# Exclude particular fields from \[all\_field\] searches

**URL:** <https://discuss.elastic.co/t/exclude-particular-fields-from-all-field-searches/76837>\
**Category:** Elasticsearch\
**Created:** [February 28, 2017, 5:17pm UTC](https://discuss.elastic.co/t/exclude-particular-fields-from-all-field-searches/76837 "2017-02-28T17:17:04Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![niaz](https://avatars.discourse-cdn.com/v4/letter/n/d9b06d/32.png) [@niaz](https://discuss.elastic.co/u/niaz)\
**Post date:** [February 28, 2017, 5:17pm UTC](https://discuss.elastic.co/t/exclude-particular-fields-from-all-field-searches/76837/1 "2017-02-28T17:17:04Z")

</div>

Hello,

I want to use "all\_field" option in my queries to search all indexed fields, but excluding a few. I have elastic search 5.2.1 installed and sent below commands using Kibana to elastic search.

PUT test\_index  
{  
"mappings": {  
"user": {  
"\_all": { "enabled": false },  
"properties": {  
"title": { "type": "text" },  
"name": { "type": "text" },  
"age": { "type": "integer" }  
}  
}  
}  
}

POST test\_index/\_bulk  
{ "index" : { "\_type" : "user", "\_id" : "1" } }  
{ "name" : "niaz", "title" : "test", "age" : 40, "tags" : "toyota, bmw" }  
{ "index" : { "\_type" : "user", "\_id" : "2" } }  
{ "name" : "john", "title" : "toyota", "age" : 30 }  
{ "index" : { "\_type" : "user", "\_id" : "3" } }  
{ "name" : "bell", "title" : "mercedes", "age" : 35 }  
{ "index" : { "\_type" : "user", "\_id" : "4" } }  
{ "name" : "akram", "title" : "bmw", "age" : 42 }

GET test\_index/\_search  
{  
"query": {  
"query\_string": {  
"query": "toyota"  
}  
}  
}

The query returns me 2 documents, this is 100% correct. The question is how can I change my all\_field configuration that the query should exclude the "tags" field from search.

In general, I can configure the custom \_all field OR send the query with multiple-fields. But then my fields will be either indexed twice OR for each query I need to send a large list of fields to elastic search.

Thanks a lot in advance for your help.

Greetings,  
Niaz

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 28, 2017, 10:29pm UTC](https://discuss.elastic.co/t/exclude-particular-fields-from-all-field-searches/76837/2 "2017-02-28T22:29:06Z")

</div>

You may want to disable `_all` and use `copy_to` to create your own version and then pick that as the default search field.

---

<div class="post-metadata">

**Author:** ![niaz](https://avatars.discourse-cdn.com/v4/letter/n/d9b06d/32.png) [@niaz](https://discuss.elastic.co/u/niaz)\
**Post date:** [March 1, 2017, 8:04am UTC](https://discuss.elastic.co/t/exclude-particular-fields-from-all-field-searches/76837/3 "2017-03-01T08:04:05Z")

</div>

Hello,

copy\_to is a possibility, like I mentioned above in this case the data will be indexed twice. Once in the field itself and secondly in the copied field. I would like to know, if there is any other possibility? Can we somehow create a virtual field or some alias in the mapping? That means when this virtual/alias is referenced in the query the corresponding configured fields will be used?

OR configure [all\_field] with one or more fields. In theory, this should be the same mechanism like [all\_field] is working. Currently [all\_field] is automatically translated to all fields in the mapping and I want to influence its translation to some special fields. e.g. for above example to all fields except "tags".

Greetings,  
Niaz

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 1, 2017, 11:12pm UTC](https://discuss.elastic.co/t/exclude-particular-fields-from-all-field-searches/76837/4 "2017-03-01T23:12:54Z")

</div>

> [@niaz](#):
>
> Can we somehow create a virtual field or some alias in the mapping? That means when this virtual/alias is referenced in the query the corresponding configured fields will be used?

Nope.

