# Elasticsearch - searching with "keyword" type don't work

**URL:** <https://discuss.elastic.co/t/elasticsearch-searching-with-keyword-type-dont-work/118050>\
**Category:** Elasticsearch\
**Created:** [February 1, 2018, 3:22pm UTC](https://discuss.elastic.co/t/elasticsearch-searching-with-keyword-type-dont-work/118050 "2018-02-01T15:22:43Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikita\_Krasnov](https://avatars.discourse-cdn.com/v4/letter/n/53a042/32.png) [@Nikita\_Krasnov](https://discuss.elastic.co/u/Nikita_Krasnov)\
**Post date:** [February 1, 2018, 3:22pm UTC](https://discuss.elastic.co/t/elasticsearch-searching-with-keyword-type-dont-work/118050/1 "2018-02-01T15:22:43Z")

</div>

I use Elasticsearch Java rest client 6.1. When I try to find logs due to a few parametrs than can be in one field I get nothing  
Here is my code:

```
 @Override
    public SearchResponse findLogsByValues(ElasticSearchLogRequest esLogRequest, Pageable pageable) {
        SearchRequest searchRequest = new SearchRequest("portal-logs-*");

        SearchSourceBuilder sourceBuilder = new SearchSourceBuilder();
        BoolQueryBuilder bqb = QueryBuilders.boolQuery();
 if (esLogRequest.getLevels() != null) {
            Iterator<String> iterator = esLogRequest.getLevels().iterator();
            int counter = 0;
            SpanOrQueryBuilder spanOrQueryBuilder = null;
            while (iterator.hasNext()) {
                if (counter == 0) {
                    spanOrQueryBuilder = new SpanOrQueryBuilder(QueryBuilders.
                            spanTermQuery("level", iterator.next().toLowerCase()));
                } else {
                    spanOrQueryBuilder.addClause(QueryBuilders.
                            spanTermQuery("level", iterator.next().toLowerCase()));
                }
                counter++;
            }
            bqb.filter(spanOrQueryBuilder);
        }
 try {
            searchResponse = client.search(searchRequest);
        } catch (IOException e) {
            e.printStackTrace();
        }
        return searchResponse;
    }

```

Here is my json request:

```
{
	
	"levels": ["TRACE","INFO"]
	
}

```

Here is my mapping template:

```
  PUT _template/portal-logs
{
  "template": "portal-logs-*",
  "settings": { "number_of_shards": 5 },
  "mappings": {
      "logs_info": {
        "_all": {
          "enabled": false
        },
        "properties": {
          "device": {"type": "keyword"},
          "header": {"type": "text"},
          "ip": {"type": "keyword"},
          "level": {"type": "keyword"},
          "location": {"type": "geo_point"},
          "message": {"type": "text"},
          "module": {"type": "keyword"},
          "node": {"type": "keyword"},
          "office": {"type": "keyword"},
          "operation": {"type": "keyword"},
          "port": {"type": "integer"},
          "sessionId": {"type": "keyword"},
          "submodule": {"type": "keyword"},
          "system": {"type": "keyword"},
          "thread": {"type": "keyword"},
          "timeStamp": {"type": "date"},
          "userLogin": {"type": "keyword"},
          "userName": {"type": "keyword"}
        }
      }
    }
  }

```

So when in mapping field "level" and set it as "text" - it works fine but when I set "keyword" - I receive an empty json.  
I need that field "level" has a strict type "keyword" and it has to work when I want to get all logs that have "level" "INFO" or "TRACE".  
What should I do in such case? Why with keyword it's not working?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 1, 2018, 3:52pm UTC](https://discuss.elastic.co/t/elasticsearch-searching-with-keyword-type-dont-work/118050/2 "2018-02-01T15:52:18Z")

</div>

I believe that this is wrong:

```
iterator.next().toLowerCase()

```

And should be

```
iterator.next().toUpperCase()
```

---

<div class="post-metadata">

**Author:** ![Nikita\_Krasnov](https://avatars.discourse-cdn.com/v4/letter/n/53a042/32.png) [@Nikita\_Krasnov](https://discuss.elastic.co/u/Nikita_Krasnov)\
**Post date:** [February 1, 2018, 4:06pm UTC](https://discuss.elastic.co/t/elasticsearch-searching-with-keyword-type-dont-work/118050/4 "2018-02-01T16:06:45Z")

</div>

I just tried to use toLowerCase() after your answer [[Searching for a few fields from Set Collection](https://discuss.elastic.co/t/searching-for-a-few-fields-from-set-collection/117189/2?u=nikita_krasnov)]([http://dadoonet](http://dadoonet) answer) and it works with "text" type but didn't work with "keyword".  
May you help with explanation of this case?

