# Logstash conf file with not\_analyzed field

**URL:** https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902
**Category:** Logstash
**Created:** [June 6, 2016, 6:29am UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902 "2016-06-06T06:29:54Z")
**Posts on this page:** 13
**Page:** 1

<div class="post-metadata">

### Author: ![chenbe2204](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@chenbe2204](https://discuss.elastic.co/u/chenbe2204)
#### Post date: [June 6, 2016, 6:29am UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/1 "2016-06-06T06:29:55Z")

</div>

Hi ,

I want to load my Json file to the Elasticsearch and add i need that one of the fields will be not\_analyzed  
This is my conf file:  
input {  
file{  
path =\> ["/root/scripts/vdm-server\_10-4\_parasoft\_103.json"]  
type =\> "json"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
}  
}

filter{  
json {  
source =\> "message"  
}  
}

filter{  
date {  
match =\> ["create\_time", "MM/dd/yyyy"]  
target =\> "@timestamp"  
}  
}

output {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {  
hosts =\> localhost  
index =\> index\_tmp1  
}  
}

example for a line from the json file:  
{"project":"server" ,"branch":"10" ,"type":"Flow" ,"build\_number":103 ,"severity":"Severity 1 = Highest" ,"line":804 ,"tool":"c++test" ,"pkg":"" ,"msg":"prior to initialization" ,"locfile":"/build\_scripts/external/minizip/src333/zip.c" ,"rule":"BD-1" ,"auth":"hudson" ,"create\_time":"06/05/2016" }

The field I need as not analyzed is "severity".

Thanks 🙂  
Chen

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [June 6, 2016, 7:00am UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/2 "2016-06-06T07:00:41Z")

</div>

You need to do that in ES via a mapping or a template, see [https://www.elastic.co/guide/en/elasticsearch/guide/current/mapping-analysis.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/mapping-analysis.html)

---

<div class="post-metadata">

### Author: ![chenbe2204](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@chenbe2204](https://discuss.elastic.co/u/chenbe2204)
#### Post date: [June 6, 2016, 7:47am UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/3 "2016-06-06T07:47:34Z")

</div>

Is there any way to define not\_analyzed field in the conf file of the Logstash ?

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [June 6, 2016, 7:48am UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/4 "2016-06-06T07:48:44Z")

</div>

No, it is an ES concept, not an LS one.

---

<div class="post-metadata">

### Author: ![chenbe2204](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@chenbe2204](https://discuss.elastic.co/u/chenbe2204)
#### Post date: [June 6, 2016, 7:54am UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/5 "2016-06-06T07:54:57Z")

</div>

So if i want to split a Chart in the Kibana by this field , how can I do it ?

---

<div class="post-metadata">

### Author: ![bryan\_stuhlsatz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryan_stuhlsatz/32/49123_2.png) [@bryan\_stuhlsatz](https://discuss.elastic.co/u/bryan_stuhlsatz)
#### Post date: [June 6, 2016, 10:45am UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/6 "2016-06-06T10:45:17Z")

</div>

This is Logstash forum. You should start a thread in Kibana.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 8, 2016, 5:38am UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/7 "2016-06-08T05:38:05Z")

</div>

> So if i want to split a Chart in the Kibana by this field , how can I do it ?

If you don't want the field to be analyzed and split into tokens, modify the indexes' mappings by changing the index template.

---

<div class="post-metadata">

### Author: ![chenbe2204](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@chenbe2204](https://discuss.elastic.co/u/chenbe2204)
#### Post date: [July 4, 2016, 6:52am UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/8 "2016-07-04T06:52:02Z")

</div>

Thanks 🙂

---

<div class="post-metadata">

### Author: ![hongyuan1306](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hongyuan1306/32/34868_2.png) [@hongyuan1306](https://discuss.elastic.co/u/hongyuan1306)
#### Post date: [July 4, 2016, 7:47am UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/9 "2016-07-04T07:47:10Z")

</div>

Can we not configure the template directly from logstash config file as indicated by the documentation like:

```
elasticsearch {
  hosts => localhost
  index => index_tmp1
  template => "/path/to/mytemplate"
  template_overwrite => true
}

```

Since the log transformation is control from the logstash config, it makes sense to place the mapping definition also on the logstash side.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [July 4, 2016, 7:50am UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/10 "2016-07-04T07:50:13Z")

</div>

> Can we not configure the template directly from logstash config file as indicated by the documentation

Sure you can.

---

<div class="post-metadata">

### Author: ![antonin42](https://avatars.discourse-cdn.com/v4/letter/a/c68b51/32.png) [@antonin42](https://discuss.elastic.co/u/antonin42)
#### Post date: [August 12, 2016, 1:31pm UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/11 "2016-08-12T13:31:32Z")

</div>

Hi @magnusbaeck , I did not find this in Logstash Online Doc. How can you configure the template directly from logstash config file ?  
Thanks in advance, good day.  
Antonin

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 12, 2016, 2:01pm UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/12 "2016-08-12T14:01:20Z")

</div>

Look at the template-related options listed in the documentation of the elasticsearch output plugin.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:43am UTC](https://discuss.elastic.co/t/logstash-conf-file-with-not-analyzed-field/51902/13 "2017-07-06T04:43:40Z")

</div>


