# Not able to search Upper case values

**URL:** <https://discuss.elastic.co/t/not-able-to-search-upper-case-values/23704>\
**Category:** Elasticsearch\
**Created:** [May 28, 2015, 8:45am UTC](https://discuss.elastic.co/t/not-able-to-search-upper-case-values/23704 "2015-05-28T08:45:38Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [May 28, 2015, 8:45am UTC](https://discuss.elastic.co/t/not-able-to-search-upper-case-values/23704/1 "2015-05-28T08:45:38Z")

</div>

Hi Experts,

In my log I have a field "Customer". It has all the values in capital  
latter like "VIKAS". Now when I fire query in Kibana like Customer:"vikas"  
or Customer:"VIK\*" I got nothing . It works only when I do exact search  
like Customer:"VIKAS".

I have following question

1. How I can search value with wildcard, something like name start with vi  
OR VI ?

My Template is like

{  
"template\_vg":{  
"template" : "vg\*",  
"settings" : {  
"number\_of\_shards" : 5,  
"index.cache.field.type" : "soft",  
"index.refresh\_interval" : "5s",  
"index.store.compress.stored" : true,  
"index.query.default\_field" : "message",  
"index.routing.allocation.total\_shards\_per\_node" : 5,  
"index":{  
"analysis":{  
"analyzer":{  
"analyzer\_keyword":{  
"type": "custom",  
"tokenizer":"keyword",  
"filter":"lowercase"  
}  
}  
}  
}  
},  
"mappings" : {  
"_default_" : {  
"\_all" : {"enabled" : false},  
"properties" : {  
"Order\_ID": {"type": "string","index" :"not\_analyzed","doc\_values" : true},  
"Customer": {"type": "string","index" : "not\_analyzed","doc\_values" : true  
,"analyzer":"analyzer\_keyword"},  
"Ordered\_On": {"type": "string","index" : "not\_analyzed","doc\_values" :  
true },  
"Required\_By": {"type": "string","index" : "not\_analyzed","doc\_values" :  
true },  
"Freight": {"type": "string","index" : "not\_analyzed","doc\_values" : true },  
"Shipped\_On": {"type": "string","index" : "not\_analyzed","doc\_values" :  
true },  
"Country": {"type": "string","index" : "not\_analyzed","doc\_values" : true },  
"Post\_Code": {"type": "string","index" : "not\_analyzed","doc\_values" : true  
}  
}  
}  
}  
}  
}

I read almost everything and got an idea that I need to use analyzer with  
Lowercase filter which will convert my values to lowercase then I can apply  
wildcard.But with the above analyzer for Customer I still got nothing . Can  
someone help me to understand what I am doing wrong .

## -- Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Allan\_Mitchell](https://avatars.discourse-cdn.com/v4/letter/a/edb3f5/32.png) [@Allan\_Mitchell](https://discuss.elastic.co/u/Allan_Mitchell)\
**Post date:** [May 28, 2015, 9:10am UTC](https://discuss.elastic.co/t/not-able-to-search-upper-case-values/23704/2 "2015-05-28T09:10:07Z")

</div>

Hi

"Customer" is set to be "not\_analyzed" so won't go through your analyser.

not\_analyzedIndex this field, so it is searchable, but index the value  
exactly as specified. Do not analyze it.

On 28 May 2015 at 09:45, vikas gopal [vikas.hafig@gmail.com](mailto:vikas.hafig@gmail.com) wrote:

