# Prefix query on fields mapped as keyword

**URL:** https://discuss.elastic.co/t/prefix-query-on-fields-mapped-as-keyword/355111
**Category:** Elastic Search
**Tags:** elastic-app-search
**Created:** [March 11, 2024, 1:04am UTC](https://discuss.elastic.co/t/prefix-query-on-fields-mapped-as-keyword/355111 "2024-03-11T01:04:28Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![india](https://avatars.discourse-cdn.com/v4/letter/i/b487fb/32.png) [@india](https://discuss.elastic.co/u/india)
#### Post date: [March 11, 2024, 1:04am UTC](https://discuss.elastic.co/t/prefix-query-on-fields-mapped-as-keyword/355111/1 "2024-03-11T01:04:28Z")

</div>

Hello,  
I use Elasticsearch version 7.17.  
In a Elasticsearch blog post ( [Find strings within strings faster with the Elasticsearch wildcard field | Elastic Blog](https://www.elastic.co/blog/find-strings-within-strings-faster-with-the-new-elasticsearch-wildcard-field) ) it's mentioned that `keyword` fields can offer better performance for prefix queries compared to `wildcard` fields. However, I couldn't find direct confirmation of this in the official Elasticsearch docs.  
Are `keyword` fields indeed optimized for prefix searches? If so, which query type should be used when searching by the beginning of a string in `keyword` fields: prefix query, wildcard query?  
Thanks

---

<div class="post-metadata">

### Author: ![Kathleen\_DeRusso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kathleen_derusso/32/132039_2.png) [@Kathleen\_DeRusso](https://discuss.elastic.co/u/Kathleen_DeRusso)
#### Post date: [March 11, 2024, 12:17pm UTC](https://discuss.elastic.co/t/prefix-query-on-fields-mapped-as-keyword/355111/2 "2024-03-11T12:17:09Z")

</div>

I think the blog post does a good job of explaining what is happening and why.

If you need more information, you can check out [issues and discussions that have been raised in Github](https://github.com/elastic/elasticsearch/issues/48852). If you still want to go even further to answer questions about your specific use case you can check out [Rally](https://esrally.readthedocs.io/en/stable/index.html) to run benchmarking against your use cases.

---

<div class="post-metadata">

### Author: ![india](https://avatars.discourse-cdn.com/v4/letter/i/b487fb/32.png) [@india](https://discuss.elastic.co/u/india)
#### Post date: [April 1, 2024, 1:22pm UTC](https://discuss.elastic.co/t/prefix-query-on-fields-mapped-as-keyword/355111/3 "2024-04-01T13:22:43Z")

</div>

Thank you for your reply.  
I have another question related to this topic.

I have a mapping for an index `test_index` as follows:

```auto
{
  "mappings": {
    "properties": {
      "field1": { "type": "keyword" }
    }
  }
}

```

I have disabled expensive queries by setting `search.allow_expensive_queries` to `false` . When running a prefix query against `field1` , which is of type `keyword` , like this:

```auto
GET test_index/_search 
{"query": {"bool": {"filter": [
  {"prefix": {
    "field1": "test"
  }}
]}}
}

```

I received the following error message:

```auto
    "root_cause" : [
      {
        "type" : "exception",
        "reason" : "[prefix] queries cannot be executed when 'search.allow_expensive_queries' is set to false. For optimised prefix queries on text fields please enable [index_prefixes]."
      }
    ]

```

I'm puzzled by this error because my query targets a `keyword` field, not a `text` field, and `index_prefixes` is not applicable to `keyword` fields. Can you help me understand why this error is occurring and how to resolve it?

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [April 1, 2024, 1:35pm UTC](https://discuss.elastic.co/t/prefix-query-on-fields-mapped-as-keyword/355111/4 "2024-04-01T13:35:43Z")

</div>

> [@india](#):
>
> I have disabled expensive queries by setting `search.allow_expensive_queries` to `false` .

You need to enable it if you want to use prefix queries on keyword fields as mentioned in the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl.html).

> prefix queries (except on wildcard fields or those without index\_prefixes)

Running a `prefix` query on a field that is not a `wildcard` field or a `text` field with `index_prefixes` needs to have `search.allow_expensive_queries` set as `true`.

---

<div class="post-metadata">

### Author: ![india](https://avatars.discourse-cdn.com/v4/letter/i/b487fb/32.png) [@india](https://discuss.elastic.co/u/india)
#### Post date: [April 21, 2024, 9:15am UTC](https://discuss.elastic.co/t/prefix-query-on-fields-mapped-as-keyword/355111/5 "2024-04-21T09:15:17Z")

</div>

So, prefix queries against keyword fields are considered expensive. However, the article I referenced in my initial post ( [Find strings within strings faster with the Elasticsearch wildcard field | Elastic Blog](https://www.elastic.co/blog/find-strings-within-strings-faster-with-the-new-elasticsearch-wildcard-field) ) describes prefix queries on keyword fields as 'fast' and on wildcard fields as 'not quite as fast'. This appears contradictory.

Why there is such a discrepancy in the performance descriptions of prefix queries on keyword fields? Is there a specific context or configuration where prefix queries on keyword fields can indeed perform efficiently?

Additionally, I am curious about why the index\_prefixes option is not available for keyword fields, whereas it is available for text fields. What is the technical reason behind this?

Thank you for any insights or clarifications.

---

<div class="post-metadata">

### Author: ![Kathleen\_DeRusso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kathleen_derusso/32/132039_2.png) [@Kathleen\_DeRusso](https://discuss.elastic.co/u/Kathleen_DeRusso)
#### Post date: [April 24, 2024, 6:59pm UTC](https://discuss.elastic.co/t/prefix-query-on-fields-mapped-as-keyword/355111/6 "2024-04-24T18:59:53Z")

</div>

You can [speed up](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-prefix-query.html#prefix-query-index-prefixes) prefix queries using index mappings. It will be faster than straight up wildcard search.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 22, 2024, 7:00pm UTC](https://discuss.elastic.co/t/prefix-query-on-fields-mapped-as-keyword/355111/7 "2024-05-22T19:00:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
