# Not analyzing string data

**URL:** <https://discuss.elastic.co/t/not-analyzing-string-data/27574>\
**Category:** Logstash\
**Created:** [August 18, 2015, 9:43am UTC](https://discuss.elastic.co/t/not-analyzing-string-data/27574 "2015-08-18T09:43:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tibo](https://avatars.discourse-cdn.com/v4/letter/t/439d5e/32.png) [@Tibo](https://discuss.elastic.co/u/Tibo)\
**Post date:** [August 18, 2015, 9:43am UTC](https://discuss.elastic.co/t/not-analyzing-string-data/27574/1 "2015-08-18T09:43:27Z")

</div>

Hi,

I'm having an issue with elasticsearch splitting words from my "request" field. I have found some clues about analyzed and not\_analyze field that would do what I want : searching my whole sentence.

So when I get my mapping :  
curl -XGET '[http://localhost:9200/pglog/\_mapping/logs](http://localhost:9200/pglog/_mapping/logs)'  
{"pglog":{"mappings":{"logs":{"properties":{"@timestamp":{"type":"date","format":"dateOptionalTime"},"@version":{"type":"string"},"contenu":{"type":"string"},"database":{"type":"string"},"date":{"type":"string"},"datestamp":{"type":"string"},"duration":{"type":"long"},"host":{"type":"string"},"message":{"type":"string"},"path":{"type":"string"}, **"request":{"type":"string"}** ,"tags":{"type":"string"}}}}}}

The "request" field does not have an "index" value, so I can't assign it to "not\_analyzed"

curl -XPUT [http://localhost:9200/pglog/\_mapping/logs](http://localhost:9200/pglog/_mapping/logs) -d'{

> "logs": {  
> "properties": {  
> "request": {  
> "type": "string",  
> "index": "not\_analyzed"  
> }  
> }  
> }  
> }'  
> {"error":"MergeMappingException[Merge failed with failures {[mapper [request] has different index values, mapper [request] has different tokenize values, mapper [request] has different index\_analyzer]}]","status":400}

And I'm getting this field from a grok match filter :  
grok {  
match =\> ["contenu", " db=%{DATA:database},user=%{DATA} duration: %{NUMBER:duration} ms %{GREEDYDATA:request}"]  
}

Is there a way to say to Logstash that I want this field to be "not\_analyzed" ? Or something else ?

Thibaut

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 18, 2015, 11:31pm UTC](https://discuss.elastic.co/t/not-analyzing-string-data/27574/2 "2015-08-18T23:31:58Z")

</div>

You need to do that in Elasticsearch by specifying a mapping for the field before it leaves LS.  
LS is just a "dumb" pipeline in that regards.

---

<div class="post-metadata">

**Author:** ![Tibo](https://avatars.discourse-cdn.com/v4/letter/t/439d5e/32.png) [@Tibo](https://discuss.elastic.co/u/Tibo)\
**Post date:** [August 19, 2015, 9:30am UTC](https://discuss.elastic.co/t/not-analyzing-string-data/27574/3 "2015-08-19T09:30:01Z")

</div>

Ok I got it thanks. My curl request to modify the field index to not\_analyzed was good, but was supposed to be executed before any data is saved on Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:31am UTC](https://discuss.elastic.co/t/not-analyzing-string-data/27574/4 "2017-07-06T05:31:35Z")

</div>


