# I'm confused: Keyword Mapping and Multi-fields

**URL:** <https://discuss.elastic.co/t/im-confused-keyword-mapping-and-multi-fields/278237>\
**Category:** Elasticsearch\
**Created:** [July 9, 2021, 5:24am UTC](https://discuss.elastic.co/t/im-confused-keyword-mapping-and-multi-fields/278237 "2021-07-09T05:24:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tomx1](https://avatars.discourse-cdn.com/v4/letter/t/779978/32.png) [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Post date:** [July 9, 2021, 5:24am UTC](https://discuss.elastic.co/t/im-confused-keyword-mapping-and-multi-fields/278237/1 "2021-07-09T05:24:50Z")

</div>

I'm trying to switch our logging data to ECS. So I've adapted our logstash config to use some new field names and created a static mapping in the destination index. But the data is not indexed as keyword as I would expect,... in this example I'll show you the 'url.full' field ([URL Fields | Elastic Common Schema (ECS) Reference [8.11] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-url.html)).

My mapping for that field looks like that:

Request:

> GET logstash-operations-2021.07.09/\_mapping/field/url.full

Response:

```auto
{
  "logstash-operations-2021.07.09" : {
    "mappings" : {
      "url.full" : {
        "full_name" : "url.full",
        "mapping" : {
          "full" : {
            "type" : "keyword",
            "fields" : {
              "text" : {
                "type" : "text"
              }
            }
          }
        }
      }
    }
  }
}

```

So I think thats consistent with what the ECS recommends:  
url.full \> Keyword  
url.full.text \> Text (as Multi Field)

But due some reason, data that is stored into the url.full field is not analyzed as Keyword:

Request:

> GET logstash-operations-2021.07.09/\_analyze  
> {  
> "field": "url.full",  
> "text": "[https://example.com/api/v1/suggest?term=monitor\_qrsew](https://example.com/api/v1/suggest?term=monitor_qrsew)"  
> }  
> Response:

```auto
{
  "tokens" : [
    {
      "token" : "https://example.com/api/v1/suggest?term=monitor_qrsew",
      "start_offset" : 0,
      "end_offset" : 53,
      "type" : "word",
      "position" : 0
    }
  ]
}

```

If I do the same request with target 'url.full.text' I see that the data is parsed as a keyword,... so exactly the opposite of what I would expect. As the data in 'url.full' is stored as text and the data in 'url.full.text' is stored as keyword.

```auto
{
  "tokens" : [
    {
      "token" : "https",
      "start_offset" : 0,
      "end_offset" : 5,
      "type" : "<ALPHANUM>",
      "position" : 0
    },
    {
      "token" : "example.com",
      "start_offset" : 8,
      "end_offset" : 19,
      "type" : "<ALPHANUM>",
      "position" : 1
    },
    {
      "token" : "api",
      "start_offset" : 20,
      "end_offset" : 23,
      "type" : "<ALPHANUM>",
      "position" : 2
    },
    {
      "token" : "v1",
      "start_offset" : 24,
      "end_offset" : 26,
      "type" : "<ALPHANUM>",
      "position" : 3
    },
    {
      "token" : "suggest",
      "start_offset" : 27,
      "end_offset" : 34,
      "type" : "<ALPHANUM>",
      "position" : 4
    },
    {
      "token" : "term",
      "start_offset" : 35,
      "end_offset" : 39,
      "type" : "<ALPHANUM>",
      "position" : 5
    },
    {
      "token" : "monitor_qrsew",
      "start_offset" : 40,
      "end_offset" : 53,
      "type" : "<ALPHANUM>",
      "position" : 6
    }
  ]
}

```

What am I missing here?

PS: Thats how the mapping config looks like in Kibana:  
 ![2021-07-09_072237](https://us1.discourse-cdn.com/elastic/original/3X/a/d/ada2715f58acc8f2d87f6597663eca818224223f.jpeg)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 9, 2021, 6:22am UTC](https://discuss.elastic.co/t/im-confused-keyword-mapping-and-multi-fields/278237/2 "2021-07-09T06:22:59Z")

</div>

> [@tomx1](#):
>
> But due some reason, data that is stored into the url.full field is not analyzed as Keyword:

It is analyzed as a keyword data type. Which means no analysis happening on that field.

> [@tomx1](#):
>
> If I do the same request with target 'url.full.text' I see that the data is parsed as a keyword,..

No. It's analyzed as a text. Meaning that the analysis process is happening on that field.

So everything is good here.

---

<div class="post-metadata">

**Author:** ![tomx1](https://avatars.discourse-cdn.com/v4/letter/t/779978/32.png) [@tomx1](https://discuss.elastic.co/u/tomx1)\
**Post date:** [July 9, 2021, 6:56am UTC](https://discuss.elastic.co/t/im-confused-keyword-mapping-and-multi-fields/278237/3 "2021-07-09T06:56:16Z")

</div>

Thanks David, seems like I have confused here some basic things...

May I ask you a second question: The "url.\*" field does not show up in Kibana search results (under discover). I see the field if I click on the JSON tab (for a single document) and I can do a search for it (like: url.full:\*[example.com](http://example.com)\*). But due some reason I can't see it here:

 ![2021-07-09_085430](https://us1.discourse-cdn.com/elastic/original/3X/3/4/34fedca64e6b1e7309c569793679f38ad79f6719.jpeg)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 9, 2021, 7:11am UTC](https://discuss.elastic.co/t/im-confused-keyword-mapping-and-multi-fields/278237/4 "2021-07-09T07:11:03Z")

</div>

I don't know. May be you need to refresh the mapping in Kibana? Under Kibana management, update the index pattern?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2021, 7:11am UTC](https://discuss.elastic.co/t/im-confused-keyword-mapping-and-multi-fields/278237/5 "2021-08-06T07:11:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
