# Declaring type IP as not\_analyzed in version 1.7

**URL:** <https://discuss.elastic.co/t/declaring-type-ip-as-not-analyzed-in-version-1-7/57113>\
**Category:** Elasticsearch\
**Created:** [August 3, 2016, 2:10pm UTC](https://discuss.elastic.co/t/declaring-type-ip-as-not-analyzed-in-version-1-7/57113 "2016-08-03T14:10:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jay224](https://avatars.discourse-cdn.com/v4/letter/j/dc4da7/32.png) [@jay224](https://discuss.elastic.co/u/jay224)\
**Post date:** [August 3, 2016, 2:10pm UTC](https://discuss.elastic.co/t/declaring-type-ip-as-not-analyzed-in-version-1-7/57113/1 "2016-08-03T14:10:33Z")

</div>

The declaration: index: "not\_analyzed" seems to be not working for type IP in version 1.7.\*  
The documentation for type IP for 1.7 doesn't say anything about not\_analyzed declaration.  
[https://www.elastic.co/guide/en/elasticsearch/reference/1.7/mapping-ip-type.html](https://www.elastic.co/guide/en/elasticsearch/reference/1.7/mapping-ip-type.html)

Why I need it? :  
Without not\_analyzed the aggregation query is returning "key\_as\_string" that I don't want in my resultset. Is there a way to declare type IP as not\_analyzed or instruct aggregation not to return "key\_as\_string" .

---

<div class="post-metadata">

**Author:** ![cbuescher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cbuescher/32/60402_2.png) [@cbuescher](https://discuss.elastic.co/u/cbuescher)\
**Post date:** [August 3, 2016, 2:41pm UTC](https://discuss.elastic.co/t/declaring-type-ip-as-not-analyzed-in-version-1-7/57113/2 "2016-08-03T14:41:50Z")

</div>

I don't quiet understand whats wrong with "key\_as\_string", you can filter that out on the client side I guess. But you can also use [multi fields](https://www.elastic.co/guide/en/elasticsearch/guide/current/multi-fields.html) to store the ip field also as `not_analyzed` string. If you dont need IP sorting or range querying you could just store the IP as string from the start.

Heres a quick example of how to do this with multi fields in version 2.3, but I guess this is quiet similar in 1.7 if you are still using that version:

```auto
PUT /foo
{
  "mappings": {
    "bar" : {
      "properties": {
        "address" : {"type": "ip",
        "fields": {
        "raw": { 
            "type": "string",
            "index": "not_analyzed"
        }
        }
    
      }
    }
  }
}
}

GET /foo/_mapping

PUT /foo/bar/1
{
  "address" : "123.123.123.123"
}

GET /foo/bar/_search
{
  "aggs": {
    "test": {
      "terms": {
        "field": "address.raw",
        "size": 10
      }
    }
  }
}

===>

"aggregations": {
    "test": {
      "doc_count_error_upper_bound": 0,
      "sum_other_doc_count": 0,
      "buckets": [
        {
          "key": "123.123.123.123",
          "doc_count": 1
        }
      ]
    }
  }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:30pm UTC](https://discuss.elastic.co/t/declaring-type-ip-as-not-analyzed-in-version-1-7/57113/3 "2017-07-05T22:30:23Z")

</div>


