# How can I make the string field not\_analyzed?

**URL:** <https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230>\
**Category:** Elasticsearch\
**Created:** [November 21, 2015, 7:31pm UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230 "2015-11-21T19:31:55Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [November 21, 2015, 7:31pm UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/1 "2015-11-21T19:31:55Z")

</div>

I am using logstash 1.5.1 and elasticsearch 1.7.3.0. I used logstash elasticsearch output to index the records residing in a bunch of csv files, and used my own mapping document where I set strings to be not\_analyzed, also set logstash default template match"\*" as string not\_analyzed. In kibana I also verified that string fields are not\_analyzed, however, when I use kibana bar chart to create bucket on string field, the string is broken down into tokens.

As you can see for example the "path" field, in kibana mapping details, it is not\_analyzed as what I set  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/b7a3bd4860036e9999b2c3281a7ff579d0e92c66.png)

Also, the value of "path" field is as follows, it is the path of csv files  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/dabc67484798893644b318800bd6107d1bdd5aed.png)

Then when I use bar chart to do bucket based on "path" field you can see the legend, the "path" field values are broken down into tokens. Instead of "/.../testcsvimport/record220k-100\_3.csv", it is broken down to "testcsvimport" "record220k" "100" "csv"...

 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/0ea05726032d993cb4156dead540289700b8ee79.png)

I don't want it to be analyzed, I want to keep the whole path field as one string, how can I do it?

I have attached logstash .conf file that i used to export to elasticsearch index, please help me.

input {

file {  
path =\> "/home/myfolder/testcsvimport/record\*.csv"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"   
}

}

filter {

csv {  
columns =\> ["some\_column\_names"] # the "path" field is added by csv filter  
}

```
grok {
	match => { "record_IP" => "%{IP:clientip}" }
}
  
geoip {
    source => "clientip"
}

mutate
{
  remove_field => ["message", "host"]
}

```

}

output {  
elasticsearch {  
host =\> "dev-elkstack:9200"  
protocol =\> "http"  
index =\> "mt\_joined\_record\_index"  
template\_name =\> "mt\_joined\_record\_type"  
manage\_template =\> false  
}

}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 21, 2015, 11:07pm UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/2 "2015-11-21T23:07:08Z")

</div>

Can you paste/link to your mapping?

---

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [November 21, 2015, 11:10pm UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/3 "2015-11-21T23:10:54Z")

</div>

PUT /mt\_joined\_record\_index  
{  
"mappings": {  
"mt\_joined\_record\_type": {  
"\_all": {  
"enabled": false,  
"omit\_norms": true  
},  
"properties": {  
"@timestamp": {  
"type": "date",  
"format": "dateOptionalTime"  
},  
"@version": {  
"type": "string",  
"index": "not\_analyzed"  
},  
"path": {  
"type": "string",  
"index": "not\_analyzed"  
},  
"record\_time": {  
"type": "date",  
"format": "yyyy-mm-dd HH:mm:ss || yyyy-mm-dd hh:mm:ss Z"  
},  
"tags": {  
"type": "string",  
"index": "not\_analyzed"  
}  
}  
}  
}

}

---

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [November 22, 2015, 12:38am UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/4 "2015-11-22T00:38:43Z")

</div>

In kibana it already showed that the "path" field analyzed as "false" as the picture I posted here  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/8/830e8f3a11d970c90ea028d038b8f69aa5a1f42c.png)  
How come in bar chart the field is still analyzed? It is not consisitent.

---

<div class="post-metadata">

**Author:** ![tinle](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@tinle](https://discuss.elastic.co/u/tinle)\
**Post date:** [November 22, 2015, 1:36am UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/5 "2015-11-22T01:36:00Z")

</div>

Did you reload your field list after making the change? It could be cached.

Tin

---

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [November 22, 2015, 1:39am UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/6 "2015-11-22T01:39:04Z")

</div>

Every time when I did new experiment, I changed index name and mapping name to new names, I believe that would be clean experiment, will not get affected by the previous experiments. I also know this mapping I created is effective, because the date type I defined in the mapping is correctly recognized by kibana.

---

<div class="post-metadata">

**Author:** ![tinle](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@tinle](https://discuss.elastic.co/u/tinle)\
**Post date:** [November 22, 2015, 2:04am UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/7 "2015-11-22T02:04:56Z")

</div>

Sure. Just for grins, would you mind trying the reload fields anyway?

Let's eliminate that.

---

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [November 22, 2015, 2:11am UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/8 "2015-11-22T02:11:05Z")

</div>

> [@tinle](#):
>
> reload your field list

Yes I did that, it still doesn't work.

---

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [November 22, 2015, 2:13am UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/9 "2015-11-22T02:13:34Z")

</div>

Can you give me a example or a link, how other people succeeded in making string fields not\_analyzed? Thank you very much!

