# How to create message.raw field to be analyzed

**URL:** <https://discuss.elastic.co/t/how-to-create-message-raw-field-to-be-analyzed/28213>\
**Category:** Elasticsearch\
**Created:** [August 28, 2015, 2:39am UTC](https://discuss.elastic.co/t/how-to-create-message-raw-field-to-be-analyzed/28213 "2015-08-28T02:39:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jason\_Zheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jason_zheng/32/4041_2.png) [@Jason\_Zheng](https://discuss.elastic.co/u/Jason_Zheng)\
**Post date:** [August 28, 2015, 2:39am UTC](https://discuss.elastic.co/t/how-to-create-message-raw-field-to-be-analyzed/28213/1 "2015-08-28T02:39:37Z")

</div>

Hi All,

I create two index pattern in elasticsearch, one of the index patterns has message.raw field (logstash-_, system default template?), but cannot found on the other one (miki-_, created by myself),

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/128ffa649670c0a02772e22c1c8a889983ba1840.png) ![](https://us1.discourse-cdn.com/elastic/original/2X/3/312f0427abcaee3786ee985eb17099587e955668.png)

Jason

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 28, 2015, 2:54am UTC](https://discuss.elastic.co/t/how-to-create-message-raw-field-to-be-analyzed/28213/2 "2015-08-28T02:54:14Z")

</div>

You need to create a mapping template that handles that for you, just like how the Logstash one does.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:53pm UTC](https://discuss.elastic.co/t/how-to-create-message-raw-field-to-be-analyzed/28213/3 "2017-07-05T23:53:22Z")

</div>


