# Not\_analyzed field with doc\_values still in fielddata cache

**URL:** <https://discuss.elastic.co/t/not-analyzed-field-with-doc-values-still-in-fielddata-cache/26298>\
**Category:** Elasticsearch\
**Created:** [July 26, 2015, 3:44am UTC](https://discuss.elastic.co/t/not-analyzed-field-with-doc-values-still-in-fielddata-cache/26298 "2015-07-26T03:44:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [July 26, 2015, 3:44am UTC](https://discuss.elastic.co/t/not-analyzed-field-with-doc-values-still-in-fielddata-cache/26298/1 "2015-07-26T03:44:38Z")

</div>

During some experiment with [fielddata vs doc\_values](https://www.elastic.co/blog/support-in-the-wild-my-biggest-elasticsearch-problem-at-scale) I encountered a weird case. In my earlier mapping, I didn't use doc values at all. In my new mapping, I've added `doc_values: true` to all fields in my mapping, except analyzed string fields and booleans ([not supported until 2.0](https://github.com/elastic/elasticsearch/issues/7851)).

So in details, here is how I proceeded:

Before reindexing all my data, I restarted my ES 1.7 cluster fresh and ran a query with sorting, aggregations and script fields to "warm up" the fielddata cache. Then I queried the `/fielddata` endpoint to have an idea of the fielddata cache usage. It looked something like this:

```
curl -XGET 'localhost:9200/_cat/fielddata?v&fields=*'

id host ip node total items.desc.raw more_fields...
rKX7... myhost 192.168.1.100 Doom 32.9mb 2.3mb ...

```

As you can see, the field `items.desc.raw` used 2.3mb of heap space. `items` is of type `nested` and contains a string multi-field with a `not_analyzed` sub-field called `raw`. In short, the mapping of that nested field looks like this:

```
    "items": {
      "type": "nested",
      "properties": {
        "desc": {
          "type": "string",
          "fields": {
            "raw": {
              "type": "string",
              "index": "not_analyzed"
            }
          }
        }
      }
    }

```

After adding `doc_values: true` to `items.desc.raw`, reindexing the whole index and running some aggregations, sorting and scripting again to warm up the fielddata cache, I queried the `/fielddata` endpoint again and here was the result:

```
curl -XGET 'localhost:9200/_cat/fielddata?v&fields=*'

id host ip node total items.desc.raw some_bools...
tAB5... myhost 192.168.1.100 Yack 2.1mb 9.2kb ...

```

So the fielddata usage has indeed been drastically lowered (which is good), the only fields I see are boolean fields (i.e. `some_bools` above) which was expected, but to my surprise my nested `not_analyzed` string field also appeared, but with a much lower space usage.

What could be the cause of `items.desc.raw` still appearing in the fielddata cache?

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [July 27, 2015, 7:20am UTC](https://discuss.elastic.co/t/not-analyzed-field-with-doc-values-still-in-fielddata-cache/26298/2 "2015-07-27T07:20:24Z")

</div>

When using Doc Values on a not\_analyzed String field you may still get some field data usage from [`global ordinals`](https://www.elastic.co/guide/en/elasticsearch/reference/current/fielddata-formats.html#_global_ordinals). This is a data structure that assigns a number (ordinal) to each term in the index for that field to save using excess memory by having multiple copies of the String value of the field when doing calculations. Global ordinals cannot be included in Doc Values as they need to be computed at query time by running over all the terms currently in the field assigning each a unique number. This would explain why you still see a small amount of field data usage even when you are using doc values for a not\_analyzed String field.

Hope that helps

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [July 27, 2015, 7:25am UTC](https://discuss.elastic.co/t/not-analyzed-field-with-doc-values-still-in-fielddata-cache/26298/3 "2015-07-27T07:25:41Z")

</div>

Thanks @colings86, that definitely helps indeed. Somehow I missed the global ordinals bit, but that all makes sense now. Thanks much again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:58pm UTC](https://discuss.elastic.co/t/not-analyzed-field-with-doc-values-still-in-fielddata-cache/26298/4 "2017-07-05T23:58:53Z")

</div>