---

<div class="post-metadata">

**Author:** ![Nikita\_Krasnov](https://avatars.discourse-cdn.com/v4/letter/n/53a042/32.png) [@Nikita\_Krasnov](https://discuss.elastic.co/u/Nikita_Krasnov)\
**Post date:** [February 1, 2018, 4:07pm UTC](https://discuss.elastic.co/t/elasticsearch-searching-with-keyword-type-dont-work/118050/5 "2018-02-01T16:07:03Z")

</div>

> [@Nikita\_Krasnov](#):
>
> with iterator.next().toUpperCase() it's also not working.
> 
> Even if I use just iterator.next() - it's not working.
> 
> But all letters in "level" fields in ES consists of upper case letters.

with iterator.next().toUpperCase() it's also not working.  
Even if I use just iterator.next() - it's not working.  
But all letters in "level" fields in ES consists of upper case letters.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 1, 2018, 4:26pm UTC](https://discuss.elastic.co/t/elasticsearch-searching-with-keyword-type-dont-work/118050/6 "2018-02-01T16:26:04Z")

</div>

I don't know exactly as I don't fully understand what you are doing. It would be better to provide a full recreation script as described in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will help to better understand what you are doing. Please, try to keep the example as simple as possible.

Not using Java but just with simple recreation that you can run in Kibana console.

Most likely, when you index a field `"foo": "BAR"`, with a default analyzer, `foo` is indexed as `bar`. With a `keyword` type, it's indexed as `BAR`.

When running a match query for example on that field, searching for `BaR` in the former case will transform to `bar` and it will match.  
Searching for `BaR` in the later case won't match `bar`.

You can understand all that by using the `_analyze` API.

---

<div class="post-metadata">

**Author:** ![Nikita\_Krasnov](https://avatars.discourse-cdn.com/v4/letter/n/53a042/32.png) [@Nikita\_Krasnov](https://discuss.elastic.co/u/Nikita_Krasnov)\
**Post date:** [February 2, 2018, 8:47am UTC](https://discuss.elastic.co/t/elasticsearch-searching-with-keyword-type-dont-work/118050/7 "2018-02-02T08:47:24Z")

</div>

```
GET /_search
{
    "query": {
        "span_or" : {
            "clauses" : [
                { "span_term" : { "level" : "TRACE" } },
                { "span_term" : { "level" : "INFO" } }
            ]
        }
    }
}

```

and in response I get this:

```
{
  "took": 16,
  "timed_out": false,
  "_shards": {
    "total": 26,
    "successful": 25,
    "skipped": 0,
    "failed": 1,
    "failures": [
      {
        "shard": 3,
        "index": "portal-logs-02.02.2018",
        "node": "SAPKQLGGSJiR8bMBdkNvfQ",
        "reason": {
          "type": "illegal_state_exception",
          "reason": """field "level" was indexed without position data; cannot run SpanTermQuery (term=TRACE)"""
        }
      }
    ]
  },
  "hits": {
    "total": 0,
    "max_score": null,
    "hits": []
  }
}
```

---

<div class="post-metadata">

**Author:** ![Nikita\_Krasnov](https://avatars.discourse-cdn.com/v4/letter/n/53a042/32.png) [@Nikita\_Krasnov](https://discuss.elastic.co/u/Nikita_Krasnov)\
**Post date:** [February 2, 2018, 9:11am UTC](https://discuss.elastic.co/t/elasticsearch-searching-with-keyword-type-dont-work/118050/8 "2018-02-02T09:11:26Z")

</div>

but when I try to set another mapping for "level" : `"level": {"type": "keyword", "term_vector":"with_positions"}`  
I get this exception:

```
{
  "error": {
    "root_cause": [
      {
        "type": "mapper_parsing_exception",
        "reason": "Mapping definition for [level] has unsupported parameters: [term_vector : with_positions]"
      }
    ],
    "type": "mapper_parsing_exception",
    "reason": "Failed to parse mapping [logs_info]: Mapping definition for [level] has unsupported parameters: [term_vector : with_positions]",
    "caused_by": {
      "type": "mapper_parsing_exception",
      "reason": "Mapping definition for [level] has unsupported parameters: [term_vector : with_positions]"
    }
  },
  "status": 400
}
```

---

<div class="post-metadata">

**Author:** ![Nikita\_Krasnov](https://avatars.discourse-cdn.com/v4/letter/n/53a042/32.png) [@Nikita\_Krasnov](https://discuss.elastic.co/u/Nikita_Krasnov)\
**Post date:** [February 2, 2018, 9:36am UTC](https://discuss.elastic.co/t/elasticsearch-searching-with-keyword-type-dont-work/118050/9 "2018-02-02T09:36:43Z")

</div>

bqb.filter(QueryBuilders.termsQuery("level", esLogRequest.getLevels()));  
this helps

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2018, 9:37am UTC](https://discuss.elastic.co/t/elasticsearch-searching-with-keyword-type-dont-work/118050/10 "2018-03-02T09:37:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
