in 1 field and display another.

Regards!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 21, 2016, 9:37am UTC](https://discuss.elastic.co/t/changed-mapping-but-field-is-still-analyzed/44960/6 "2016-03-21T09:37:17Z")

</div>

Searching in `non_analyzed` fields? Yes you can. But you will have to search the exact term.

For example, if you indexed: `My CITY NaME`, searching for `CITY`, `my city name`... won't work.

That's why using multi fields as I explained is interesting.

You still run your searches on `city` field but you run aggregations on `city.raw`.

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [March 21, 2016, 9:37am UTC](https://discuss.elastic.co/t/changed-mapping-but-field-is-still-analyzed/44960/7 "2016-03-21T09:37:30Z")

</div>

Thanks Chirag ,

But how it is achievable to search in 1 field and display another ?. Sorry I do not understand it.

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [March 21, 2016, 9:42am UTC](https://discuss.elastic.co/t/changed-mapping-but-field-is-still-analyzed/44960/8 "2016-03-21T09:42:55Z")

</div>

I see what you guys are saying , thanks @David and @Chirag..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:06pm UTC](https://discuss.elastic.co/t/changed-mapping-but-field-is-still-analyzed/44960/9 "2017-07-05T23:06:41Z")

</div>


