# Non-expected ".keyword" behavior

**URL:** <https://discuss.elastic.co/t/non-expected-keyword-behavior/156860>\
**Category:** Elasticsearch\
**Created:** [November 15, 2018, 1:03pm UTC](https://discuss.elastic.co/t/non-expected-keyword-behavior/156860 "2018-11-15T13:03:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![reweber](https://avatars.discourse-cdn.com/v4/letter/r/45deac/32.png) [@reweber](https://discuss.elastic.co/u/reweber)\
**Post date:** [November 15, 2018, 1:03pm UTC](https://discuss.elastic.co/t/non-expected-keyword-behavior/156860/1 "2018-11-15T13:03:00Z")

</div>

I have a log entry  
"http\_url": "[https://login.live.com/GetCredentialType.srf?wa=wsignin1.0](https://login.live.com/GetCredentialType.srf?wa=wsignin1.0)....."

Why does this query find the entry:

```
GET _search
{
  "query": {
    "bool": {
      "must": [
         { "wildcard": { "http_url": "*getcredentialtype*"} },
         { "exists" : { "field" : "http_url" } }
      ]
    }
  },
  "sort": ["_doc"],
  "size": 1000
}

```

but this doesnt:

```
GET _search
{
  "query": {
    "bool": {
      "must": [
         { "wildcard": { "http_url.keyword": "*GetCredentialType*"} },
         { "exists" : { "field" : "http_url" } }
      ]
    }
  },
  "sort": ["_doc"],
  "size": 1000
}

```

I thought ".keyword" gives me the unanalyzed field and then I can search in this field. I have not found one way to add the .keyword such that this log will ever appear.

---

<div class="post-metadata">

**Author:** ![mayya](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mayya/32/83147_2.png) [@mayya](https://discuss.elastic.co/u/mayya)\
**Post date:** [November 30, 2018, 10:12pm UTC](https://discuss.elastic.co/t/non-expected-keyword-behavior/156860/2 "2018-11-30T22:12:49Z")

</div>

I am surprised you are getting these results. In elasticsearch 6.x with default settings for `text` and `keyword` fields you should get the opposite: you find results with `"http_url.keyword"`, and you don't get results with `"http_url"`? What elasticsearch version are you using, and what is your index mapping for `http_url` field? Are you using any normalizers for the `keyword` field? You can check how your text got indexed using [Term Vectors API](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-termvectors.html).

About analysis - exactly as you said, `keyword` gives you not-analyzed field by default. And `wildcard query` as a term level query also works on not-analyzed text. So if you index `GetCredentialType` into the keyword field, it will keep it exactly as it is. So, to find it using term level queries, you also need to search for the exact word.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2018, 10:12pm UTC](https://discuss.elastic.co/t/non-expected-keyword-behavior/156860/3 "2018-12-28T22:12:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
