# Lower case all fields

**URL:** <https://discuss.elastic.co/t/lower-case-all-fields/359791>\
**Category:** Elasticsearch\
**Created:** [May 20, 2024, 7:13am UTC](https://discuss.elastic.co/t/lower-case-all-fields/359791 "2024-05-20T07:13:51Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![han\_fatzot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/han_fatzot/32/134164_2.png) [@han\_fatzot](https://discuss.elastic.co/u/han_fatzot)\
**Post date:** [May 20, 2024, 7:13am UTC](https://discuss.elastic.co/t/lower-case-all-fields/359791/1 "2024-05-20T07:13:51Z")

</div>

hello 😊  
I want to create visualizations on lowercase fields.  
Text type can not work because it can be aggerated.  
example:  
I want to create a visualization that shows the top ten process.executable but i want to make sure that all the process.executable are in lowercase. c:\temp\virus.exe and c:\temp\Virus.exe is the same for me.  
how can i do it on all the fields in my index???

---

<div class="post-metadata">

**Author:** ![Carlos\_D](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_d/32/126245_2.png) [@Carlos\_D](https://discuss.elastic.co/u/Carlos_D)\
**Post date:** [May 20, 2024, 8:01am UTC](https://discuss.elastic.co/t/lower-case-all-fields/359791/2 "2024-05-20T08:01:49Z")

</div>

Hey @han_fatzot !

If you want to lowercase your keyword fields, you can use [normalizers](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-normalizers.html) for that. It allows you to use an analyzer-like chain for keyword values.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![han\_fatzot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/han_fatzot/32/134164_2.png) [@han\_fatzot](https://discuss.elastic.co/u/han_fatzot)\
**Post date:** [May 20, 2024, 8:07am UTC](https://discuss.elastic.co/t/lower-case-all-fields/359791/3 "2024-05-20T08:07:39Z")

</div>

how to do it on all my fields without writing on every field with normalizer??  
how to do it in index template??

---

<div class="post-metadata">

**Author:** ![Carlos\_D](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_d/32/126245_2.png) [@Carlos\_D](https://discuss.elastic.co/u/Carlos_D)\
**Post date:** [May 20, 2024, 8:21am UTC](https://discuss.elastic.co/t/lower-case-all-fields/359791/4 "2024-05-20T08:21:23Z")

</div>

You could use [dynamic templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-templates.html) for that, something similar to:

```auto
PUT my-index
{
  "settings": {
     ...
  },
  "mappings": {
    "dynamic_templates": [
      {
        "strings": {
          "match_mapping_type": "string",
          "mapping": {
            "type": "keyword",
            "ignore_above": 256,
            "normalizer": "my-normalizer"
          }
        }
      }
    ]
  }
}

```

That would match all string fields that don't exist already in the mapping and use a `keyword` with a specific normalizer for mapping them.

---

<div class="post-metadata">

**Author:** ![han\_fatzot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/han_fatzot/32/134164_2.png) [@han\_fatzot](https://discuss.elastic.co/u/han_fatzot)\
**Post date:** [May 20, 2024, 8:40am UTC](https://discuss.elastic.co/t/lower-case-all-fields/359791/5 "2024-05-20T08:40:08Z")

</div>

how to do it on already mapped fields?

---

<div class="post-metadata">

**Author:** ![Carlos\_D](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_d/32/126245_2.png) [@Carlos\_D](https://discuss.elastic.co/u/Carlos_D)\
**Post date:** [May 20, 2024, 8:59am UTC](https://discuss.elastic.co/t/lower-case-all-fields/359791/6 "2024-05-20T08:59:32Z")

</div>

I would recommend [reindexing](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html) into a new index that already have the dynamic mapping.

---

<div class="post-metadata">

**Author:** ![han\_fatzot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/han_fatzot/32/134164_2.png) [@han\_fatzot](https://discuss.elastic.co/u/han_fatzot)\
**Post date:** [May 20, 2024, 9:07am UTC](https://discuss.elastic.co/t/lower-case-all-fields/359791/7 "2024-05-20T09:07:06Z")

</div>

but i have default mapping in my mapping template so if i do it in the dynamic mapping. will it change all the fields? also the fields that are mapped

---

<div class="post-metadata">

**Author:** ![han\_fatzot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/han_fatzot/32/134164_2.png) [@han\_fatzot](https://discuss.elastic.co/u/han_fatzot)\
**Post date:** [May 20, 2024, 10:48am UTC](https://discuss.elastic.co/t/lower-case-all-fields/359791/8 "2024-05-20T10:48:23Z")

</div>

@Carlos_D

---

<div class="post-metadata">

**Author:** ![Carlos\_D](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_d/32/126245_2.png) [@Carlos\_D](https://discuss.elastic.co/u/Carlos_D)\
**Post date:** [May 21, 2024, 7:44am UTC](https://discuss.elastic.co/t/lower-case-all-fields/359791/9 "2024-05-21T07:44:20Z")

</div>

> [@han\_fatzot](#):
>
> but i have default mapping in my mapping template so if i do it in the dynamic mapping. will it change all the fields? also the fields that are mapped

Once your mapping is created for a field, it won't change using dynamic mapping. You need to reindex into a different index with that dynamic template mapping to apply it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 18, 2024, 7:45am UTC](https://discuss.elastic.co/t/lower-case-all-fields/359791/10 "2024-06-18T07:45:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
