# Enable .keyword fields for specific fields only

**URL:** <https://discuss.elastic.co/t/enable-keyword-fields-for-specific-fields-only/286866>\
**Category:** Elasticsearch\
**Created:** [October 15, 2021, 5:51pm UTC](https://discuss.elastic.co/t/enable-keyword-fields-for-specific-fields-only/286866 "2021-10-15T17:51:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rakesh\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakesh_b/32/48128_2.png) [@Rakesh\_B](https://discuss.elastic.co/u/Rakesh_B)\
**Post date:** [October 15, 2021, 5:51pm UTC](https://discuss.elastic.co/t/enable-keyword-fields-for-specific-fields-only/286866/1 "2021-10-15T17:51:51Z")

</div>

Hi,

Elasticsearch Version: 7.15.0  
Logstash Version: 7.15.0

We have a ton of fields for our index and we get new fields frequently so, we cannot disable dynamic mapping. Dynamic mapping creates `.keyword` fields for a majority of the fields and we don't want that for `ALL` fields. By default we want to disable creating `.keyword` fields for all fields and enable that feature for specific fields. Can someone please tell us how we can achieve that?

FYI: we tried the following config on the index template (hoping that just `request.*` fields will get `.keyword` field) but it didn't work, we noticed that ALL `.keyword` fields are removed including `request.*` fields:

```auto
  "mappings" : {
      "dynamic_templates": [
      {
        "strings": {
          "match_mapping_type": "string",
          "path_unmatch": "request.*",
          "mapping": {
            "type": "text"
          }
        }
      },
      {
        "request_url": {
          "match_mapping_type": "string",
          "path_match": "request.*",
          "mapping": {
            "type": "keyword"
          }
        }
      }
    ]
  },

```

- Thank you

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 15, 2021, 8:08pm UTC](https://discuss.elastic.co/t/enable-keyword-fields-for-specific-fields-only/286866/2 "2021-10-15T20:08:07Z")

</div>

I think there is some confusion here, you are mixing up the name of the field with the mapping of the field.

If you do not create a mapping for a field, Elasticsearch will create a mapping for this field when it receives the first document, for string fields it will map the field first as a `text` field and then it will map the same field again as a `keyword` field, this is done using [multi-fields](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/multi-fields.html#multi-fields).

What happens is that, for example, if you have an unmapped field named `ExampleField`, and let Elasticsearch create the mapping, this is what you will have in the mapping:

```auto
        "ExampleField": {
          "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
        }

```

The parte after `fields` is the multi-field, what it is doing is mapping the same field on a different way with the suffix `keyword`.

So you have `ExampleField` as a `text` field and `Example.keyword` as a `keyword` field.

Since you are explicitly telling Elasticsearch to map fields starting with `request.*` as `keyword`, you will not have any field with the suffix `.keyword`, but all the `request.*` field will be mapped as `keyword` field.

---

<div class="post-metadata">

**Author:** ![Rakesh\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakesh_b/32/48128_2.png) [@Rakesh\_B](https://discuss.elastic.co/u/Rakesh_B)\
**Post date:** [October 15, 2021, 8:16pm UTC](https://discuss.elastic.co/t/enable-keyword-fields-for-specific-fields-only/286866/3 "2021-10-15T20:16:31Z")

</div>

Thank you very much for a speedy reply.  
I guess my next question is:

- How do I enable both `text` and `keyword` fields for `request.*` fields? right now we are only getting `keyword` fields, we want a `text` field like `request.*` and ` keyword` field `request.*.keyword` as well.

- Thank you

---

<div class="post-metadata">

**Author:** ![Rakesh\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rakesh_b/32/48128_2.png) [@Rakesh\_B](https://discuss.elastic.co/u/Rakesh_B)\
**Post date:** [October 15, 2021, 8:26pm UTC](https://discuss.elastic.co/t/enable-keyword-fields-for-specific-fields-only/286866/4 "2021-10-15T20:26:16Z")

</div>

this worked for me:

```auto
      "dynamic_templates": [
      {
        "strings": {
          "match_mapping_type": "string",
          "path_unmatch": "request.*",
          "match": "*",
          "mapping": {
            "type": "text"
          }
        }
      },
      {
        "request_url": {
          "match_mapping_type": "string",
          "path_match": "request.*",
          "mapping": {
            "type": "text",
          "fields": {
            "keyword": {
              "type": "keyword",
              "ignore_above": 256
            }
          }
          }
        }
      }
    ]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2021, 8:26pm UTC](https://discuss.elastic.co/t/enable-keyword-fields-for-specific-fields-only/286866/5 "2021-11-12T20:26:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
