# Logstash using not\_analyzed not working

**URL:** https://discuss.elastic.co/t/logstash-using-not-analyzed-not-working/24533
**Category:** Logstash
**Created:** [June 29, 2015, 9:26am UTC](https://discuss.elastic.co/t/logstash-using-not-analyzed-not-working/24533 "2015-06-29T09:26:56Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![JeroenvdV](https://avatars.discourse-cdn.com/v4/letter/j/a8b319/32.png) [@JeroenvdV](https://discuss.elastic.co/u/JeroenvdV)
#### Post date: [June 29, 2015, 9:26am UTC](https://discuss.elastic.co/t/logstash-using-not-analyzed-not-working/24533/1 "2015-06-29T09:26:56Z")

</div>

I am a total newby to the ELK stack and probably trying to setup a much to complicated config to start with... 🙂

I am running the whole stack on a windows 7 laptop. and I am importing a CSV which goes well but I cannot get the string field to be NOT analysed which is giving me broken text in the kibana visualisations.

Last try was with a template.

Both the template and the conf file are located in the c:\logstash-1.5.0\bin directory.

This is the conf file:

```
input {  
  file {
      path => "C:\Users\jeroen\Documents\temp\CSV\ElasticSearch_Input_vc.csv"
      type => "core2"
      start_position => "beginning" }
}

filter {  
csv {
    columns => ["snapshot_date_time","Country","Tower","Service","Division","USD Group","Ref Nr","Processtype","Importance","Priority","Severity","Status and Reason","Category","Is_Valid_Category","Summary","Open Date Time","Closed Date Time","Opened By","Last Modified","Resolve Completed Date Time","Hrs_Assigned_To_Completed","First Assign Date Time","Hrs_New_To_Assign","Customer Organization","Requested By","Assignee","Active Flag","In Out SLA Resolution 1"]

    separator => ";"
}
date
{ match => ["snapshot_date_time", "yyyy-MM-dd HH:mm:ss"] }
mutate {
convert => { "Hrs_Assigned_To_Completed" => "float" }
convert => { "Hrs_New_To_Assign" => "float" }
  }
}
output {  
elasticsearch {
    action => "index"
    host => "localhost"
    index => "qdb-%{+YYYY.MM.dd}"
    workers => 1
    template => "template.json"
}
#stdout {
   #codec => rubydebug
#}
}

```

And this is the template (which honestly I just copied from another topic and changed the "template name") And I am in doubt if the location on my laptop is correct or what to do with the 7th line as this is probably specific for the data used by the originator...

```
#template.json:
{
"template": "qdb-%{+YYYY.MM.dd}",
"settings" : {
    "number_of_shards" : 1,
    "number_of_replicas" : 0,
    "index" : {"query" : { "default_field" : "userid" } 
    }
},
"mappings": {
    "_default_": { 
        "_all": { "enabled": false },
        "_source": { "compress": true },
        "dynamic_templates": [
            {
                "string_template" : { 
                    "match" : "*",
                    "mapping": { "type": "string", "index": "not_analyzed" },
                    "match_mapping_type" : "string"
                 } 
             }
         ],
         "properties" : {
            "date" : { "type" : "date", "format": "yyyy-MM-dd HH:mm:ss"},
            "device" : { "type" : "string", "fields": {"raw": {"type": "string","index": 
"not_analyzed"}}},
            "distance" : { "type" : "integer"}
    }
}
}

```

Any help/hints/tips are appreciated!

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 29, 2015, 12:57pm UTC](https://discuss.elastic.co/t/logstash-using-not-analyzed-not-working/24533/2 "2015-06-29T12:57:09Z")

</div>

Your index template has "qdb-%{+YYYY.MM.dd}" as the index name pattern, but that won't work. That kind of pattern is specific to Logstash's elasticsearch output. Use "qdb-\*" or "qdb-????.??.??" instead.

