# Documentation for the raw field

**URL:** <https://discuss.elastic.co/t/documentation-for-the-raw-field/111137>\
**Category:** Logstash\
**Created:** [December 11, 2017, 4:08pm UTC](https://discuss.elastic.co/t/documentation-for-the-raw-field/111137 "2017-12-11T16:08:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul\_D\_Ambra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_d_ambra/32/10728_2.png) [@Paul\_D\_Ambra](https://discuss.elastic.co/u/Paul_D_Ambra)\
**Post date:** [December 11, 2017, 4:08pm UTC](https://discuss.elastic.co/t/documentation-for-the-raw-field/111137/1 "2017-12-11T16:08:17Z")

</div>

I've found some code where applications are purposefully logging JSON instead of a message and inside that JSON logging a string into a field called raw.

My understanding is that raw is normally autocreated and we're limiting our query abilities by writing directly to it. Is that right? Is the raw field documented somewhere so I can support my request for change?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 12, 2017, 6:29am UTC](https://discuss.elastic.co/t/documentation-for-the-raw-field/111137/2 "2017-12-12T06:29:00Z")

</div>

> I've found some code where applications are purposefully logging JSON instead of a message and inside that JSON logging a string into a field called raw.

Can you show an example so it's clear exactly what we're talking about?

> My understanding is that raw is normally autocreated and we're limiting our query abilities by writing directly to it. Is that right? Is the raw field documented somewhere so I can support my request for change?

You can certainly name fields `raw`; they won't collide with the `.raw` or `.keyword` subfields exposed in Elasticsearch (depending on the index's mappings). To understand the different between fields `x` and `x.keyword` read what the ES documentation says about text and keyword fields.

---

<div class="post-metadata">

**Author:** ![Paul\_D\_Ambra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_d_ambra/32/10728_2.png) [@Paul\_D\_Ambra](https://discuss.elastic.co/u/Paul_D_Ambra)\
**Post date:** [December 12, 2017, 8:43am UTC](https://discuss.elastic.co/t/documentation-for-the-raw-field/111137/3 "2017-12-12T08:43:21Z")

</div>

Thanks for replying 🙂

so the JSON sent to logstash would be like

```
{ @timestamp: "2017-04-01etc", message: { raw: "some text" }}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 12, 2017, 8:46am UTC](https://discuss.elastic.co/t/documentation-for-the-raw-field/111137/4 "2017-12-12T08:46:11Z")

</div>

That's not valid JSON, but yes, structure-wise that should be okay.

---

<div class="post-metadata">

**Author:** ![Paul\_D\_Ambra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_d_ambra/32/10728_2.png) [@Paul\_D\_Ambra](https://discuss.elastic.co/u/Paul_D_Ambra)\
**Post date:** [December 12, 2017, 9:08am UTC](https://discuss.elastic.co/t/documentation-for-the-raw-field/111137/5 "2017-12-12T09:08:32Z")

</div>

Yep, wrote it by hand for example purposes 😃

So, in that scenario because message.raw is a string field we'd have ended up with message.raw.raw?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 12, 2017, 9:34am UTC](https://discuss.elastic.co/t/documentation-for-the-raw-field/111137/6 "2017-12-12T09:34:10Z")

</div>

Yes, if it's an analyzed string field (ES prior to 5.0) or a text field (ES 5+).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2018, 9:34am UTC](https://discuss.elastic.co/t/documentation-for-the-raw-field/111137/7 "2018-01-09T09:34:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
