# Logstash how to send string as not\_analyzed into elasticsearch

**URL:** https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922
**Category:** Logstash
**Created:** [September 9, 2015, 12:02pm UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922 "2015-09-09T12:02:02Z")
**Posts on this page:** 12
**Page:** 1

<div class="post-metadata">

### Author: ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)
#### Post date: [September 9, 2015, 12:02pm UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922/1 "2015-09-09T12:02:02Z")

</div>

Hi ,

I am usng logstash 1.5.4 , while indexing the data through logstash, all the string data type indexing as analyzed , but my requirement is it should be not\_analyzed ..  
So I had changed the file elastic-template.json

> "dynamic\_templates" : [ {  
> "message\_field" : {  
> "match" : "message",  
> "match\_mapping\_type" : "string",  
> "mapping" : {  
> "type" : "string", "index" : "not\_analyzed", "omit\_norms" : true

but still the string type is indexing as anayzed , why ?  
how to overcome this ...

Thanks

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 9, 2015, 6:01pm UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922/2 "2015-09-09T18:01:56Z")

</div>

Assuming you made the change in the right place, it'll only take effect for newly created indexes. Are you taking that into account?

---

<div class="post-metadata">

### Author: ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)
#### Post date: [September 10, 2015, 5:39am UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922/3 "2015-09-10T05:39:11Z")

</div>

yes, after that I had changed the template file and again trying to index the doc , still showing analyzed in kibana

my elastic-template.json file is

```
    {
      "template" : "logstash-*",
      "settings" : {
        "index.refresh_interval" : "5s"
      },
      "mappings" : {
        "_default_" : {
           "_all" : {"enabled" : true, "omit_norms" : true},
           "dynamic_templates" : [ {
             "message_field" : {
               "match" : "message",
               "match_mapping_type" : "string",
               "mapping" : {
                 "type" : "string", "index" : "not_analyzed", "omit_norms" : true
               }
             }
           }, {
             "string_fields" : {
               "match" : "*",
               "match_mapping_type" : "string",
               "mapping" : {
                 "type" : "string", "index" : "not_analyzed", "omit_norms" : true,
                   "fields" : {
                     "raw" : {"type": "string", "index" : "not_analyzed", "ignore_above" : true}
                   }
               }
             }
           } ],
           "properties" : {
             "@version": { "type": "string", "index": "not_analyzed" },
             "geoip" : {
               "type" : "object",
                 "dynamic": true,
                 "properties" : {
                   "location" : { "type" : "geo_point" }
                 }
             }
           }
        }
      }

}

```

and Logstash output is

```
elasticsearch
		{
			action => "index"
			host => "localhost"
			cluster => "navneet"		
			template => "D:/es_tools/logstash-1.5.4/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-1.0.7-java/lib/logstash/outputs/elasticsearch/elasticsearch-template.json"
			index => "ems"
		}
```

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 10, 2015, 5:58am UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922/4 "2015-09-10T05:58:43Z")

</div>

Your template is for indexes whose name matches the pattern logstash-\* but you're pushing data to an index named ems so it won't use your template.

---

<div class="post-metadata">

### Author: ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)
#### Post date: [September 10, 2015, 6:00am UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922/5 "2015-09-10T06:00:18Z")

</div>

I have changed the template with "\*" , but still the same  
all the string fields are occurring as analyzed only , am I doing something wrong somewhere ?

---

<div class="post-metadata">

### Author: ![zappe](https://avatars.discourse-cdn.com/v4/letter/z/439d5e/32.png) [@zappe](https://discuss.elastic.co/u/zappe)
#### Post date: [November 20, 2015, 2:55pm UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922/6 "2015-11-20T14:55:04Z")

</div>

Any update on this?  
I have the same issue.

---

<div class="post-metadata">

### Author: ![zappe](https://avatars.discourse-cdn.com/v4/letter/z/439d5e/32.png) [@zappe](https://discuss.elastic.co/u/zappe)
#### Post date: [November 27, 2015, 11:22am UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922/7 "2015-11-27T11:22:21Z")

</div>

No one?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [November 27, 2015, 12:23pm UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922/8 "2015-11-27T12:23:47Z")

</div>

@zappe: To maximize your chances of getting help, start a new thread and post a complete recipe for reproducing your problem. You might be experiencing the same symptom as the original poster in this thread but the root cause could be something completely different.

---

<div class="post-metadata">

### Author: ![Navneet\_Mathpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/navneet_mathpal/32/3677_2.png) [@Navneet\_Mathpal](https://discuss.elastic.co/u/Navneet_Mathpal)
#### Post date: [December 29, 2015, 5:41am UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922/9 "2015-12-29T05:41:28Z")

</div>

@zappe

It was not working when referring the template from logstash so I had created the template in elastic only ..  
if your index name starts with elastic- ... you can create template (dynamic template ) for elastic-\* (this works the same as referring the template from logstash ).

---

<div class="post-metadata">

### Author: ![srikanth.guduru](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@srikanth.guduru](https://discuss.elastic.co/u/srikanth.guduru)
#### Post date: [January 27, 2016, 7:00pm UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922/10 "2016-01-27T19:00:09Z")

</div>

Hi Navneet. I just wanted to know that you created template in elasticsearch using curl command etc, then did you use manage\_template filed in logstash configuration for elasticsearch output?

---

<div class="post-metadata">

### Author: ![karthikeyan95](https://avatars.discourse-cdn.com/v4/letter/k/f14d63/32.png) [@karthikeyan95](https://discuss.elastic.co/u/karthikeyan95)
#### Post date: [September 6, 2016, 9:49am UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922/11 "2016-09-06T09:49:26Z")

</div>

As you say, if creating a dynamic template in Elasticsearch works, then why not referring in Logstash is not working?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:39am UTC](https://discuss.elastic.co/t/logstash-how-to-send-string-as-not-analyzed-into-elasticsearch/28922/12 "2017-07-06T04:39:44Z")

</div>