---

<div class="post-metadata">

**Author:** ![tinle](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@tinle](https://discuss.elastic.co/u/tinle)\
**Post date:** [November 22, 2015, 2:55am UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/10 "2015-11-22T02:55:03Z")

</div>

The index mapping you shown above seem to come from a PUT. Could you please post a mapping for the current index you are having problem with? from a GET?

Something like from similar command.

`curl localhost:9200/logstash-YYYY.MM.DD/_mapping?pretty`

---

<div class="post-metadata">

**Author:** ![Marcin\_Kubica](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcin_kubica/32/5614_2.png) [@Marcin\_Kubica](https://discuss.elastic.co/u/Marcin_Kubica)\
**Post date:** [November 22, 2015, 2:55am UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/11 "2015-11-22T02:55:53Z")

</div>

Sorry can't tell what's wrong in your case @sharon.c however I'm using non analysed fields alot and never had this issue.

Deploy your ELK from scratch and try again?

---

<div class="post-metadata">

**Author:** ![sharon.c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharon.c/32/16076_2.png) [@sharon.c](https://discuss.elastic.co/u/sharon.c)\
**Post date:** [November 23, 2015, 12:07am UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/12 "2015-11-23T00:07:09Z")

</div>

I think I solved it by using raw field, because I need to do aggregation on that field, I think it is better to just use raw field, instead using not\_analyzed.

---

<div class="post-metadata">

**Author:** ![chrisribe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisribe/32/22398_2.png) [@chrisribe](https://discuss.elastic.co/u/chrisribe)\
**Post date:** [September 30, 2016, 3:12pm UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/13 "2016-09-30T15:12:08Z")

</div>

Could you post your solution ?  
Having the same issue...  
Thanks

---

<div class="post-metadata">

**Author:** ![chrisribe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrisribe/32/22398_2.png) [@chrisribe](https://discuss.elastic.co/u/chrisribe)\
**Post date:** [September 30, 2016, 6:09pm UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/14 "2016-09-30T18:09:56Z")

</div>

Found it, here is my mapping solution for mysql-\* mappings.  
Creates raw fields if the fields is a string less than 256 chars.

```
{
  "template" : "mysql-*",
  "settings" : {
    "index.refresh_interval" : "5s",
    "analysis" : {
      "analyzer" : {
        "default" : {
          "type" : "standard",
          "stopwords" : "_none_"
        }
      }
    }
  },
  "mappings" : {
    "_default_" : {
       "_all" : {"enabled" : true},
       "dynamic_templates" : [ {
         "string_fields" : {
           "match" : "*",
           "match_mapping_type" : "string",
           "mapping" : {
             "type" : "multi_field",
               "fields" : {
                 "{name}" : {"type": "string", "index" : "analyzed", "omit_norms" : true, "index_options" : "docs"},
                 "raw" : {"type": "string", "index" : "not_analyzed", "ignore_above" : 256}
               }
           }
         }
       } ],
       "properties" : {
         "@version": { "type": "string", "index": "not_analyzed" }
       }
    }
  }
}

```

Reference (see : logstash index template)

> **[Logstash 1.3.1 Released!
	  	 | Elastic](https://www.elastic.co/blog/logstash-1-3-1-released)**
>
> Hello friends! We have released logstash 1.3.1 with lots of new fixes and features. You can view the full changelog, but I’d like to highlight two of the new features, both of which were impleme...

---

<div class="post-metadata">

**Author:** ![Sami\_Bensmida](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sami_bensmida/32/13836_2.png) [@Sami\_Bensmida](https://discuss.elastic.co/u/Sami_Bensmida)\
**Post date:** [December 13, 2016, 2:31pm UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/15 "2016-12-13T14:31:57Z")

</div>

Hello,

I'm using talend telasticsearch component for the ETL, converting CSV Data to Json in order to load it in elasticsearch, witch that's mean the mapping is generated automatically in background and I cant see the code.

Default mode : All the String fields are **_ANALYZED_** I want o change it to **NOT ANALYZED**.

Ideas please ?

