# Elasticsearch Output and the raw field

**URL:** <https://discuss.elastic.co/t/elasticsearch-output-and-the-raw-field/754>\
**Category:** Logstash\
**Created:** [May 15, 2015, 1:54pm UTC](https://discuss.elastic.co/t/elasticsearch-output-and-the-raw-field/754 "2015-05-15T13:54:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![elvarb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elvarb/32/44840_2.png) [@elvarb](https://discuss.elastic.co/u/elvarb)\
**Post date:** [May 15, 2015, 1:54pm UTC](https://discuss.elastic.co/t/elasticsearch-output-and-the-raw-field/754/1 "2015-05-15T13:54:05Z")

</div>

Now that the elasticsearch output no longer gives you a message.raw field by default

From the changelog

- Logstash does not create a "message.raw" by default whic is usually not\_analyzed; this helps save disk space (#11)
- Logstash will not create a message.raw field by default now. Message field is not\_analyzed by Elasticsearch and adding a multi-field was essentially doubling the disk space required, with no benefit

The issue goes into enabling it again by modifying the default mapping though.

> <https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/11>
>
> The template that ships with this plugin will add a raw field for each event field. However, in most cases, the...

And this issue shows the method

> <https://github.com/elastic/logstash/issues/2506>

How would I go about disabling the .raw field for other large fields?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 15, 2015, 10:11pm UTC](https://discuss.elastic.co/t/elasticsearch-output-and-the-raw-field/754/2 "2015-05-15T22:11:03Z")

</div>

You need to alter the mapping in Elasticsearch and then just remove those fields.

`curl localhost:9200/_template/logstash` to get the existing mapping template.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/elasticsearch-output-and-the-raw-field/754/3 "2017-07-06T05:39:47Z")

</div>


