# Not able to understand the mapping in elasticsearch

**URL:** <https://discuss.elastic.co/t/not-able-to-understand-the-mapping-in-elasticsearch/134388>\
**Category:** Elasticsearch\
**Created:** [June 4, 2018, 8:26am UTC](https://discuss.elastic.co/t/not-able-to-understand-the-mapping-in-elasticsearch/134388 "2018-06-04T08:26:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![roshni](https://avatars.discourse-cdn.com/v4/letter/r/ce7236/32.png) [@roshni](https://discuss.elastic.co/u/roshni)\
**Post date:** [June 4, 2018, 8:26am UTC](https://discuss.elastic.co/t/not-able-to-understand-the-mapping-in-elasticsearch/134388/1 "2018-06-04T08:26:09Z")

</div>

Hi ,

I am very new to elasticsearch . Presently working in v5.4.3  
I was ging through the concept of mapping but could not get much clarity on the different types of mapping .  
For example -  
#curl -XPUT '[http://localhost:9200/twitter/user/XYZ?pretty](http://localhost:9200/twitter/user/XYZ?pretty)' -H 'Content-Type: application/json' -d '{ "name" : "ABC" }'

Is this automatic mapping (or default mapping ) ????? Since mapping is not defined before actual insertion of data takes place ???

And where we define the mapping template first and then insert data accordingly is explicit mapping ??  
like below -  
[root@node1 ~]# curl -X PUT "localhost:9200/test" -H 'Content-Type: application/json' -d'  
{  
"settings" : {  
"number\_of\_shards" : 1,  
"number\_of\_replicas" : 0  
},  
"mappings" : {  
"type1" : {  
"properties" : {  
"field1" : { "type" : "text" }  
}  
}  
}  
}  
'  
{"acknowledged":true,"shards\_acknowledged":true,"index":"test"}[root@node1 ~]#

And now insert data after defining mapping  
[root@node1 ~]# curl -X PUT "localhost:9200/test/type1/1?" -H 'Content-Type: application/json' -d'

> {  
> "title": "User2-Document6"  
> }  
> '

Is my understanding correct ?? I read mapping related information in the official site but not very clear .  
Kindly help me understand the same .  
Any leads would be highly appreciable !!

Thanks,  
R\_C

---

<div class="post-metadata">

**Author:** ![tdasch](https://avatars.discourse-cdn.com/v4/letter/t/58f4c7/32.png) [@tdasch](https://discuss.elastic.co/u/tdasch)\
**Post date:** [June 4, 2018, 1:44pm UTC](https://discuss.elastic.co/t/not-able-to-understand-the-mapping-in-elasticsearch/134388/2 "2018-06-04T13:44:10Z")

</div>

Hey Roshni,

With your first example,

> PUT twitter/user/xyz  
> {  
> "name": "ABC"  
> }

you get a mapping of,

> ```
> "twitter": {
> "mappings": {
> "user": {
> "properties": {
> "name": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> 
> ```

ES has turned your name field into both text and keyword (look at [multi-fields](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-fields.html)). Text gets run through an analyzer and keyword is the source.

With your second example, you are correct, you are using Explicit Mapping. You are setting up a mapping type of type1 with properties. field1 is where you should specify the field name.

In your example

```
> PUT test
> {
> "mappings": {
> "type1": {
> "properties": {
> "field1": {
> "type": "text"
> }
> }
> }
> }
> }

```

If you insert your data

> PUT test/type1/1  
> {  
> "title": "User2-Document6"  
> }

The result of your mapping if you run

> GET test/\_mapping/type1

will be

```
> {
> "test": {
> "mappings": {
> "type1": {
> "properties": {
> "field1": {
> "type": "text"
> },
> "title": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> }
> 

```

Which I don't think was your intention. Your now have mapping for `type1` and `title` You probably wanted just the title type. So you could have done the following

```
> PUT test
> {
> "mappings": {
> "type1": {
> "properties": {
> "title": {
> "type": "text"
> }

```

> PUT test/type1/1  
> {  
> "title": "User2-Document6"  
> }

And then a GET test/\_mapping/type1 would produce the following

```
> {
> "test": {
> "mappings": {
> "type1": {
> "properties": {
> "title": {
> "type": "text"
> }

```

Which I think was your intended result, maybe? A good read is [here](https://www.elastic.co/guide/en/elasticsearch/guide/2.x/mapping-analysis.html). Hope this helps!

