# How are strings mapped?

**URL:** <https://discuss.elastic.co/t/how-are-strings-mapped/126787>\
**Category:** Elasticsearch\
**Created:** [April 4, 2018, 4:54pm UTC](https://discuss.elastic.co/t/how-are-strings-mapped/126787 "2018-04-04T16:54:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tony\_Chirillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_chirillo/32/22647_2.png) [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Post date:** [April 4, 2018, 4:54pm UTC](https://discuss.elastic.co/t/how-are-strings-mapped/126787/1 "2018-04-04T16:54:58Z")

</div>

In ES 6.2.2, how are string mapped by default? Are they still mapped as both as both text and keyword by default, or did that change?

---

<div class="post-metadata">

**Author:** ![Evesy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evesy/32/29520_2.png) [@Evesy](https://discuss.elastic.co/u/Evesy)\
**Post date:** [April 4, 2018, 5:09pm UTC](https://discuss.elastic.co/t/how-are-strings-mapped/126787/2 "2018-04-04T17:09:03Z")

</div>

If a string field does not have an explicit mapping in 6.x it'll be mapped by default to both, as per below:

```
"type" "text",
"fields": {
  "keyword": {
    "type": "keyword",
    "ignore_above": 256
  }
}
```

---

<div class="post-metadata">

**Author:** ![Tony\_Chirillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_chirillo/32/22647_2.png) [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Post date:** [April 4, 2018, 5:29pm UTC](https://discuss.elastic.co/t/how-are-strings-mapped/126787/3 "2018-04-04T17:29:41Z")

</div>

Ok Thanks! Do you have much experience with templates? I think I have a template that might be overriding the default settings and only setting the value to one. I'll post it. If you have time, could you let me know if you possible see the mistake? We pulled the template from the web, it is not home grown. As you can tell, I am still working on trying to understand all the different relationships between things. Thanks for the reply.

{  
"template\_exchange": {  
"order": 1,  
"index\_patterns": [  
"exchange-_"  
],  
"settings": {  
"index": {  
"mapping": {  
"total\_fields": {  
"limit": "10000"  
}  
},  
"refresh\_interval": "5s"  
}  
},  
"mappings": {  
"exchange": {  
"dynamic\_templates": [  
{  
"fields": {  
"mapping": {  
"type": "keyword"  
},  
"match\_mapping\_type": "string",  
"path\_match": "fields._"  
}  
},  
{  
"strings\_as\_keyword": {  
"mapping": {  
"ignore\_above": 1024,  
"type": "keyword"  
},  
"match\_mapping\_type": "string"  
}  
}  
],  
"properties": {  
"@timestamp": {  
"type": "date"  
},  
"geoip": {  
"dynamic": true,  
"type": "object",  
"properties": {  
"location": {  
"type": "geo\_point"  
}  
}  
},  
"fields": {  
"type": "object"  
},  
"offset": {  
"type": "long"  
},  
"message": {  
"norms": false,  
"type": "text"  
},  
"beat": {  
"properties": {  
"name": {  
"type": "keyword",  
"ignore\_above": 1024  
},  
"hostname": {  
"type": "keyword",  
"ignore\_above": 1024  
},  
"timezone": {  
"type": "keyword",  
"ignore\_above": 1024  
},  
"version": {  
"type": "keyword",  
"ignore\_above": 1024  
}  
}  
},  
"tags": {  
"type": "keyword",  
"ignore\_above": 1024  
},  
"error": {  
"properties": {  
"message": {  
"type": "text",  
"norms": false  
},  
"code": {  
"type": "long"  
},  
"type": {  
"type": "keyword",  
"ignore\_above": 1024  
}  
}  
},  
"source": {  
"type": "keyword",  
"ignore\_above": 1024  
},  
"prospector": {  
"properties": {  
"type": {  
"type": "keyword",  
"ignore\_above": 1024  
}  
}  
},  
"read\_timestamp": {  
"type": "keyword",  
"ignore\_above": 1024  
}  
},  
"\_meta": {  
"version": "6.1.1"  
},  
"date\_detection": false  
}  
},  
"aliases": {}  
}  
}

---

<div class="post-metadata">

**Author:** ![Evesy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evesy/32/29520_2.png) [@Evesy](https://discuss.elastic.co/u/Evesy)\
**Post date:** [April 4, 2018, 6:10pm UTC](https://discuss.elastic.co/t/how-are-strings-mapped/126787/4 "2018-04-04T18:10:50Z")

</div>

I've had a quick glance -- Anything in the `properties` block is explicitly mapped, i.e. `offset` will always by type `long`.

The config in the `dynamic_templates` array is more of interest. You have two dynamic mappings, both of which are setting (Unless explicitly mapped elsewhere) anything that Elasticsearch determines to be a string (Due to this bit: `match_mapping_type": "string"`) as a `keyword`.

The difference is the first object is only matching Elasticsearch fields that begin `fields.` (Due to: `"path_match": "fields."`). If the field begins with that, it's mapped as a keyword. If not, it'll be caught by the second object that will also map as a keyword but with `"ignore_above": 1024` (i.e. if the field has more than this many characters don't index it.).

I'm not too familiar with `path_match`, I'd expect to see a wildcard after the period. Either way though, all string fields using this template will be mapped as keywords, rather than both text & keyword.

What's the behaviour you're after?

Cheers,  
Mike

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2018, 6:10pm UTC](https://discuss.elastic.co/t/how-are-strings-mapped/126787/5 "2018-05-02T18:10:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