> Hi Experts,
> 
> In my log I have a field "Customer". It has all the values in capital  
> latter like "VIKAS". Now when I fire query in Kibana like Customer:"vikas"  
> or Customer:"VIK\*" I got nothing . It works only when I do exact search  
> like Customer:"VIKAS".
> 
> I have following question
> 
> 1. How I can search value with wildcard, something like name start with vi  
> OR VI ?
> 
> My Template is like
> 
> {  
> "template\_vg":{  
> "template" : "vg\*",  
> "settings" : {  
> "number\_of\_shards" : 5,  
> "index.cache.field.type" : "soft",  
> "index.refresh\_interval" : "5s",  
> "index.store.compress.stored" : true,  
> "index.query.default\_field" : "message",  
> "index.routing.allocation.total\_shards\_per\_node" : 5,  
> "index":{  
> "analysis":{  
> "analyzer":{  
> "analyzer\_keyword":{  
> "type": "custom",  
> "tokenizer":"keyword",  
> "filter":"lowercase"  
> }  
> }  
> }  
> }  
> },  
> "mappings" : {  
> "_default_" : {  
> "\_all" : {"enabled" : false},  
> "properties" : {  
> "Order\_ID": {"type": "string","index" :"not\_analyzed","doc\_values" : true},  
> "Customer": {"type": "string","index" : "not\_analyzed","doc\_values" : true  
> ,"analyzer":"analyzer\_keyword"},  
> "Ordered\_On": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> true },  
> "Required\_By": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> true },  
> "Freight": {"type": "string","index" : "not\_analyzed","doc\_values" : true  
> },  
> "Shipped\_On": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> true },  
> "Country": {"type": "string","index" : "not\_analyzed","doc\_values" : true  
> },  
> "Post\_Code": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> true }  
> }  
> }  
> }  
> }  
> }
> 
> I read almost everything and got an idea that I need to use analyzer with  
> Lowercase filter which will convert my values to lowercase then I can apply  
> wildcard.But with the above analyzer for Customer I still got nothing . Can  
> someone help me to understand what I am doing wrong .
> 
> ## -- Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)
> 
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

## -- Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAECdJzBkQ%3DE%3DnFtrwbcUCazx8AZFnVv9SaC7X2Ju9fMSg7mD4Q%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAECdJzBkQ%3DE%3DnFtrwbcUCazx8AZFnVv9SaC7X2Ju9fMSg7mD4Q%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [May 28, 2015, 10:03am UTC](https://discuss.elastic.co/t/not-able-to-search-upper-case-values/23704/3 "2015-05-28T10:03:14Z")

</div>

Thanks Allan,

I have changed it to ""Customer": {"type": "string","index" :  
"analyzed","doc\_values" : true ,"analyzer":"analyzer\_keyword"}," , but with  
this setting LS is not able to create an index.

On Thursday, May 28, 2015 at 2:40:14 PM UTC+5:30, Allan Mitchell wrote:

> Hi
> 
> "Customer" is set to be "not\_analyzed" so won't go through your analyser.
> 
> not\_analyzedIndex this field, so it is searchable, but index the value  
> exactly as specified. Do not analyze it.
> 
> On 28 May 2015 at 09:45, vikas gopal \<[vikas...@gmail.com](mailto:vikas...@gmail.com) \<javascript:\>\>  
> wrote:
> 
> > Hi Experts,
> > 
> > In my log I have a field "Customer". It has all the values in capital  
> > latter like "VIKAS". Now when I fire query in Kibana like Customer:"vikas"  
> > or Customer:"VIK\*" I got nothing . It works only when I do exact search  
> > like Customer:"VIKAS".
> > 
> > I have following question
> > 
> > 1. How I can search value with wildcard, something like name start with  
> > vi OR VI ?
> > 
> > My Template is like
> > 
> > {  
> > "template\_vg":{  
> > "template" : "vg\*",  
> > "settings" : {  
> > "number\_of\_shards" : 5,  
> > "index.cache.field.type" : "soft",  
> > "index.refresh\_interval" : "5s",  
> > "index.store.compress.stored" : true,  
> > "index.query.default\_field" : "message",  
> > "index.routing.allocation.total\_shards\_per\_node" : 5,  
> > "index":{  
> > "analysis":{  
> > "analyzer":{  
> > "analyzer\_keyword":{  
> > "type": "custom",  
> > "tokenizer":"keyword",  
> > "filter":"lowercase"  
> > }  
> > }  
> > }  
> > }  
> > },  
> > "mappings" : {  
> > "_default_" : {  
> > "\_all" : {"enabled" : false},  
> > "properties" : {  
> > "Order\_ID": {"type": "string","index" :"not\_analyzed","doc\_values" :  
> > true},  
> > "Customer": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > true ,"analyzer":"analyzer\_keyword"},  
> > "Ordered\_On": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > true },  
> > "Required\_By": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > true },  
> > "Freight": {"type": "string","index" : "not\_analyzed","doc\_values" : true  
> > },  
> > "Shipped\_On": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > true },  
> > "Country": {"type": "string","index" : "not\_analyzed","doc\_values" : true  
> > },  
> > "Post\_Code": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > true }  
> > }  
> > }  
> > }  
> > }  
> > }
> > 
> > I read almost everything and got an idea that I need to use analyzer with  
> > Lowercase filter which will convert my values to lowercase then I can apply  
> > wildcard.But with the above analyzer for Customer I still got nothing . Can  
> > someone help me to understand what I am doing wrong .
> > 
> > ## -- Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)
> > 
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

