# Confusion on what is actually stored per field

**URL:** <https://discuss.elastic.co/t/confusion-on-what-is-actually-stored-per-field/7599>\
**Category:** Elasticsearch\
**Created:** [May 8, 2012, 1:29pm UTC](https://discuss.elastic.co/t/confusion-on-what-is-actually-stored-per-field/7599 "2012-05-08T13:29:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jan\_Fiedler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jan_fiedler/32/2518_2.png) [@Jan\_Fiedler](https://discuss.elastic.co/u/Jan_Fiedler)\
**Post date:** [May 8, 2012, 1:29pm UTC](https://discuss.elastic.co/t/confusion-on-what-is-actually-stored-per-field/7599/1 "2012-05-08T13:29:12Z")

</div>

I got quite confused today doing some testing (Java client) around what is  
actually stored in the index for a field. Before investing into a REST gist  
I just wanted to check whether there is a major misunderstanding on my side:

- I have a type mapping with \_source = disabled and dynamic = false.
- I have index = analyzed and store = no for my field
- I index some content in the field
- I run a get request for the indexed content and configured the get  
request to return the field

I checked that the mapping I defined is really in effect on the index (so  
no basic misconfiguration). I expected the field to be null on the get  
response (as it is not stored). If not null, I expected at least only the  
analyzed version (e.g. lowercase which is my custom test analyzer).  
However, what I am getting is _always_ the real (non-analyzed) value? Is  
this correct behavior?

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [May 8, 2012, 2:47pm UTC](https://discuss.elastic.co/t/confusion-on-what-is-actually-stored-per-field/7599/2 "2012-05-08T14:47:34Z")

</div>

I see whats going on. What happens is that when you do a get, its a  
realtime get that is read from the transaction log (as you index more data,  
that will move into getting the doc from the "index"). And, even if \_source  
is disabled, it is still stored in the transaction log (so we can replay  
it). Opened an issue so we will be more consistent:  
[Get API: When \_source is disabled, the source is still used if fetched from the transaction log · Issue #1927 · elastic/elasticsearch · GitHub](https://github.com/elasticsearch/elasticsearch/issues/1927).

On Tue, May 8, 2012 at 4:29 PM, Jan Fiedler [fiedler.jan@gmail.com](mailto:fiedler.jan@gmail.com) wrote:

> I got quite confused today doing some testing (Java client) around what is  
> actually stored in the index for a field. Before investing into a REST gist  
> I just wanted to check whether there is a major misunderstanding on my side:
> 
> - I have a type mapping with \_source = disabled and dynamic = false.
> - I have index = analyzed and store = no for my field
> - I index some content in the field
> - I run a get request for the indexed content and configured the get  
> request to return the field
> 
> I checked that the mapping I defined is really in effect on the index (so  
> no basic misconfiguration). I expected the field to be null on the get  
> response (as it is not stored). If not null, I expected at least only the  
> analyzed version (e.g. lowercase which is my custom test analyzer).  
> However, what I am getting is _always_ the real (non-analyzed) value? Is  
> this correct behavior?

---

<div class="post-metadata">

**Author:** ![Jan\_Fiedler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jan_fiedler/32/2518_2.png) [@Jan\_Fiedler](https://discuss.elastic.co/u/Jan_Fiedler)\
**Post date:** [May 8, 2012, 3:27pm UTC](https://discuss.elastic.co/t/confusion-on-what-is-actually-stored-per-field/7599/3 "2012-05-08T15:27:11Z")

</div>

Awesome! Thanks for getting back so quickly. The background to this  
question / test was that I plan to implement a special 'hashing' analyzer  
for security relevant fields (e.g. stuff like social security numbers). I  
am trying to provide some security for such fields (in case the index gets  
compromised / stolen) while still providing some basic (very) search  
capabilities on those fields. Obviously, for this you must not be able to  
access the original field value (which is why I was so surprised in my test  
case).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:29am UTC](https://discuss.elastic.co/t/confusion-on-what-is-actually-stored-per-field/7599/4 "2017-07-06T03:29:48Z")

</div>


