# No .raw field

**URL:** <https://discuss.elastic.co/t/no-raw-field/49342>\
**Category:** Logstash\
**Created:** [May 5, 2016, 8:55pm UTC](https://discuss.elastic.co/t/no-raw-field/49342 "2016-05-05T20:55:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andre\_de\_Martini](https://avatars.discourse-cdn.com/v4/letter/a/e79b87/32.png) [@Andre\_de\_Martini](https://discuss.elastic.co/u/Andre_de_Martini)\
**Post date:** [May 5, 2016, 8:55pm UTC](https://discuss.elastic.co/t/no-raw-field/49342/1 "2016-05-05T20:55:06Z")

</div>

Hi people!!

Don't know why but my latest logstash/elasticsearch/kibana are not using the .raw fields (I guess that it is true by default isnt?).

The real problem is that my string fields are been split by the spaces on the data.

Can someone help me?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 5, 2016, 11:37pm UTC](https://discuss.elastic.co/t/no-raw-field/49342/2 "2016-05-05T23:37:46Z")

</div>

Those fields are created by ES thanks to the LS template.  
So check the `_templates` endpoint in ES to make sure you have a matching one 🙂

---

<div class="post-metadata">

**Author:** ![m0tek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/m0tek/32/9656_2.png) [@m0tek](https://discuss.elastic.co/u/m0tek)\
**Post date:** [May 7, 2016, 9:37pm UTC](https://discuss.elastic.co/t/no-raw-field/49342/3 "2016-05-07T21:37:19Z")

</div>

Are you using the default logstash indexing ? (default template?)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 8, 2016, 7:45pm UTC](https://discuss.elastic.co/t/no-raw-field/49342/4 "2016-05-08T19:45:35Z")

</div>

I suspect you've changed the index name with the elasticsearch output's `index` option. Note that Logstash's default index template only applies to indexes whose names match logstash-\*.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:58am UTC](https://discuss.elastic.co/t/no-raw-field/49342/5 "2017-07-06T04:58:50Z")

</div>


