# Confused about ignore\_above and how to update

**URL:** <https://discuss.elastic.co/t/confused-about-ignore-above-and-how-to-update/245962>\
**Category:** Kibana\
**Created:** [August 21, 2020, 8:49pm UTC](https://discuss.elastic.co/t/confused-about-ignore-above-and-how-to-update/245962 "2020-08-21T20:49:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gswartz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gswartz/32/45582_2.png) [@gswartz](https://discuss.elastic.co/u/gswartz)\
**Post date:** [August 21, 2020, 8:49pm UTC](https://discuss.elastic.co/t/confused-about-ignore-above-and-how-to-update/245962/1 "2020-08-21T20:49:57Z")

</div>

I have an index that I created simply by importing a bunch of docs, so elasticsearch created all the mappings by default. One of the fields is a potentially large text field that we need the whole thing to be keyword searchable. Here's the mapping for it.

```auto
"notes" : {
  "type" : "text",
  "fields" : {
    "keyword" : {
      "type" : "keyword",
      "ignore_above" : 256
    }
  }
}

```

From what I've read, the ignore\_above would limit it to only indexing the first 256 chars. So I then found this command I should be able to run in Kibana to update it.

```auto
PUT /notes-index/_mapping
	{
	  "properties": {
	    "notes": {
	      "type": "text",
              "ignore_above" : 5000
	    }
	  }
	}

```

When I run that I get an error.

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "mapper_parsing_exception",
        "reason": "Mapping definition for [notes] has unsupported parameters: [ignore_above : 5000]"
      }
    ],
    "type": "mapper_parsing_exception",
    "reason": "Mapping definition for [notes] has unsupported parameters: [ignore_above : 5000]"
  },
  "status": 400
}

```

So, I'm confused, is this notes field a text type or keyword type? I'm wondering if it's a text, and each analyzed word is a keyword? Is that how it works? Thanks.

---

<div class="post-metadata">

**Author:** ![cheiligers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cheiligers/32/73114_2.png) [@cheiligers](https://discuss.elastic.co/u/cheiligers)\
**Post date:** [August 21, 2020, 11:06pm UTC](https://discuss.elastic.co/t/confused-about-ignore-above-and-how-to-update/245962/2 "2020-08-21T23:06:33Z")

</div>

@gswartz, welcome to the community!  
`ignore_above` is only applicable to `keyword` fields.  
Elasticsearch tries to help one out by creating a mapping if one isn't defined but it doesn't always get it _just the way you want it_ 🙂  
If you want _both_ text and keyword, you can use a [multi-field](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-fields.html) mapping as follows:

```auto
PUT /notes-index/_mapping
	{
	  "properties": {
	    "notes": {
	      "type": "text",
              "fields": {
                  "text.keyword": {
                       "type": "keyword"
                       "ignore_above": 5000
                  }
             }
	    }
	}

```

I wouldn't go as far as 5000 though, because the keyword type treats each entry as an individual, unique term. The default is 256.  
There is an important note at the bottom of the docs that I'l reiterate here:  
" The value for `ignore_above` is the _character count_ , but Lucene counts bytes. If you use UTF-8 text with many non-ASCII characters, you may want to set the limit to `32766 / 4 = 8191` since UTF-8 characters may occupy at most 4 bytes."

If you want to do a full text search and plan to use an analyzer, I suggest you remap the field as text only. There's a great explanation and how to use the analyzers [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-fields.html).  
I hope that helps.

---

<div class="post-metadata">

**Author:** ![gswartz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gswartz/32/45582_2.png) [@gswartz](https://discuss.elastic.co/u/gswartz)\
**Post date:** [August 24, 2020, 2:12pm UTC](https://discuss.elastic.co/t/confused-about-ignore-above-and-how-to-update/245962/3 "2020-08-24T14:12:30Z")

</div>

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2020, 2:12pm UTC](https://discuss.elastic.co/t/confused-about-ignore-above-and-how-to-update/245962/4 "2020-09-21T14:12:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
