# How to disable querying ALL fields by default

**URL:** https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249
**Category:** Kibana
**Created:** [November 29, 2023, 3:19pm UTC](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249 "2023-11-29T15:19:01Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![Matt\_McGovern](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_mcgovern/32/90131_2.png) [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)
#### Post date: [November 29, 2023, 3:19pm UTC](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249/1 "2023-11-29T15:19:01Z")

</div>

We have some users that are killing our performance because they're not putting a field in their Discover searches...rather they are just putting a single value only so elasticsearch has to search through everything.

There used to be an \_all field but that was deprecated in 6.0. We're running 8.6. How do I restrict users from doing this, or at least force their queries to hit a certain field instead of every field in the index?

---

<div class="post-metadata">

### Author: ![Matt\_McGovern](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_mcgovern/32/90131_2.png) [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)
#### Post date: [November 29, 2023, 3:48pm UTC](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249/2 "2023-11-29T15:48:44Z")

</div>

I'm looking into the default\_field setting described here: [Add default field API | Kibana Guide [8.6] | Elastic](https://www.elastic.co/guide/en/kibana/8.6/upgrade-assistant-api-default-field.html) but it's not even recognizing the handler when I try it. I don't think the URI is correct.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [November 29, 2023, 3:49pm UTC](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249/3 "2023-11-29T15:49:11Z")

</div>

What vesion are you on?

There is a setting you can put in the template

```auto
  "settings" : {
      "index" : {
        "query" : {
          "default_field" : ["message"]

```

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [November 29, 2023, 3:51pm UTC](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249/4 "2023-11-29T15:51:27Z")

</div>

> [@Matt\_McGovern](#):
>
> I'm looking into the default\_field setting described here: [Add default field API | Kibana Guide [8.6] | Elastic ](https://www.elastic.co/guide/en/kibana/8.6/upgrade-assistant-api-default-field.html) but it's not even recognizing the handler when I try it. I don't think the URI is correct.

That is the upgrade assistant... are you trying to use the upgrade assistant?

Look [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules.html)

> `index.query.default_field`
> 
> (string or array of strings) Wildcard (`*`) patterns matching one or more fields. The following query types search these matching fields by default:
> 
> - [More like this](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-mlt-query.html)
> - [Multi-match](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-multi-match-query.html)
> - [Query string](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html)
> - [Simple query string](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-simple-query-string-query.html)

---

<div class="post-metadata">

### Author: ![Matt\_McGovern](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_mcgovern/32/90131_2.png) [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)
#### Post date: [November 29, 2023, 4:26pm UTC](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249/5 "2023-11-29T16:26:01Z")

</div>

8.6.1

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [November 29, 2023, 4:33pm UTC](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249/6 "2023-11-29T16:33:42Z")

</div>

What I showed above should work, I use it all the time.

It is even dynamic which means you can change it on existing indices!

---

<div class="post-metadata">

### Author: ![Matt\_McGovern](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_mcgovern/32/90131_2.png) [@Matt\_McGovern](https://discuss.elastic.co/u/Matt_McGovern)
#### Post date: [November 29, 2023, 7:47pm UTC](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249/7 "2023-11-29T19:47:58Z")

</div>

This worked perfectly and was exactly what we needed. Thanks!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 27, 2023, 7:48pm UTC](https://discuss.elastic.co/t/how-to-disable-querying-all-fields-by-default/348249/8 "2023-12-27T19:48:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
