# Counting a whole strings not individual words in the string

**URL:** <https://discuss.elastic.co/t/counting-a-whole-strings-not-individual-words-in-the-string/39357>\
**Category:** Elasticsearch\
**Created:** [January 15, 2016, 8:23pm UTC](https://discuss.elastic.co/t/counting-a-whole-strings-not-individual-words-in-the-string/39357 "2016-01-15T20:23:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Christopher\_Curzon](https://avatars.discourse-cdn.com/v4/letter/c/2acd7d/32.png) [@Christopher\_Curzon](https://discuss.elastic.co/u/Christopher_Curzon)\
**Post date:** [January 15, 2016, 8:23pm UTC](https://discuss.elastic.co/t/counting-a-whole-strings-not-individual-words-in-the-string/39357/1 "2016-01-15T20:23:31Z")

</div>

I'm looking at a data file something like this

shipid status  
ship01, in harbor  
ship02, in transit  
ship03, moored  
ship04, in transit  
ship05, in transit

Now using an aggregate query like this

```
"aggs": {
    "ship_agg": {
        "terms": {
            "field": "status",
        }
    }
}

```

gives me buckets, where the individual words are counted.

bucket("in") is 4  
bucket("harbor") is 1  
bucket("transit") is 3  
bucket("moored") is 1

But what I need are counts of the whole status field, where the values are treated in whole,

bucket ("in harbor") is 3  
bucket ("in transit") is 1  
bucket ("moored") is 1

Can you suggest how my "aggs" clause can be changed to do this?

Thanks.

-- Chris Curzon

---

<div class="post-metadata">

**Author:** ![msimos](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@msimos](https://discuss.elastic.co/u/msimos)\
**Post date:** [January 15, 2016, 9:28pm UTC](https://discuss.elastic.co/t/counting-a-whole-strings-not-individual-words-in-the-string/39357/2 "2016-01-15T21:28:36Z")

</div>

You need to change or add another field with the index as not\_analyzed:

```auto
{
    "status": {
        "type": "string",
        "index": "not_analyzed"
    }
}

```

[https://www.elastic.co/guide/en/elasticsearch/reference/2.1/string.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.1/string.html)

You can also use multi-fields to have status & status.raw:

[https://www.elastic.co/guide/en/elasticsearch/reference/2.1/multi-fields.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.1/multi-fields.html)

---

<div class="post-metadata">

**Author:** ![Christopher\_Curzon](https://avatars.discourse-cdn.com/v4/letter/c/2acd7d/32.png) [@Christopher\_Curzon](https://discuss.elastic.co/u/Christopher_Curzon)\
**Post date:** [January 15, 2016, 11:40pm UTC](https://discuss.elastic.co/t/counting-a-whole-strings-not-individual-words-in-the-string/39357/3 "2016-01-15T23:40:46Z")

</div>

Thanks for the reply.

We did try the "not\_analyzed" feature, but the results still seemed to drill down to the word.

Maybe I'm not handling the bigger picture correctly. Here's what I'm doing.

------------- config file -------------

input { file ... etc }

filter {  
csv {  
columns =\> [  
"shipid",  
"status",  
"rec\_date"  
]  
separator =\> ","  
}  
}

output { elasticsearch ... etc ...}

* * *

I'm not really fluent with the syntax yet. In the Logstash config, where would your suggestion go? Should I add the type and index into the csv column list. So would I change the filter{} clause, like this

filter {  
csv {  
columns =\> [  
"shipid",  
"status" : { "type": "string", "index": "not\_analyzed" }  
"rec\_date" ]  
separator =\> ","  
}  
}

but that doesn't pass --configtest in Logstash, so I'm not sure how to proceed.

Thanks.

---

<div class="post-metadata">

**Author:** ![msimos](https://avatars.discourse-cdn.com/v4/letter/m/bb73d2/32.png) [@msimos](https://discuss.elastic.co/u/msimos)\
**Post date:** [January 16, 2016, 12:15am UTC](https://discuss.elastic.co/t/counting-a-whole-strings-not-individual-words-in-the-string/39357/4 "2016-01-16T00:15:06Z")

</div>

Hi,

You can have 2 fields, one analyzed and one not\_analyzed. If you do a query you can use the analyzed field. And if you do a aggregation, you can do it on the not\_analyzed field.

You need to update your index mapping in Elasticsearch.

[https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:23pm UTC](https://discuss.elastic.co/t/counting-a-whole-strings-not-individual-words-in-the-string/39357/5 "2017-07-05T23:23:54Z")

</div>