## -- Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Allan\_Mitchell](https://avatars.discourse-cdn.com/v4/letter/a/edb3f5/32.png) [@Allan\_Mitchell](https://discuss.elastic.co/u/Allan_Mitchell)\
**Post date:** [May 28, 2015, 10:15am UTC](https://discuss.elastic.co/t/not-able-to-search-upper-case-values/23704/4 "2015-05-28T10:15:16Z")

</div>

Hi

That is correct.

Doc values can be enabled for numeric, date, Boolean, binary, and geo-point  
fields, and for not\_analyzed string fields.  
[https://www.elastic.co/guide/en/elasticsearch/guide/current/doc-values.html#id-1.7.12.6.9.2.2](https://www.elastic.co/guide/en/elasticsearch/guide/current/doc-values.html#id-1.7.12.6.9.2.2)

[https://www.elastic.co/guide/en/elasticsearch/guide/current/doc-values.html#id-1.7.12.6.9.2.3](https://www.elastic.co/guide/en/elasticsearch/guide/current/doc-values.html#id-1.7.12.6.9.2.3)They  
do not currently work with analyzed string fields. Doc values are enabled  
per field in the field mapping, which means that you can combine in-memory  
fielddata with doc values:

Your error message will have been similar to

{  
"error": "MapperParsingException[mapping [mytype]]; nested:  
MapperParsingException[Field [myfield] cannot be analyzed and have doc  
values]; ",  
"status": 400  
}

On 28 May 2015 at 11:03, vikas gopal [vikas.hafig@gmail.com](mailto:vikas.hafig@gmail.com) wrote:

> Thanks Allan,
> 
> I have changed it to ""Customer": {"type": "string","index" :  
> "analyzed","doc\_values" : true ,"analyzer":"analyzer\_keyword"}," , but with  
> this setting LS is not able to create an index.
> 
> On Thursday, May 28, 2015 at 2:40:14 PM UTC+5:30, Allan Mitchell wrote:
> 
> > Hi
> > 
> > "Customer" is set to be "not\_analyzed" so won't go through your analyser.
> > 
> > not\_analyzedIndex this field, so it is searchable, but index the value  
> > exactly as specified. Do not analyze it.
> > 
> > On 28 May 2015 at 09:45, vikas gopal [vikas...@gmail.com](mailto:vikas...@gmail.com) wrote:
> > 
> > > Hi Experts,
> > > 
> > > In my log I have a field "Customer". It has all the values in capital  
> > > latter like "VIKAS". Now when I fire query in Kibana like Customer:"vikas"  
> > > or Customer:"VIK\*" I got nothing . It works only when I do exact search  
> > > like Customer:"VIKAS".
> > > 
> > > I have following question
> > > 
> > > 1. How I can search value with wildcard, something like name start with  
> > > vi OR VI ?
> > > 
> > > My Template is like
> > > 
> > > {  
> > > "template\_vg":{  
> > > "template" : "vg\*",  
> > > "settings" : {  
> > > "number\_of\_shards" : 5,  
> > > "index.cache.field.type" : "soft",  
> > > "index.refresh\_interval" : "5s",  
> > > "index.store.compress.stored" : true,  
> > > "index.query.default\_field" : "message",  
> > > "index.routing.allocation.total\_shards\_per\_node" : 5,  
> > > "index":{  
> > > "analysis":{  
> > > "analyzer":{  
> > > "analyzer\_keyword":{  
> > > "type": "custom",  
> > > "tokenizer":"keyword",  
> > > "filter":"lowercase"  
> > > }  
> > > }  
> > > }  
> > > }  
> > > },  
> > > "mappings" : {  
> > > "_default_" : {  
> > > "\_all" : {"enabled" : false},  
> > > "properties" : {  
> > > "Order\_ID": {"type": "string","index" :"not\_analyzed","doc\_values" :  
> > > true},  
> > > "Customer": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true ,"analyzer":"analyzer\_keyword"},  
> > > "Ordered\_On": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true },  
> > > "Required\_By": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true },  
> > > "Freight": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true },  
> > > "Shipped\_On": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true },  
> > > "Country": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true },  
> > > "Post\_Code": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true }  
> > > }  
> > > }  
> > > }  
> > > }  
> > > }
> > > 
> > > I read almost everything and got an idea that I need to use analyzer  
> > > with Lowercase filter which will convert my values to lowercase then I can  
> > > apply wildcard.But with the above analyzer for Customer I still got nothing  
> > > . Can someone help me to understand what I am doing wrong .
> > > 
> > > ## -- Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)
> > > 
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > To view this discussion on the web visit  
> > > [https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)
> 
> * * *
> 
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