Thank's in advance,  
Sami BENSMIDA

---

<div class="post-metadata">

**Author:** ![Black-Star](https://avatars.discourse-cdn.com/v4/letter/b/a4c791/32.png) [@Black-Star](https://discuss.elastic.co/u/Black-Star)\
**Post date:** [January 3, 2017, 6:46am UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/16 "2017-01-03T06:46:29Z")

</div>

Here is [Stackoverflow](http://stackoverflow.com/a/36449107/1585003) link for some similar question

```
curl -XPUT localhost:9200/_template/global -d '{
  "template": "*",
  "mappings": {
    "_default_": {
      "dynamic_templates": [
        {
          "strings": {
            "match_mapping_type": "string",
            "mapping": {
              "type": "string",
              "index": "not_analyzed"
            }
          }
        }
      ]
    }
  }
}'
```

---

<div class="post-metadata">

**Author:** ![venkat\_venkat](https://avatars.discourse-cdn.com/v4/letter/v/f17d59/32.png) [@venkat\_venkat](https://discuss.elastic.co/u/venkat_venkat)\
**Post date:** [March 23, 2017, 5:17pm UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/17 "2017-03-23T17:17:33Z")

</div>

Hi ,

I am facing the same issue, I am trying to remove the hostname string field analyzed to non-analyzed, every time I am getting analyzed only, please help me out how to remove analyzed for the hostname.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/3/5/35891d669e73f6fbdf0a87df7212130aadc6ca07.png)

Please find the below template, I am using.

curl -XPUT '[http://localhost:9200/\_template/elasticsearchstats](http://localhost:9200/_template/elasticsearchstats)' -d '{  
"template": "elasticsearchstats",  
"order": 10,  
"settings": {  
"index.refresh\_interval": "5s"  
},  
"mappings": {  
"_default_": {  
"\_all": {  
"enabled": true,  
"omit\_norms": true  
},  
"dynamic\_templates": [  
{  
"string\_fields": {  
"match": "_",  
"match\_mapping\_type": "string",  
"mapping": {  
"type": "keyword"  
}  
}  
},  
{  
"float\_fields": {  
"match": "_",  
"match\_mapping\_type": "float",  
"mapping": {  
"type": "float",  
"doc\_values": true  
}  
}  
},  
{  
"double\_fields": {  
"match": "_",  
"match\_mapping\_type": "double",  
"mapping": {  
"type": "double",  
"doc\_values": true  
}  
}  
},  
{  
"byte\_fields": {  
"match": "_",  
"match\_mapping\_type": "byte",  
"mapping": {  
"type": "byte",  
"doc\_values": true  
}  
}  
},  
{  
"short\_fields": {  
"match": "_",  
"match\_mapping\_type": "short",  
"mapping": {  
"type": "short",  
"doc\_values": true  
}  
}  
},  
{  
"integer\_fields": {  
"match": "_",  
"match\_mapping\_type": "integer",  
"mapping": {  
"type": "integer",  
"doc\_values": true  
}  
}  
},  
{  
"long\_fields": {  
"match": "_",  
"match\_mapping\_type": "long",  
"mapping": {  
"type": "long",  
"doc\_values": true  
}  
}  
},  
{  
"date\_fields": {  
"match": "_",  
"match\_mapping\_type": "date",  
"mapping": {  
"type": "date",  
"doc\_values": true  
}  
}  
},  
{  
"geo\_point\_fields": {  
"match": "\*",  
"match\_mapping\_type": "geo\_point",  
"mapping": {  
"type": "geo\_point",  
"doc\_values": true  
}  
}  
}  
],  
"properties": {  
"@timestamp": {  
"type": "date",  
"doc\_values": true  
},  
"@version": {  
"type": "string",  
"index": "not\_analyzed",  
"doc\_values": true  
},  
"clusterstatus" : {  
"type" : "long"  
},  
"cpupercent" : {  
"type" : "long"  
},  
"fielddataestimated" : {  
"type" : "long"  
},  
"fielddatalimit" : {  
"type" : "long"  
},  
"freedisk" : {  
"type" : "long"  
},  
"currentstatus" : {  
"type" : "string",  
"index" : "not\_analyzed"  
},  
"hostname" : {  
"type": "keyword",  
"index" : "no"  
},  
"testname" : {  
"type": "keyword"  
},  
"freemem" : {  
"type" : "long"  
},  
"heapold" : {  
"type" : "long"  
},  
"heapsurvior" : {  
"type" : "long"  
},  
"heapused" : {  
"type" : "long"  
},  
"heapyoung" : {  
"type" : "long"  
},  
"loadaverage" : {  
"type" : "long"  
},  
"hostname" : {  
"type" : "string"  
},  
"openfiles" : {  
"type" : "float"  
},  
"threadcount" : {  
"type" : "float"  
},  
"type" : {  
"type" : "string"  
},  
"geoip": {  
"type": "object",  
"dynamic": true,  
"properties": {  
"ip": {  
"type": "ip",  
"doc\_values": true  
},  
"location": {  
"type": "geo\_point",  
"doc\_values": true  
},  
"latitude": {  
"type": "float",  
"doc\_values": true  
},  
"longitude": {  
"type": "float",  
"doc\_values": true  
}  
}  
}  
}  
}  
}  
}'

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:01pm UTC](https://discuss.elastic.co/t/how-can-i-make-the-string-field-not-analyzed/35230/18 "2017-07-05T22:01:58Z")

</div>


