# Keyword field not aggregatable and not searchable

**URL:** <https://discuss.elastic.co/t/keyword-field-not-aggregatable-and-not-searchable/84631>\
**Category:** Elasticsearch\
**Created:** [May 4, 2017, 9:43pm UTC](https://discuss.elastic.co/t/keyword-field-not-aggregatable-and-not-searchable/84631 "2017-05-04T21:43:56Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajnfde](https://avatars.discourse-cdn.com/v4/letter/a/85e7bf/32.png) [@ajnfde](https://discuss.elastic.co/u/ajnfde)\
**Post date:** [May 4, 2017, 9:43pm UTC](https://discuss.elastic.co/t/keyword-field-not-aggregatable-and-not-searchable/84631/1 "2017-05-04T21:43:57Z")

</div>

Hi, I can't make visualisation table using a field I add from logstash.

In logstash conf file used, I read a log file containing XML data.

XML data example :

```
<root_doc>
    ...
	<Body>
		<Source>
			<tag>
				<Header Version="x" SentAt="date" To="to" />    				
                          ...
			</tag>
		</Source>
	</Body>
</root_doc>

```

I add fields into elasticsearch like this

```
		xpath => ["//Header/@Version" , "Version"]
		xpath => ["//Header/@SentAt" , "SentAt"]
		xpath => ["//Header/@To" , "To"]
		xpath => ["//Source/*" , "XMLOrigine"]

```

So, fields Version, SentAt, To, XMLOrigine are created, Version.keyword, SentAt.keyword, To.keyword and XMLOrigine.keyword too.  
They are all string.

But only the XMLOrigine.keyword field is not searcheable and aggregatable.

Can someone explain me why and how can I transform the XMLOrigine.keyword searchable and aggregatable.

---

<div class="post-metadata">

**Author:** ![mmichaels01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmichaels01/32/22513_2.png) [@mmichaels01](https://discuss.elastic.co/u/mmichaels01)\
**Post date:** [May 4, 2017, 9:56pm UTC](https://discuss.elastic.co/t/keyword-field-not-aggregatable-and-not-searchable/84631/2 "2017-05-04T21:56:59Z")

</div>

Can you post the {{index}}/{{type}}/\_mapping result from Elasticsearch here?

Keyword should be searchable, it just requires that a query token will have an exact match.

As to the issue surrounding not being able to aggregate, that seems weird. What kind of aggregation are you trying to use, term ? I currently use keyword fields for term aggregations in multiple places in Elastic 5.3, so seeing what your index's mapping looks like would help here as well.

---

<div class="post-metadata">

**Author:** ![ajnfde](https://avatars.discourse-cdn.com/v4/letter/a/85e7bf/32.png) [@ajnfde](https://discuss.elastic.co/u/ajnfde)\
**Post date:** [May 5, 2017, 11:42am UTC](https://discuss.elastic.co/t/keyword-field-not-aggregatable-and-not-searchable/84631/3 "2017-05-05T11:42:50Z")

</div>

Post {{index}}/{{type}}/\_mapping result

{  
"index": {  
"mappings": {  
"type": {  
"properties": {  
"@timestamp": {  
"type": "date"  
},  
"From": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"SentAt": {  
"type": "date"  
},  
"To": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Version": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"XMLOrigine": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
}  
}  
}  
}  
}  
}

I think I know why the XMLOrigine.keyword is not searchable and aggregatable.  
The XMLOrgine content is above 256 characters.

How can I disablle ou modify the ignore criteria from elasticsearch or logstash configuration?

---

<div class="post-metadata">

**Author:** ![mmichaels01](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmichaels01/32/22513_2.png) [@mmichaels01](https://discuss.elastic.co/u/mmichaels01)\
**Post date:** [May 5, 2017, 5:17pm UTC](https://discuss.elastic.co/t/keyword-field-not-aggregatable-and-not-searchable/84631/4 "2017-05-05T17:17:43Z")

</div>

[https://www.elastic.co/guide/en/elasticsearch/reference/current/ignore-above.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/ignore-above.html)

This should answer your question.

---

<div class="post-metadata">

**Author:** ![ajnfde](https://avatars.discourse-cdn.com/v4/letter/a/85e7bf/32.png) [@ajnfde](https://discuss.elastic.co/u/ajnfde)\
**Post date:** [May 8, 2017, 9:14pm UTC](https://discuss.elastic.co/t/keyword-field-not-aggregatable-and-not-searchable/84631/5 "2017-05-08T21:14:41Z")

</div>

Thanks mmichaels01.

Is it possible to do it in Logstash or elasticsearch yml files ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2017, 9:20pm UTC](https://discuss.elastic.co/t/keyword-field-not-aggregatable-and-not-searchable/84631/6 "2017-06-05T21:20:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