## -- Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAECdJzC6625TyyB%3DnaQr0o3vgcP5Krcy8x2\_PA7Nv2DLjGoNvg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAECdJzC6625TyyB%3DnaQr0o3vgcP5Krcy8x2_PA7Nv2DLjGoNvg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 28, 2015, 10:25am UTC](https://discuss.elastic.co/t/not-able-to-search-upper-case-values/23704/5 "2015-05-28T10:25:49Z")

</div>

You cannot set doc values on an analysed field.

PS - We're moving to [https://discuss.elastic.co/](https://discuss.elastic.co/), please join us there for  
any future discussions!

On 28 May 2015 at 20:03, vikas gopal [vikas.hafig@gmail.com](mailto:vikas.hafig@gmail.com) wrote:

> Thanks Allan,
> 
> I have changed it to ""Customer": {"type": "string","index" :  
> "analyzed","doc\_values" : true ,"analyzer":"analyzer\_keyword"}," , but with  
> this setting LS is not able to create an index.
> 
> On Thursday, May 28, 2015 at 2:40:14 PM UTC+5:30, Allan Mitchell wrote:
> 
> > Hi
> > 
> > "Customer" is set to be "not\_analyzed" so won't go through your analyser.
> > 
> > not\_analyzedIndex this field, so it is searchable, but index the value  
> > exactly as specified. Do not analyze it.
> > 
> > On 28 May 2015 at 09:45, vikas gopal [vikas...@gmail.com](mailto:vikas...@gmail.com) wrote:
> > 
> > > Hi Experts,
> > > 
> > > In my log I have a field "Customer". It has all the values in capital  
> > > latter like "VIKAS". Now when I fire query in Kibana like Customer:"vikas"  
> > > or Customer:"VIK\*" I got nothing . It works only when I do exact search  
> > > like Customer:"VIKAS".
> > > 
> > > I have following question
> > > 
> > > 1. How I can search value with wildcard, something like name start with  
> > > vi OR VI ?
> > > 
> > > My Template is like
> > > 
> > > {  
> > > "template\_vg":{  
> > > "template" : "vg\*",  
> > > "settings" : {  
> > > "number\_of\_shards" : 5,  
> > > "index.cache.field.type" : "soft",  
> > > "index.refresh\_interval" : "5s",  
> > > "index.store.compress.stored" : true,  
> > > "index.query.default\_field" : "message",  
> > > "index.routing.allocation.total\_shards\_per\_node" : 5,  
> > > "index":{  
> > > "analysis":{  
> > > "analyzer":{  
> > > "analyzer\_keyword":{  
> > > "type": "custom",  
> > > "tokenizer":"keyword",  
> > > "filter":"lowercase"  
> > > }  
> > > }  
> > > }  
> > > }  
> > > },  
> > > "mappings" : {  
> > > "_default_" : {  
> > > "\_all" : {"enabled" : false},  
> > > "properties" : {  
> > > "Order\_ID": {"type": "string","index" :"not\_analyzed","doc\_values" :  
> > > true},  
> > > "Customer": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true ,"analyzer":"analyzer\_keyword"},  
> > > "Ordered\_On": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true },  
> > > "Required\_By": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true },  
> > > "Freight": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true },  
> > > "Shipped\_On": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true },  
> > > "Country": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true },  
> > > "Post\_Code": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > true }  
> > > }  
> > > }  
> > > }  
> > > }  
> > > }
> > > 
> > > I read almost everything and got an idea that I need to use analyzer  
> > > with Lowercase filter which will convert my values to lowercase then I can  
> > > apply wildcard.But with the above analyzer for Customer I still got nothing  
> > > . Can someone help me to understand what I am doing wrong .
> > > 
> > > ## -- Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)
> > > 
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > To view this discussion on the web visit  
> > > [https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com)  
> > > [https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > 
> > --  
> > Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)
> 
> * * *
> 
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