You could look at [include\_in\_all | Elasticsearch Guide [5.2] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/5.2/include-in-all.html)

---

<div class="post-metadata">

**Author:** ![niaz](https://avatars.discourse-cdn.com/v4/letter/n/d9b06d/32.png) [@niaz](https://discuss.elastic.co/u/niaz)\
**Post date:** [March 2, 2017, 9:51am UTC](https://discuss.elastic.co/t/exclude-particular-fields-from-all-field-searches/76837/5 "2017-03-02T09:51:16Z")

</div>

It seems "include\_in\_all" solves what I need. But the only thing that I want to confirm is:

1 - Does "include\_in\_all" configures in the background the antique "\_all" field where all fields with "include\_in\_all=true" will be double indexed?

OR

2 - This setting only affects the queries with no default field for search and the fields configured with "include\_in\_all=true" will be taken to search in. This is my wished behavior.

I will make an example for (2) and post later today.

Thanks  
Niaz

---

<div class="post-metadata">

**Author:** ![niaz](https://avatars.discourse-cdn.com/v4/letter/n/d9b06d/32.png) [@niaz](https://discuss.elastic.co/u/niaz)\
**Post date:** [March 2, 2017, 10:49am UTC](https://discuss.elastic.co/t/exclude-particular-fields-from-all-field-searches/76837/6 "2017-03-02T10:49:16Z")

</div>

Hello Mark,

I have executed following code and it seems under the hood \_all field is used. That means, the feature of elasticsearch 5.1 can not be used where we can disable the \_all field completely.

1. 

DELETE test\_index

1. 

PUT test\_index  
{  
"mappings": {  
"user": {  
"include\_in\_all": false,  
"properties": {  
"title": { "type": "text", "include\_in\_all": true },  
"name": { "type": "text", "include\_in\_all": true },  
"age": { "type": "integer" },  
"tags": { "type": "text", "include\_in\_all": false }  
}  
}  
}  
}

1. 

POST test\_index/\_bulk  
{ "index" : { "\_type" : "user", "\_id" : "1" } }  
{ "name" : "niaz", "title" : "test", "age" : 40, "tags" : "toyota, bmw" }  
{ "index" : { "\_type" : "user", "\_id" : "2" } }  
{ "name" : "john", "title" : "toyota", "age" : 30 }  
{ "index" : { "\_type" : "user", "\_id" : "3" } }  
{ "name" : "bell", "title" : "mercedes", "age" : 35 }  
{ "index" : { "\_type" : "user", "\_id" : "4" } }  
{ "name" : "akram", "title" : "bmw", "age" : 42 }

1. 

GET test\_index/\_search  
{  
"query": {  
"query\_string": {  
"query": "toyota"  
}  
}  
}

The query under 4 results ONE document, CORRECT as we had disabled "include\_in\_all" from our "tags" field.

Now update the mapping for "tags" field like below:

1. 

PUT test\_index/\_mapping/user  
{  
"properties": {  
"tags" : { "type": "text", "include\_in\_all": true }  
}  
}

Execute the query from point 4 again and it will return again 1 document. That means, the "include\_in\_all" cannot be changed dynamically. Instead the documents that are already indexed will not be affected when this setting is changed from false to true or vice versa.

1. 

I post one more document using below command.  
POST test\_index/\_bulk  
{ "index" : { "\_type" : "user", "\_id" : "5" } }  
{ "name" : "Mark Walkom", "title" : "elastic", "age" : 35, "tags" : "toyota, tesla" }

Execute the query under (4) again and this time 2 documents will be returned as the "tags" field from (6) is indexed.

My point: I want to use the feature of elastic search 5.1 where \_all field can be disabled by default and all fields are indexed only once. At the time of search, when no default field is provided a user configured \_all field should be used for searching. Please accept this feature request for next version of elastic search.

Thanks  
Niaz

---

<div class="post-metadata">

**Author:** ![aaron\_ximm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron_ximm/32/61229_2.png) [@aaron\_ximm](https://discuss.elastic.co/u/aaron_ximm)\
**Post date:** [March 9, 2017, 9:12pm UTC](https://discuss.elastic.co/t/exclude-particular-fields-from-all-field-searches/76837/7 "2017-03-09T21:12:34Z")

</div>

We will want the same thing: to be able to control which fields are excluded from all\_fields in 6.x.

For our case it is critical to be able to exclude specific fields from all\_fields as it would not be feasible to enumerate only included fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2017, 9:13pm UTC](https://discuss.elastic.co/t/exclude-particular-fields-from-all-field-searches/76837/8 "2017-04-06T21:13:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
