# Issue in getting raw fields

**URL:** <https://discuss.elastic.co/t/issue-in-getting-raw-fields/43736>\
**Category:** Elasticsearch\
**Created:** [March 8, 2016, 8:23am UTC](https://discuss.elastic.co/t/issue-in-getting-raw-fields/43736 "2016-03-08T08:23:32Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![NiteshBarnwal](https://avatars.discourse-cdn.com/v4/letter/n/e495f1/32.png) [@NiteshBarnwal](https://discuss.elastic.co/u/NiteshBarnwal)\
**Post date:** [March 8, 2016, 8:23am UTC](https://discuss.elastic.co/t/issue-in-getting-raw-fields/43736/1 "2016-03-08T08:23:32Z")

</div>

I have created template as below.

> "dynamic\_templates": [  
> {  
> "disk\_space3": {  
> "match\_mapping\_type": "string",  
> "match": "\*",  
> "mapping": {  
> "type": "string",  
> "fields": {  
> "raw": {  
> "type": "string",  
> "index": "not\_analyzed",  
> "ignore\_above": 256  
> }  
> }  
> }  
> }  
> }  
> ]

And output is as below:

> output {  
> elasticsearch {  
> action =\> "index"  
> hosts =\> "localhost:9200"  
> index =\> "%{type}"  
> workers =\> 1  
> manage\_template =\> false  
> template =\> "/installdir/ELK/logstash-2.2.0/template/b\_analyzed.json"  
> template\_name =\> disk\_space3  
> }  
> stdout {  
> codec =\> json  
> }  
> }

But is is still analyzing the field. Can you help.

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [March 8, 2016, 9:55am UTC](https://discuss.elastic.co/t/issue-in-getting-raw-fields/43736/2 "2016-03-08T09:55:04Z")

</div>

To be clear, your fields will still be analyzed. However elasticsearch will create sub fields that are NOT analyzed and can be used for sorting or aggregations. For instance if one of your string fields is "foo", then you will have a "foo.raw" field that is not analyzed.

---

<div class="post-metadata">

**Author:** ![NiteshBarnwal](https://avatars.discourse-cdn.com/v4/letter/n/e495f1/32.png) [@NiteshBarnwal](https://discuss.elastic.co/u/NiteshBarnwal)\
**Post date:** [March 8, 2016, 10:17am UTC](https://discuss.elastic.co/t/issue-in-getting-raw-fields/43736/3 "2016-03-08T10:17:27Z")

</div>

> [@jpountz](#):
>
> However elasticsearch will create sub fields that are NOT analyzed and can be used for sorting or aggregations

This is what I am looking for. but I am not getting any field with `.raw` Am I missing anything here?

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [March 8, 2016, 10:24am UTC](https://discuss.elastic.co/t/issue-in-getting-raw-fields/43736/4 "2016-03-08T10:24:21Z")

</div>

Templates only apply to fields that are not defined in the mappings yet. Maybe this explains why you don't see any new fields being created?

---

<div class="post-metadata">

**Author:** ![NiteshBarnwal](https://avatars.discourse-cdn.com/v4/letter/n/e495f1/32.png) [@NiteshBarnwal](https://discuss.elastic.co/u/NiteshBarnwal)\
**Post date:** [March 8, 2016, 1:48pm UTC](https://discuss.elastic.co/t/issue-in-getting-raw-fields/43736/5 "2016-03-08T13:48:29Z")

</div>

```
I have all the new fields
if [type] == "disk_space" {
  grok {

    match => ["message", "%{DATESTAMP:date} %{NUMBER:used:int} %{GREEDYDATA:disk_part}"]

  }
}

```

even it is showing as analyzed. not sure where I am making mistake

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [March 8, 2016, 5:29pm UTC](https://discuss.elastic.co/t/issue-in-getting-raw-fields/43736/6 "2016-03-08T17:29:38Z")

</div>

Could you delete the index and try again? I suspect the source of the problem is that you are indexing into an existing index, so dynamic templates won't be applied.

---

<div class="post-metadata">

**Author:** ![NiteshBarnwal](https://avatars.discourse-cdn.com/v4/letter/n/e495f1/32.png) [@NiteshBarnwal](https://discuss.elastic.co/u/NiteshBarnwal)\
**Post date:** [March 8, 2016, 8:11pm UTC](https://discuss.elastic.co/t/issue-in-getting-raw-fields/43736/7 "2016-03-08T20:11:34Z")

</div>

are my template and output good? I tried to reindex and also with different index but no luck.  
Do I need to load the template in elasticsearch. Is it possible

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2016, 8:53pm UTC](https://discuss.elastic.co/t/issue-in-getting-raw-fields/43736/8 "2016-03-09T20:53:35Z")

</div>

> index =\> "%{type}"

Does your template apply to indexes with this name? Logstash's default template only applies to logstash-\* indexes, for example.

---

<div class="post-metadata">

**Author:** ![NiteshBarnwal](https://avatars.discourse-cdn.com/v4/letter/n/e495f1/32.png) [@NiteshBarnwal](https://discuss.elastic.co/u/NiteshBarnwal)\
**Post date:** [March 10, 2016, 8:27pm UTC](https://discuss.elastic.co/t/issue-in-getting-raw-fields/43736/9 "2016-03-10T20:27:09Z")

</div>

@magnusbaeck I was trying to create the same. Is it possible. I was making another template.

As of now my testing is blocked due to [Redundancy in logging "Flushing buffer at interval"](https://discuss.elastic.co/t/redundancy-in-logging-flushing-buffer-at-interval/43888)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:09pm UTC](https://discuss.elastic.co/t/issue-in-getting-raw-fields/43736/10 "2017-07-05T23:09:21Z")

</div>