---

<div class="post-metadata">

### Author: ![JeroenvdV](https://avatars.discourse-cdn.com/v4/letter/j/a8b319/32.png) [@JeroenvdV](https://discuss.elastic.co/u/JeroenvdV)
#### Post date: [June 29, 2015, 2:29pm UTC](https://discuss.elastic.co/t/logstash-using-not-analyzed-not-working/24533/3 "2015-06-29T14:29:21Z")

</div>

Hi Magnus, thx for the reply.

I changed it to "qdb-\*", deleted the sincedb and all indexes in ES, reran logstash, deleted the index pattern from kibana and added the index pattern in kibana but I am still seeing almost all fields as "analyzed" in kibana.

any other idea's?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 29, 2015, 2:41pm UTC](https://discuss.elastic.co/t/logstash-using-not-analyzed-not-working/24533/4 "2015-06-29T14:41:09Z")

</div>

What does the actual mapping look like for the index in question (use e.g. the [get mapping API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html)).

---

<div class="post-metadata">

### Author: ![JeroenvdV](https://avatars.discourse-cdn.com/v4/letter/j/a8b319/32.png) [@JeroenvdV](https://discuss.elastic.co/u/JeroenvdV)
#### Post date: [June 29, 2015, 3:29pm UTC](https://discuss.elastic.co/t/logstash-using-not-analyzed-not-working/24533/5 "2015-06-29T15:29:18Z")

</div>

```
"qdb-2014.02.14": {
      "mappings": {
         "core2": {
            "_all": {
               "enabled": false},
            "_source": {
               "compress": true},
            "properties": {
               "@timestamp": {"type": "date", "format": "dateOptionalTime"},
               "@version": {"type": "string"},
               "Active Flag": {"type": "string"},
               "Assignee": {"type": "string"},
               "Category": {"type": "string"},
               "Closed Date Time": {"type": "string"},
               "Country": {"type": "string"},
               "Customer Organization": {"type": "string"},
               "Division": {"type": "string"},
               "First Assign Date Time": {"type": "string"},
               "Hrs_Assigned_To_Completed": {"type": "double"},
               "Hrs_New_To_Assign": {"type": "double"},
               "Importance": {"type": "string"},
               "In Out SLA Resolution 1": {"type": "string"},
               "Is_Valid_Category": {"type": "string"},
               "Last Modified": {"type": "string"},
               "Open Date Time": {"type": "string"},
               "Opened By": {"type": "string"},
               "Priority": {"type": "string"},
               "Processtype": {"type": "string"},
               "Ref Nr": {"type": "string"},
               "Requested By": {"type": "string"},
               "Resolve Completed Date Time": {"type": "string"},
               "Service": {"type": "string"},
               "Severity": {"type": "string"},
               "Status and Reason": {"type": "string"},
               "Summary": {"type": "string"},
               "Tower": {"type": "string"},
               "USD Group": {"type": "string"},
               "host": {"type": "string"},
               "message": {"type": "string"},
               "path": {"type": "string"},
               "snapshot_date_time": {"type": "string"},
               "source_host": {"type": "string","index": "not_analyzed"},
               "tags": {"type": "string","index": "not_analyzed"},
               "type": {"type": "string","index": "not_analyzed"}
            }
         }
      }
   },
```

---

<div class="post-metadata">

### Author: ![JeroenvdV](https://avatars.discourse-cdn.com/v4/letter/j/a8b319/32.png) [@JeroenvdV](https://discuss.elastic.co/u/JeroenvdV)
#### Post date: [June 30, 2015, 8:48am UTC](https://discuss.elastic.co/t/logstash-using-not-analyzed-not-working/24533/6 "2015-06-30T08:48:57Z")

</div>

I tried another approach, I uploaded a template via curl directly into elasticsearch. Removed the template lines from the conf file, deleted all indexes and sincedb and re indexed... voila. It worked...  
(maybe/probably my original attempts with the template.json the template was in the wrong folder or naming was not correct...??? maybe I will find out later but for now it works 🙂 )

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:36am UTC](https://discuss.elastic.co/t/logstash-using-not-analyzed-not-working/24533/7 "2017-07-06T05:36:02Z")

</div>


