# Logstash input twitter

**URL:** <https://discuss.elastic.co/t/logstash-input-twitter/2298>\
**Category:** Logstash\
**Created:** [June 10, 2015, 11:07am UTC](https://discuss.elastic.co/t/logstash-input-twitter/2298 "2015-06-10T11:07:34Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![abaykal](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@abaykal](https://discuss.elastic.co/u/abaykal)\
**Post date:** [June 10, 2015, 11:07am UTC](https://discuss.elastic.co/t/logstash-input-twitter/2298/1 "2015-06-10T11:07:34Z")

</div>

I am using logstash-input-twitter plugin. I dont want certain fields to be not\_analyzed. is this something I can define in the output tag? if so, can you provide an example?

Thanks

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 10, 2015, 5:03pm UTC](https://discuss.elastic.co/t/logstash-input-twitter/2298/2 "2015-06-10T17:03:30Z")

</div>

not\_analyzed is handled at the Elasticsearch level.

By default, the Elasticsearch mapping template included with Logstash (which applies to indices named logstash-YYYY.MM.dd) has a "multi-field" mapping. All string fields automatically get both an analyzed (the regular field name) and not\_analyzed (fieldname.raw) version of the field.

If you have a different index naming pattern, this template will not be applied.

---

<div class="post-metadata">

**Author:** ![abaykal](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@abaykal](https://discuss.elastic.co/u/abaykal)\
**Post date:** [June 10, 2015, 5:28pm UTC](https://discuss.elastic.co/t/logstash-input-twitter/2298/3 "2015-06-10T17:28:36Z")

</div>

I thought they removed the .raw field from 1.5

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 10, 2015, 5:43pm UTC](https://discuss.elastic.co/t/logstash-input-twitter/2298/4 "2015-06-10T17:43:58Z")

</div>

Only from the message field. All other string fields get the .raw treatment still.

---

<div class="post-metadata">

**Author:** ![abaykal](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@abaykal](https://discuss.elastic.co/u/abaykal)\
**Post date:** [June 11, 2015, 10:39pm UTC](https://discuss.elastic.co/t/logstash-input-twitter/2298/5 "2015-06-11T22:39:49Z")

</div>

how do I access the .raw field from the kibana to create graphs?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 12, 2015, 3:36am UTC](https://discuss.elastic.co/t/logstash-input-twitter/2298/6 "2015-06-12T03:36:15Z")

</div>

All string fields should have a .raw version, e.g. `fieldname` would also appear as `fieldname.raw`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:37am UTC](https://discuss.elastic.co/t/logstash-input-twitter/2298/7 "2017-07-06T05:37:37Z")

</div>


