# Only one analyzed field among a not\_analyzed index

**URL:** <https://discuss.elastic.co/t/only-one-analyzed-field-among-a-not-analyzed-index/63456>\
**Category:** Elasticsearch\
**Created:** [October 20, 2016, 12:18am UTC](https://discuss.elastic.co/t/only-one-analyzed-field-among-a-not-analyzed-index/63456 "2016-10-20T00:18:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pixelrebel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pixelrebel/32/14056_2.png) [@pixelrebel](https://discuss.elastic.co/u/pixelrebel)\
**Post date:** [October 20, 2016, 12:18am UTC](https://discuss.elastic.co/t/only-one-analyzed-field-among-a-not-analyzed-index/63456/1 "2016-10-20T00:18:20Z")

</div>

My index is not\_analyzed by default. However I want to analyze the hostname for case insensitive and partial matching.

I want to do the opposite of what most people do. Instead of creating a `.raw` field for analyzed strings, I want to create a `.anal` field for not\_analyzed fields matching "host" field name. I tried something like this in my template without any luck:

```auto
          "string_fields" : {
            "mapping" : {
              "fielddata" : {
                "format" : "disabled"
              },
              "index" : "not_analyzed",
              "omit_norms" : true,
              "type" : "string",
              "fields" : {
                "anal" : {
                  "index" : "analyzed",
                  "type" : "string"
                }
              }
            },
            "match_mapping_type" : "string",
            "match" : "host"
          }

```

---

<div class="post-metadata">

**Author:** ![pixelrebel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pixelrebel/32/14056_2.png) [@pixelrebel](https://discuss.elastic.co/u/pixelrebel)\
**Post date:** [October 20, 2016, 12:31am UTC](https://discuss.elastic.co/t/only-one-analyzed-field-among-a-not-analyzed-index/63456/2 "2016-10-20T00:31:12Z")

</div>

I figured out a solution:

```auto
{
  "order" : 1,
  "template": "myindex-*",
  "settings": {
    "index.refresh_interval": "5s"
  },
  "mappings": {
    "_default_": {
      "dynamic_templates": [
        {
          "base": {
            "mapping": {
              "index": "not_analyzed"
            },
            "match": "*",
            "match_mapping_type": "*"
          }
        }
      ]
    },
    "host_field": {
      "properties": {
        "host": {
          "type": "string",
          "fields": {
            "analyzed": {
              "type": "string",
              "index": "analyzed"
            }
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![pixelrebel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pixelrebel/32/14056_2.png) [@pixelrebel](https://discuss.elastic.co/u/pixelrebel)\
**Post date:** [October 20, 2016, 12:53am UTC](https://discuss.elastic.co/t/only-one-analyzed-field-among-a-not-analyzed-index/63456/3 "2016-10-20T00:53:18Z")

</div>

So this doesn't work, even though the `host` field is not\_analyzed. Aggs are still splitting `my-host` into separate `my` and `host` aggregations. This should only happen when I bucket `host.analyzed` not `host`. What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [October 21, 2016, 3:58pm UTC](https://discuss.elastic.co/t/only-one-analyzed-field-among-a-not-analyzed-index/63456/4 "2016-10-21T15:58:12Z")

</div>

[Dynamic templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-templates.html) allow you to define custom mappings that can be applied to **dynamically added fields** based on:

You already define `host` field statically, then it doesn't applied to `host` field. If you add `host2`, it has `index: not_analyzed`.  
You should add `"index": "not_analyzed"` to `host` field definition.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:10pm UTC](https://discuss.elastic.co/t/only-one-analyzed-field-among-a-not-analyzed-index/63456/5 "2017-07-05T22:10:30Z")

</div>


