# ES Mapping template taking "index : analyzed" despite I am using "index : not\_analyzed"

**URL:** https://discuss.elastic.co/t/es-mapping-template-taking-index-analyzed-despite-i-am-using-index-not-analyzed/28592
**Category:** Elasticsearch
**Created:** [September 3, 2015, 9:37am UTC](https://discuss.elastic.co/t/es-mapping-template-taking-index-analyzed-despite-i-am-using-index-not-analyzed/28592 "2015-09-03T09:37:14Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![peterj](https://avatars.discourse-cdn.com/v4/letter/p/22d042/32.png) [@peterj](https://discuss.elastic.co/u/peterj)
#### Post date: [September 3, 2015, 9:37am UTC](https://discuss.elastic.co/t/es-mapping-template-taking-index-analyzed-despite-i-am-using-index-not-analyzed/28592/1 "2015-09-03T09:37:14Z")

</div>

Hello Experts,

I am using below ES/logstash template to create a mapping. I used "index : not\_analyzed" in my template but after index creation when I look it via kibana/curl I am getting index as analyzed. Why did index set as analyzed? Can someone help me to fix this issue?

ES Template

* * *

{  
"template" : "apacheaccesslog",  
"settings" : { "index.refresh\_interval" : "60s" },  
"mappings" : {  
"_default_" : {  
"\_all" : { "enabled" : false },  
"dynamic\_templates" : [{  
"message\_field" : {  
"match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : { "type" : "string", "index" : "not\_analyzed" }  
}  
}, {  
"string\_fields" : {  
"match" : "\*",  
"match\_mapping\_type" : "string",  
"mapping" : { "type" : "string", "index" : "not\_analyzed" }  
}  
}],  
"properties" : {  
"@timestamp" : { "type" : "date", "format" : "dateOptionalTime" },  
"@version" : { "type" : "integer", "index" : "not\_analyzed" },  
"agent" : { "type" : "string", "index" : "not\_analyzed" },  
"bytes" : { "type" : "long", "norms" : { "enabled" : false } },  
"host" : { "type" : "string", "index" : "not\_analyzed" },  
"clientip" : { "type" : "ip", "norms" : { "enabled" : false } },  
"httpversion" : { "type" : "float" },  
"referrer" : { "type" : "string", "index" : "not\_analyzed" },  
"request" : { "type" : "string", "index" : "not\_analyzed", "include\_in\_all": false },  
"response" : { "type" : "integer", "index" : "not\_analyzed" },  
"geoip" : { "type" : "object", "dynamic" : true, "path" : "full", "properties" : { "location" : { "type" : "geo\_point" } } },  
"verb" : { "type" : "string", "norms" : { "enabled" : false } }  
}  
}  
}  
}

Logstash output part

* * *

output {  
elasticsearch {  
host =\> "192.168.1.24"  
cluster =\> "remcal"  
protocol =\> "http"  
index =\> "apacheaccesslog-%{+YYYY.MM.dd}"  
template =\> "/etc/elasticsearch/templates/apacheaccess.json"  
template\_name =\> "apacheaccesslog"  
template\_overwrite =\> true  
}  
}

ES Mapping after index creation

* * *

[root@peter templates]# curl -XGET '[http://localhost:9200/apacheaccesslog-2015.08.31/\_mapping?pretty=true](http://localhost:9200/apacheaccesslog-2015.08.31/_mapping?pretty=true)  
'  
{  
"apache-accesslog-2015.08.31" : {  
"mappings" : {  
"apache\_access" : {  
"properties" : {  
"@timestamp" : {  
"type" : "date",  
"format" : "dateOptionalTime"  
},  
"@version" : {  
"type" : "string"  
},  
"agent" : {  
"type" : "string"  
},  
"agent.device" : {  
"type" : "string"  
},  
"agent.name" : {  
"type" : "string"  
},  
"agent.os" : {  
"type" : "string"  
},  
"agent.os\_name" : {  
"type" : "string"  
},  
"auth" : {  
"type" : "string"  
},  
"bytes" : {  
"type" : "string"  
},  
"clientip" : {  
"type" : "string"  
},  
"host" : {  
"type" : "string"  
},  
"httpversion" : {  
"type" : "string"  
},  
"ident" : {  
"type" : "string"  
},  
"message" : {  
"type" : "string"  
},  
"path" : {  
"type" : "string"  
},  
"referrer" : {  
"type" : "string"  
},  
.......  
},  
"verb" : {  
"type" : "string"  
}  
}  
}  
}  
}  
}

ES Version

* * *

[root@peter templates]# rpm -q elasticsearch  
elasticsearch-1.7.1-1.noarch

Regards,  
Peter

---

<div class="post-metadata">

### Author: ![peterj](https://avatars.discourse-cdn.com/v4/letter/p/22d042/32.png) [@peterj](https://discuss.elastic.co/u/peterj)
#### Post date: [September 3, 2015, 7:05pm UTC](https://discuss.elastic.co/t/es-mapping-template-taking-index-analyzed-despite-i-am-using-index-not-analyzed/28592/3 "2015-09-03T19:05:03Z")

</div>

Hello,

Can anyone help me with this?

Regards,  
Peter

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [September 3, 2015, 8:40pm UTC](https://discuss.elastic.co/t/es-mapping-template-taking-index-analyzed-despite-i-am-using-index-not-analyzed/28592/4 "2015-09-03T20:40:54Z")

</div>

> [@peterj](#):
>
> "template" : "apacheaccesslog"

The template you have provided does not contain a wildcard to make it match the index pattern specified in the logstash config. Try changing this to _"template" : "apacheaccesslog_"\* instead and it should apply correctly for newly created indices.

---

<div class="post-metadata">

### Author: ![peterj](https://avatars.discourse-cdn.com/v4/letter/p/22d042/32.png) [@peterj](https://discuss.elastic.co/u/peterj)
#### Post date: [September 4, 2015, 11:25am UTC](https://discuss.elastic.co/t/es-mapping-template-taking-index-analyzed-despite-i-am-using-index-not-analyzed/28592/5 "2015-09-04T11:25:45Z")

</div>

Thanks Christian,

Let me check and get back to you

Regards,  
Peter

---

<div class="post-metadata">

### Author: ![peterj](https://avatars.discourse-cdn.com/v4/letter/p/22d042/32.png) [@peterj](https://discuss.elastic.co/u/peterj)
#### Post date: [September 4, 2015, 5:56pm UTC](https://discuss.elastic.co/t/es-mapping-template-taking-index-analyzed-despite-i-am-using-index-not-analyzed/28592/6 "2015-09-04T17:56:55Z")

</div>

@Christian_Dahlqvist,

Thanks, finally the issue got solved by following your suggestion. I knew I made a minor mistake but could't figure it out.

Regards,  
Peter

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 11:52pm UTC](https://discuss.elastic.co/t/es-mapping-template-taking-index-analyzed-despite-i-am-using-index-not-analyzed/28592/7 "2017-07-05T23:52:02Z")

</div>


