# Disable source for metric index, any downside?

**URL:** <https://discuss.elastic.co/t/disable-source-for-metric-index-any-downside/51201>\
**Category:** Elasticsearch\
**Created:** [May 27, 2016, 9:51pm UTC](https://discuss.elastic.co/t/disable-source-for-metric-index-any-downside/51201 "2016-05-27T21:51:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![iamthealex](https://avatars.discourse-cdn.com/v4/letter/i/e9c0ed/32.png) [@iamthealex](https://discuss.elastic.co/u/iamthealex)\
**Post date:** [May 27, 2016, 9:51pm UTC](https://discuss.elastic.co/t/disable-source-for-metric-index-any-downside/51201/1 "2016-05-27T21:51:17Z")

</div>

I have an index that is all metrics.  
I have disabled \_source and \_all for entries in this index.  
I have verified that I can do aggregate queries against this index.  
I am assuming that kibana only cares about is the returned aggregation information and doesn't care about source.  
I'm struggling to determine any upside for keeping \_source around for a metric index.

Not only do I plan to visualize my data using Kibana, but I also intend to do ad-hoc queries against my data. When I disable \_source, I find that I can still get ad-hoc search results by adding a fielddata\_fields child to the \_search endpoint.

I use a search syntax like this:  
GET /access-log-lines/v1/\_search  
{  
"query": {  
"bool": {  
"must": {  
"prefix": {  
"http.request.host": "[www.example.com](http://www.example.com)"  
}  
},  
"must\_not": {  
"match": {  
"[http.request.UA.name](http://http.request.UA.name)": "Chrome"  
}  
}  
}  
},  
"fielddata\_fields": [  
"[http.request.UA.name](http://http.request.UA.name)"  
]  
}

I get output from that ad-hoc (non-aggregate) search query that looks like this:  
...  
{  
"\_index": "access-log-lines",  
"\_type": "v1",  
"\_id": "314159",  
"\_score": 1.0,  
"fields": {  
"http.request.host": [  
"[www.example.com](http://www.example.com)"  
],  
"http.request.UA.os\_name": [  
"Other"  
]  
}  
},  
...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 28, 2016, 1:00am UTC](https://discuss.elastic.co/t/disable-source-for-metric-index-any-downside/51201/2 "2016-05-28T01:00:28Z")

</div>

For this sort of use case the only downside would be that you cannot reindex.  
This may not matter much to you, but there are some changes around strings in 5.0 that may have you second guessing disabling things.

---

<div class="post-metadata">

**Author:** ![iamthealex](https://avatars.discourse-cdn.com/v4/letter/i/e9c0ed/32.png) [@iamthealex](https://discuss.elastic.co/u/iamthealex)\
**Post date:** [May 31, 2016, 9:48pm UTC](https://discuss.elastic.co/t/disable-source-for-metric-index-any-downside/51201/3 "2016-05-31T21:48:00Z")

</div>

Okay, so it sounds like the roadmap is such that I shouldn't worry about disabling source.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:47pm UTC](https://discuss.elastic.co/t/disable-source-for-metric-index-any-downside/51201/4 "2017-07-05T22:47:29Z")

</div>