## -- Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEYi1X\_HfCJqEEf1QrNV48EFT6L48SL0Y0nJ-hSkxMbJYKmMow%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEYi1X_HfCJqEEf1QrNV48EFT6L48SL0Y0nJ-hSkxMbJYKmMow%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![shoebalig](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@shoebalig](https://discuss.elastic.co/u/shoebalig)\
**Post date:** [May 28, 2015, 11:19am UTC](https://discuss.elastic.co/t/not-able-to-search-upper-case-values/23704/6 "2015-05-28T11:19:14Z")

</div>

Use any analyzer to you input query string, then use analysed string to process query. you will get the appropriate results.  
I faced the same problem , i used standard analyser for my query string and problem got resolved.

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [May 28, 2015, 2:31pm UTC](https://discuss.elastic.co/t/not-able-to-search-upper-case-values/23704/7 "2015-05-28T14:31:05Z")

</div>

Wow that works thank you Mark

On Thursday, May 28, 2015 at 3:56:17 PM UTC+5:30, Mark Walkom wrote:

> You cannot set doc values on an analysed field.
> 
> PS - We're moving to [https://discuss.elastic.co/](https://discuss.elastic.co/), please join us there  
> for any future discussions!
> 
> On 28 May 2015 at 20:03, vikas gopal \<[vikas...@gmail.com](mailto:vikas...@gmail.com) \<javascript:\>\>  
> wrote:
> 
> > Thanks Allan,
> > 
> > I have changed it to ""Customer": {"type": "string","index" :  
> > "analyzed","doc\_values" : true ,"analyzer":"analyzer\_keyword"}," , but with  
> > this setting LS is not able to create an index.
> > 
> > On Thursday, May 28, 2015 at 2:40:14 PM UTC+5:30, Allan Mitchell wrote:
> > 
> > > Hi
> > > 
> > > "Customer" is set to be "not\_analyzed" so won't go through your analyser.
> > > 
> > > not\_analyzedIndex this field, so it is searchable, but index the value  
> > > exactly as specified. Do not analyze it.
> > > 
> > > On 28 May 2015 at 09:45, vikas gopal [vikas...@gmail.com](mailto:vikas...@gmail.com) wrote:
> > > 
> > > > Hi Experts,
> > > > 
> > > > In my log I have a field "Customer". It has all the values in capital  
> > > > latter like "VIKAS". Now when I fire query in Kibana like Customer:"vikas"  
> > > > or Customer:"VIK\*" I got nothing . It works only when I do exact search  
> > > > like Customer:"VIKAS".
> > > > 
> > > > I have following question
> > > > 
> > > > 1. How I can search value with wildcard, something like name start with  
> > > > vi OR VI ?
> > > > 
> > > > My Template is like
> > > > 
> > > > {  
> > > > "template\_vg":{  
> > > > "template" : "vg\*",  
> > > > "settings" : {  
> > > > "number\_of\_shards" : 5,  
> > > > "index.cache.field.type" : "soft",  
> > > > "index.refresh\_interval" : "5s",  
> > > > "index.store.compress.stored" : true,  
> > > > "index.query.default\_field" : "message",  
> > > > "index.routing.allocation.total\_shards\_per\_node" : 5,  
> > > > "index":{  
> > > > "analysis":{  
> > > > "analyzer":{  
> > > > "analyzer\_keyword":{  
> > > > "type": "custom",  
> > > > "tokenizer":"keyword",  
> > > > "filter":"lowercase"  
> > > > }  
> > > > }  
> > > > }  
> > > > }  
> > > > },  
> > > > "mappings" : {  
> > > > "_default_" : {  
> > > > "\_all" : {"enabled" : false},  
> > > > "properties" : {  
> > > > "Order\_ID": {"type": "string","index" :"not\_analyzed","doc\_values" :  
> > > > true},  
> > > > "Customer": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > > true ,"analyzer":"analyzer\_keyword"},  
> > > > "Ordered\_On": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > > true },  
> > > > "Required\_By": {"type": "string","index" : "not\_analyzed","doc\_values"  
