# Keyword analyzer expected behaviour

**URL:** <https://discuss.elastic.co/t/keyword-analyzer-expected-behaviour/12673>\
**Category:** Elasticsearch\
**Created:** [July 5, 2013, 8:32am UTC](https://discuss.elastic.co/t/keyword-analyzer-expected-behaviour/12673 "2013-07-05T08:32:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ankit\_Jain](https://avatars.discourse-cdn.com/v4/letter/a/96bed5/32.png) [@Ankit\_Jain](https://discuss.elastic.co/u/Ankit_Jain)\
**Post date:** [July 5, 2013, 8:32am UTC](https://discuss.elastic.co/t/keyword-analyzer-expected-behaviour/12673/1 "2013-07-05T08:32:18Z")

</div>

Hi All,

I am analysing the field using keyword analyzer.

For example: Value of input record is -  
{{98.138.26.90},{auto\_remote@98.138.26.90}},{{192.168.50.73},{auto\_local@98.138.26.90}}

I am using below queries for fetching the record:

_Case 1:_ pass whole value : pass and getting result

"query\_string" : {  
"query" :  
"c52:"{{98.138.26.90},{auto\_remote@98.138.26.90}},{{192.168.50.73},{auto\_local@98.138.26.90}}"",  
"default\_operator" : "and"  
}  
}}

_Case 2:_ Fail, because I am getting records.

"query\_string" : {  
"query" : "c52:"{{98.138.26.90},{auto\_remote@98.138.26.90}}"",  
"default\_operator" : "and"  
}  
}}

\*Case3: \*fail, because i am getting records.

"query\_string" : {  
"query" : "c52:"\*[[\*98.138.26.90},{auto\_remote@98.138.26.90}}"",  
"default\_operator" : "and"  
}  
}}

I would like to use keyword analyzer instead of not\_analyzed to provide  
case-insensetive support.

Thanks,  
Ankit

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Ankit\_Jain](https://avatars.discourse-cdn.com/v4/letter/a/96bed5/32.png) [@Ankit\_Jain](https://discuss.elastic.co/u/Ankit_Jain)\
**Post date:** [July 5, 2013, 9:54am UTC](https://discuss.elastic.co/t/keyword-analyzer-expected-behaviour/12673/2 "2013-07-05T09:54:07Z")

</div>

Hi All,

Just like to add few things:

_Case1:_ If i am passing whole value of field in query string, then i am  
getting. So, this query is giving expected result.

_Case2:_ If i am passing sub part of value of field in query string, then i  
am also getting records. While the expected behaviour is no match.

Case3: If i am replacing "{" with "[", then also i am getting records.  
While expected behaviour is no match.

Thanks,  
Ankit

On Friday, 5 July 2013 14:02:18 UTC+5:30, Ankit Jain wrote:

> Hi All,
> 
> I am analysing the field using keyword analyzer.
> 
> For example: Value of input record is - {{98.138.26.90},{  
> [auto\_remote@98.138.26.90](mailto:auto_remote@98.138.26.90)}},{{192.168.50.73},{auto\_local@98.138.26.90}}
> 
> I am using below queries for fetching the record:
> 
> _Case 1:_ pass whole value : pass and getting result
> 
> "query\_string" : {  
> "query" : "c52:"{{98.138.26.90},{auto\_remote@98.138.26.90  
> }},{{192.168.50.73},{auto\_local@98.138.26.90}}"",  
> "default\_operator" : "and"  
> }  
> }}
> 
> _Case 2:_ Fail, because I am getting records.
> 
> "query\_string" : {  
> "query" : "c52:"{{98.138.26.90},{auto\_remote@98.138.26.90}}"",  
> "default\_operator" : "and"  
> }  
> }}
> 
> \*Case3: \*fail, because i am getting records.
> 
> "query\_string" : {  
> "query" : "c52:"\*[[\*98.138.26.90},{auto\_remote@98.138.26.90}}"",  
> "default\_operator" : "and"  
> }  
> }}
> 
> I would like to use keyword analyzer instead of not\_analyzed to provide  
> case-insensetive support.
> 
> Thanks,  
> Ankit

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![imdhmd](https://avatars.discourse-cdn.com/v4/letter/i/d07c76/32.png) [@imdhmd](https://discuss.elastic.co/u/imdhmd)\
**Post date:** [July 8, 2013, 2:51pm UTC](https://discuss.elastic.co/t/keyword-analyzer-expected-behaviour/12673/3 "2013-07-08T14:51:21Z")

</div>

Hey Ankit,

Can you mention your analyzer settings and/or index mapping?  
Did you mean to have c52 as the field name or is it _really_ part of the  
query?  
I did not understand the need to specify default operator as 'and'.

- if c52 is a field name, you need to use a term query  
([Elasticsearch Platform — Find real-time answers at scale | Elastic](http://www.elasticsearch.org/guide/reference/query-dsl/term-query/)), like  
this:  
{  
"term": {  
"c52": "{{98.138.26.90},{auto\_remote@98.138.26.90}}"  
}  
}

- if it is part of the query have quotes across the whole query string:  
{  
"query\_string": {  
"query" : ""c52:{{98.138.26.90},{auto\_remote@98.138.26.90}}"",  
"analyzer": "keyword"  
}  
}  
The reason we need to mention analyzer here is because in case of  
query\_string query, analyzer is also applied to query string, default being  
standard analyzer. Since you want it to be not analyzed, specify the  
analyzer explicitly as 'keyword'.

- Imdad

On Friday, July 5, 2013 2:02:18 PM UTC+5:30, Ankit Jain wrote:

> Hi All,
> 
> I am analysing the field using keyword analyzer.
> 
> For example: Value of input record is - {{98.138.26.90},{  
> [auto\_...@98.138.26.90](mailto:auto_...@98.138.26.90) \<javascript:\>}},{{192.168.50.73},{  
> [auto\_...@98.138.26.90](mailto:auto_...@98.138.26.90) \<javascript:\>}}
> 
> I am using below queries for fetching the record:
> 
> _Case 1:_ pass whole value : pass and getting result
> 
> "query\_string" : {  
> "query" : "c52:"{{98.138.26.90},{auto\_remote@98.138.26.90\<javascript:\>  
> }},{{192.168.50.73},{auto\_...@98.138.26.90 \<javascript:\>}}"",  
> "default\_operator" : "and"  
> }  
> }}
> 
> _Case 2:_ Fail, because I am getting records.
> 
> "query\_string" : {  
> "query" : "c52:"{{98.138.26.90},{auto\_remote@98.138.26.90\<javascript:\>  
> }}"",  
> "default\_operator" : "and"  
> }  
> }}
> 
> \*Case3: \*fail, because i am getting records.
> 
> "query\_string" : {  
> "query" : "c52:"\*[[\*98.138.26.90},{auto\_remote@98.138.26.90\<javascript:\>  
> }}"",  
> "default\_operator" : "and"  
> }  
> }}
> 
> I would like to use keyword analyzer instead of not\_analyzed to provide  
> case-insensetive support.
> 
> Thanks,  
> Ankit

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:27am UTC](https://discuss.elastic.co/t/keyword-analyzer-expected-behaviour/12673/4 "2017-07-06T02:27:36Z")

</div>


