# Elasticsearch how to create index template with raw field

**URL:** <https://discuss.elastic.co/t/elasticsearch-how-to-create-index-template-with-raw-field/114253>\
**Category:** Elasticsearch\
**Created:** [January 5, 2018, 9:47am UTC](https://discuss.elastic.co/t/elasticsearch-how-to-create-index-template-with-raw-field/114253 "2018-01-05T09:47:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jerrychen](https://avatars.discourse-cdn.com/v4/letter/j/839c29/32.png) [@jerrychen](https://discuss.elastic.co/u/jerrychen)\
**Post date:** [January 5, 2018, 9:47am UTC](https://discuss.elastic.co/t/elasticsearch-how-to-create-index-template-with-raw-field/114253/1 "2018-01-05T09:47:55Z")

</div>

Elasticsearch 5.4.0  
My logstash will create index by date, I want to create index template,which can auto add raw field not-analyzed. so i can do aggs term by string field. I got some error when create template by kibana dev tools.  
DSL text:  
put /\_template/template\_log  
{  
"template": "logstash-log\*",  
"mappings": {  
"gw-apache": {  
"properties": {  
"url": {  
"type" :"text",  
"fileds":{  
"raw":{  
"type":"text",  
"index":"not\_analyzed"  
}  
}  
}  
}  
}  
}  
}  
error output:  
{  
"error": {  
"root\_cause": [  
{  
"type": "mapper\_parsing\_exception",  
"reason": "Mapping definition for [url] has unsupported parameters: [fileds : {raw={index=not\_analyzed, type=text}}]"  
}  
],  
"type": "mapper\_parsing\_exception",  
"reason": "Failed to parse mapping [gw\_apache]: Mapping definition for [url] has unsupported parameters: [fileds : {raw={index=not\_analyzed, type=text}}]",  
"caused\_by": {  
"type": "mapper\_parsing\_exception",  
"reason": "Mapping definition for [url] has unsupported parameters: [fileds : {raw={index=not\_analyzed, type=text}}]"  
}  
},  
"status": 400  
}

Thanks for your help

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [January 5, 2018, 1:02pm UTC](https://discuss.elastic.co/t/elasticsearch-how-to-create-index-template-with-raw-field/114253/2 "2018-01-05T13:02:53Z")

</div>

There are two problems with your index template:

- A typo: you wrote `fileds` instead of `fields`
- `"index":"not_analyzed"` for `text` fields does not exist anymore. It has been replaced by [a `keyword` type](https://www.elastic.co/blog/strings-are-dead-long-live-strings).

The following index template should work:

```
PUT /_template/template_log
{
  "template": "logstash-log*",
  "mappings": {
    "gw-apache": {
      "properties": {
        "url": {
          "type": "text",
          "fields": {
            "raw": {
              "type": "keyword"
            }
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![abdon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abdon/32/9195_2.png) [@abdon](https://discuss.elastic.co/u/abdon)\
**Post date:** [January 5, 2018, 1:05pm UTC](https://discuss.elastic.co/t/elasticsearch-how-to-create-index-template-with-raw-field/114253/3 "2018-01-05T13:05:13Z")

</div>

By the way, what you're trying to do with the index template is the default behavior of Elasticsearch since 5.0. By default, any string will be dynamically mapped to type `text` as well as as a `keyword` multifield. To access that multifield, use `url.keyword` instead of `url.raw`. So, you may not need that index template...

---

<div class="post-metadata">

**Author:** ![jerrychen](https://avatars.discourse-cdn.com/v4/letter/j/839c29/32.png) [@jerrychen](https://discuss.elastic.co/u/jerrychen)\
**Post date:** [January 8, 2018, 10:32am UTC](https://discuss.elastic.co/t/elasticsearch-how-to-create-index-template-with-raw-field/114253/4 "2018-01-08T10:32:52Z")

</div>

Thank you so much.I got it

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2018, 10:32am UTC](https://discuss.elastic.co/t/elasticsearch-how-to-create-index-template-with-raw-field/114253/5 "2018-02-05T10:32:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