> > > > : true },  
> > > > "Freight": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > > true },  
> > > > "Shipped\_On": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > > true },  
> > > > "Country": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > > true },  
> > > > "Post\_Code": {"type": "string","index" : "not\_analyzed","doc\_values" :  
> > > > true }  
> > > > }  
> > > > }  
> > > > }  
> > > > }  
> > > > }
> > > > 
> > > > I read almost everything and got an idea that I need to use analyzer  
> > > > with Lowercase filter which will convert my values to lowercase then I can  
> > > > apply wildcard.But with the above analyzer for Customer I still got nothing  
> > > > . Can someone help me to understand what I am doing wrong .
> > > > 
> > > > ## -- Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)
> > > > 
> > > > You received this message because you are subscribed to the Google  
> > > > Groups "elasticsearch" group.  
> > > > To unsubscribe from this group and stop receiving emails from it, send  
> > > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).  
> > > > To view this discussion on the web visit  
> > > > [https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com)  
> > > > [https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/eb6bda79-428d-4fdc-b478-65f07905fe89%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > > .  
> > > > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).
> > > 
> > > --  
> > > Please update your bookmarks! We have moved to  
> > > [https://discuss.elastic.co/](https://discuss.elastic.co/)
> > 
> > * * *
> > 
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com)  
> > [https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/46c4f481-6876-463b-9c7e-bfb22e4acdee%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .
> > 
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

## -- Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/98ba086f-f343-430f-8aa4-de1cfe10b0e9%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/98ba086f-f343-430f-8aa4-de1cfe10b0e9%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [May 28, 2015, 2:32pm UTC](https://discuss.elastic.co/t/not-able-to-search-upper-case-values/23704/8 "2015-05-28T14:32:35Z")

</div>

Thank you Shoeb,

Actually the problem was I was using Not\_analyzed along with doc\_value :  
true, which causes the problem . Thanks to Mark , problem has been resolved  
now. Thank you again for your suggestion and support.

On Thursday, May 28, 2015 at 6:13:31 PM UTC+5:30, shoeb khan wrote:

> Use any analyzer to you input query string, then use analysed string to  
> process query. you will get the appropriate results.  
> I faced the same problem , i used standard analyser for my query string  
> and  
> problem got resolved.
> 
> --  
> View this message in context:  
> [http://elasticsearch-users.115913.n3.nabble.com/Not-able-to-search-Upper-case-values-tp4074950p4074966.html](http://elasticsearch-users.115913.n3.nabble.com/Not-able-to-search-Upper-case-values-tp4074950p4074966.html)  
> Sent from the Elasticsearch Users mailing list archive at [Nabble.com](http://Nabble.com).

## -- Please update your bookmarks! We have moved to [https://discuss.elastic.co/](https://discuss.elastic.co/)

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a288c1ed-8ef3-459b-bed4-311b184e4e62%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a288c1ed-8ef3-459b-bed4-311b184e4e62%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:11am UTC](https://discuss.elastic.co/t/not-able-to-search-upper-case-values/23704/9 "2017-07-06T00:11:16Z")

</div>