---

<div class="post-metadata">

**Author:** ![roshni](https://avatars.discourse-cdn.com/v4/letter/r/ce7236/32.png) [@roshni](https://discuss.elastic.co/u/roshni)\
**Post date:** [June 5, 2018, 10:14am UTC](https://discuss.elastic.co/t/not-able-to-understand-the-mapping-in-elasticsearch/134388/3 "2018-06-05T10:14:35Z")

</div>

thanks .. that was much help ... !! require some more insight on indexing types :analysed, not\_analysed and default

And also what is the exact role of keyword !!

## Case 1

curl -X PUT "localhost:9200/elasticsearch\_data" -H 'Content-Type: application/json' -d'  
{  
"mappings": {  
"user" : {  
"properties" : {  
"text" : {  
"type" : "string",  
"analyzer": "standard"  
}  
}  
}  
}  
}

## And inserted same data 5 times (5 docs ) curl -X PUT "localhost:9200/elasticsearch\_data/user/1?" -H 'Content-Type: application/json' -d' { "text": "This is a string only " } ' Case 2

curl -X PUT "localhost:9200/elasticsearch\_data\_notanalyzed" -H 'Content-Type: application/json' -d'  
{  
"mappings": {  
"user" : {  
"properties" : {  
"text" : {  
"type" : "string",  
"index" : "not\_analyzed"  
}  
}  
}  
}  
}  
'

And inserted data 5 times (same as above )

curl -X PUT "localhost:9200/elasticsearch\_data\_notanalyzed/user/1?" -H 'Content-Type: application/json' -d'  
{  
"text": "This is a string only "  
}  
'

Case 3:  
Automatic mapping

curl -X PUT "localhost:9200/elasticsearch/user/5?" -H 'Content-Type: application/json' -d'  
{  
"text": "This is a string only "  
}  
'

(inserted 5 docs with same data )

# Memory Status

[root@node1 ~]# curl -X GET "localhost:9200/\_cat/indices?v"  
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
yellow open elasticsearch\_data\_notanalyzed HaTktqKVRVCS6cxeCg1sUg 5 1 5 0 14.2kb 14.2kb  
yellow open elasticsearch\_data Z8SkXvZwTNqaYVzXickCdA 5 1 5 0 14.2kb 14.2kb  
yellow open elasticsearch tT\_gYO4dRPa3AlOutylN9g 5 1 5 0 17.1kb 17.1kb

It seems for the last case it takes more storage space for same data .  
Can you please help me analyze the reason for this observation

Thanks and regards,  
Roshni

---

<div class="post-metadata">

**Author:** ![tdasch](https://avatars.discourse-cdn.com/v4/letter/t/58f4c7/32.png) [@tdasch](https://discuss.elastic.co/u/tdasch)\
**Post date:** [June 5, 2018, 12:08pm UTC](https://discuss.elastic.co/t/not-able-to-understand-the-mapping-in-elasticsearch/134388/4 "2018-06-05T12:08:42Z")

</div>

I'm glad that was helpful! I'll do my best to try and answer your other questions.

`String` types are automatically analyzed as multi-fields by ES. The default analyzer is the [Standard Analyzer](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-standard-analyzer.html#analysis-standard-analyzer). The two multi-field types are `text`, which by default uses the standard tokenizer to divide the text into tokens for the inverted index, and the other type is `keyword` which is not analyzed. `keyword` is the exact text that was put into ES. There is an older blog post [here](https://www.elastic.co/blog/strings-are-dead-long-live-strings) that could benefit you by explaining why Elastic made the switch to multi-fields for `string` types.

Having your data stored as `text` allows full-text search. Having your data stored as `keyword` allows keyword searches and aggregations to be performed.

Regarding your last question about the difference in the index sizes, I don't know.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2018, 12:08pm UTC](https://discuss.elastic.co/t/not-able-to-understand-the-mapping-in-elasticsearch/134388/5 "2018-07-03T12:08:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
