# Mapping with type keyword is still analyzed

**URL:** <https://discuss.elastic.co/t/mapping-with-type-keyword-is-still-analyzed/77239>\
**Category:** Elasticsearch\
**Created:** [March 3, 2017, 12:30am UTC](https://discuss.elastic.co/t/mapping-with-type-keyword-is-still-analyzed/77239 "2017-03-03T00:30:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![birduser](https://avatars.discourse-cdn.com/v4/letter/b/f1d935/32.png) [@birduser](https://discuss.elastic.co/u/birduser)\
**Post date:** [March 3, 2017, 12:30am UTC](https://discuss.elastic.co/t/mapping-with-type-keyword-is-still-analyzed/77239/1 "2017-03-03T00:30:53Z")

</div>

**Elasticsearch version** : 5.2.2

**Plugins installed** : [none]

**JVM version** :

```auto
java version "1.8.0_121"
Java(TM) SE Runtime Environment (build 1.8.0_121-b13)
Java HotSpot(TM) 64-Bit Server VM (build 25.121-b13, mixed mode)

```

**OS version** :  
CentOS 7

**Description of the problem including expected versus actual behavior** :  
Fields should not be analyzed, not working with type : keyword, I still find the record when searching parts of a string

**Steps to reproduce** :  
Create New Index, all future message fields in this index shall be not\_analyzed (since v5 = type : keyword):

```auto
curl -X PUT 'http://10.2.5.230:9200/twitter' -d '{
  "mappings": {
    "tweet": {
      "properties": {
        "message": {
          "type": "keyword"
        }
      }
    }
  }
}'

```

Get mapping for check:

```auto
curl -X GET 'http://10.2.5.230:9200/twitter/_mapping/tweet?pretty'
{
  "twitter" : {
    "mappings" : {
      "tweet" : {
        "properties" : {
          "message" : {
            "type" : "keyword"
          }
        }
      }
    }
  }
}

```

Seems good, add record:

```auto
curl -X PUT 'http://10.2.5.230:9200/twitter/tweet/xyz?pretty' -d '{
  "foo" : "2",
  "message" : "trying out Elasticsearch"
}'

```

Now search for a part of the string "trying out Elasticsearch", should return in zero hits:

```auto
curl -X POST 'http://10.2.5.230:9200/twitter/tweet/_search?pretty' -d '{
  "query": { "query_string": { "query" : "out" } }
}'

```

But it has been found:

```auto
{
  "took" : 4,
  "timed_out" : false,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "failed" : 0
  },
  "hits" : {
    "total" : 1,
    "max_score" : 0.2876821,
    "hits" : [
      {
        "_index" : "twitter",
        "_type" : "tweet",
        "_id" : "xyz",
        "_score" : 0.2876821,
        "_source" : {
          "foo" : "2",
          "message" : "trying out Elasticsearch"
        }
      }
    ]
  }
}

```

Is it a bug or am I too stupid to use it?

---

<div class="post-metadata">

**Author:** ![birduser](https://avatars.discourse-cdn.com/v4/letter/b/f1d935/32.png) [@birduser](https://discuss.elastic.co/u/birduser)\
**Post date:** [March 3, 2017, 1:21am UTC](https://discuss.elastic.co/t/mapping-with-type-keyword-is-still-analyzed/77239/2 "2017-03-03T01:21:13Z")

</div>

Okay, I got it...  
The query has to be in the following format:

```auto
curl -X POST 'http://10.2.5.230:9200/twitter/tweet/_search?pretty' -d '{
    "query" : {
        "constant_score" : {
            "filter" : {
                "term" : {
                    "message" : "trying out Elasticsearch"
                }
            }
        }
    }
}'

```

But I don't get it. Why can it still be found with "query\_string"?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 3, 2017, 4:08am UTC](https://discuss.elastic.co/t/mapping-with-type-keyword-is-still-analyzed/77239/3 "2017-03-03T04:08:39Z")

</div>

What is the mapping after you inserted your doc?

BTW it's strange that a keyword analyzer is defined on the keyword type. Only normalizers can be defined.

---

<div class="post-metadata">

**Author:** ![birduser](https://avatars.discourse-cdn.com/v4/letter/b/f1d935/32.png) [@birduser](https://discuss.elastic.co/u/birduser)\
**Post date:** [March 3, 2017, 11:03am UTC](https://discuss.elastic.co/t/mapping-with-type-keyword-is-still-analyzed/77239/4 "2017-03-03T11:03:26Z")

</div>

After adding a record the mapping looks like this:

```auto
{
  "twitter" : {
    "mappings" : {
      "tweet" : {
        "properties" : {
          "foo" : {
            "type" : "text",
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          },
          "message" : {
            "type" : "keyword"
          }
        }
      }
    }
  }
}

```

Isn't it strange, that the record can be found with "query\_string"?  
I mean the idea of "type : keyword" is NOT to index the single parts of the string, why can it still be found?  
Would it be a good idea to make "type:keyword" as default for all fields and query exact searches with "constant\_score" and fulltext with "query\_string"?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 3, 2017, 11:21am UTC](https://discuss.elastic.co/t/mapping-with-type-keyword-is-still-analyzed/77239/5 "2017-03-03T11:21:28Z")

</div>

Actually I missed one part:

```auto
curl -X POST 'http://10.2.5.230:9200/twitter/tweet/_search?pretty' -d '{
  "query": { "query_string": { "query" : "out" } }
}'

```

You are searching here in the `_all` field as you did not set the field. `_all` uses by default the standard analyzer.

Try:

```auto
curl -X POST 'http://10.2.5.230:9200/twitter/tweet/_search?pretty' -d '{
  "query": { "query_string": { "query" : "message:out" } }
}'

```

Or

```auto
curl 'http://10.2.5.230:9200/twitter/tweet/_search?q=message:out'

```

---

<div class="post-metadata">

**Author:** ![birduser](https://avatars.discourse-cdn.com/v4/letter/b/f1d935/32.png) [@birduser](https://discuss.elastic.co/u/birduser)\
**Post date:** [March 3, 2017, 12:45pm UTC](https://discuss.elastic.co/t/mapping-with-type-keyword-is-still-analyzed/77239/6 "2017-03-03T12:45:45Z")

</div>

Ah, okay, I think I got it! Thank you for your time! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2017, 12:45pm UTC](https://discuss.elastic.co/t/mapping-with-type-keyword-is-still-analyzed/77239/7 "2017-03-31T12:45:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
