# Elastic SQL: How to get length of a field?

**URL:** <https://discuss.elastic.co/t/elastic-sql-how-to-get-length-of-a-field/252417>\
**Category:** Elasticsearch\
**Created:** [October 17, 2020, 10:26am UTC](https://discuss.elastic.co/t/elastic-sql-how-to-get-length-of-a-field/252417 "2020-10-17T10:26:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [October 17, 2020, 10:26am UTC](https://discuss.elastic.co/t/elastic-sql-how-to-get-length-of-a-field/252417/1 "2020-10-17T10:26:33Z")

</div>

SQL query fails when I do a String function

The original data is

```auto
  SELECT "message" FROM ".kibana-event-log-7.9.1-000001"
     message     
-----------------
eventLog starting
eventLog starting

```

When I do a length

```auto
POST /_sql?format=txt
{
  "query": """
  SELECT LENGTH("message") FROM ".kibana-event-log-7.9.1-000001"
  """
} 

```

The error shown is

```auto
"reason" : "Found 1 problem\nline 2:10: [LENGTH(\"message\")] cannot operate on field of data type [text]: 
No keyword/multi-field defined exact matches for [message]; define one or use MATCH/QUERY instead"

```

if I put as `message.keyword`, it fails completely by saying there is no such field present.

```auto
  SELECT LENGTH("message.keyword") FROM ".kibana-event-log-7.9.1-000001"

        "reason" : "Found 1 problem\nline 2:17: Unknown column [message.keyword]"

```

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [October 17, 2020, 11:38am UTC](https://discuss.elastic.co/t/elastic-sql-how-to-get-length-of-a-field/252417/2 "2020-10-17T11:38:13Z")

</div>

May be you need to update your index mapping to add the keywork field, as SQL function LENGTH can be only applied to keyword field

```
PUT .kibana-event-log-7.9.1-000001/_mapping
{
  "properties": {
    "message": {
      "type": "text",
       "norms" : false,
      "fields": {
        "keyword": {
          "type": "keyword"
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [October 17, 2020, 3:12pm UTC](https://discuss.elastic.co/t/elastic-sql-how-to-get-length-of-a-field/252417/3 "2020-10-17T15:12:29Z")

</div>

I thought Elastic did keyword by default for all string fields? i.e. there will be a "message" and "message.keyword" automatically. may be i'm wrong

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [October 17, 2020, 3:16pm UTC](https://discuss.elastic.co/t/elastic-sql-how-to-get-length-of-a-field/252417/4 "2020-10-17T15:16:37Z")

</div>

There is a mapping template behind  
Check it here `GET _template/.kibana-event-log-7.9.1-template`  
You will see this part, wish show that there is no keyword field

```
"message" : {
  "norms" : false,
  "type" : "text"
},

```

If there is no explicit mapping defined, Yes elasticsearch will automtically create 2 fields message as text and message.keyword as keyword

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [October 17, 2020, 4:04pm UTC](https://discuss.elastic.co/t/elastic-sql-how-to-get-length-of-a-field/252417/5 "2020-10-17T16:04:08Z")

</div>

correct. Mine shows as

```auto
        "message" : {
          "norms" : false,
          "type" : "text"
        },

```

Since, no explicity mapping not defined, should ES have created keyword field also?

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [October 17, 2020, 4:06pm UTC](https://discuss.elastic.co/t/elastic-sql-how-to-get-length-of-a-field/252417/6 "2020-10-17T16:06:27Z")

</div>

This an explicit mapping that was defined, so no keyword will added by default  
You should change the template` .kibana-event-log-7.9.1-template`  
and also change the mapping of already created indexes like `.kibana-event-log-7.9.1-000001`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2020, 4:06pm UTC](https://discuss.elastic.co/t/elastic-sql-how-to-get-length-of-a-field/252417/7 "2020-11-14T16:06:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
