# Problem creating custom analyzer

**URL:** <https://discuss.elastic.co/t/problem-creating-custom-analyzer/129257>\
**Category:** Elasticsearch\
**Created:** [April 24, 2018, 8:16am UTC](https://discuss.elastic.co/t/problem-creating-custom-analyzer/129257 "2018-04-24T08:16:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AccordISSupport](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@AccordISSupport](https://discuss.elastic.co/u/AccordISSupport)\
**Post date:** [April 24, 2018, 8:16am UTC](https://discuss.elastic.co/t/problem-creating-custom-analyzer/129257/1 "2018-04-24T08:16:46Z")

</div>

Hi,

I have ELK stack receiving logs from Winlogbeat but I have a problem whereby the standard analyzer is being used to process the fields and the text field 'event\_data.TargetUserName' sometimes contains a $ as it sometimes contains a machine name, which I want to filter out, but the standard analyzer strips the $ so I can't then filter it in Kibana.

As this ELK is only receiving logs from Winlogbeat, I am trying to make a custom analyzer in a template that applies to all indices, that will leave the text in the field alone and pass it all through, allowing me to filter on $.

When I create the template with just the custom analyzer in it like this:

```
{
  "template": "*",
  "settings": {
               "number_of_shards": 2,
               "number_of_replicas": 1,
               "analysis": {
                        "analyzer": {
		                     "TargetUserNameAnalyzer": {
    		    		                		"type": "custom",
    			    			                "tokenizer": "keyword"
					          	       }
		                    }
                           }
              }
}

```

it obviously doesn't change anything but the template is accepted and I still get data from Winlogbeat.

If I then try it by adding in a custom mapping to apply that analyzer to the field, the indices are created in ES but they are all empty:

```
green open winlogbeat-6.2.4-2015.08 mUyYiNtFRZqItBVeiC7l0Q 2 1 0 0 920b 460b
green open winlogbeat-6.2.4-2014.08 dHcEBwiIQ32H8pNkNL3N9Q 2 1 0 0 920b 460b
green open winlogbeat-6.2.4-2017.01 5SM0gqNlQUWVaPUOspCP5A 2 1 0 0 920b 460b
green open winlogbeat-6.2.4-2016.09 jwzvvQjpTaKMugAIOyU_xg 2 1 0 0 920b 460b
green open winlogbeat-6.2.4-2012.11 fzQE_Sv4Te2b9jv25lbB3A 2 1 0 0 920b 460b
green open winlogbeat-6.2.4-2011.10 V4Nj7QsYSgiWflMCAED3_Q 2 1 0 0 920b 460b
green open winlogbeat-6.2.4-2014.06 ZPzx5FsiTXKqgH3Zlzd1Ag 2 1 0 0 920b 460b
green open winlogbeat-6.2.4-2015.12 M0McqzKERDyPw1QwdC7PZA 2 1 0 0 920b 460b
green open winlogbeat-6.2.4-2013.03 SUSpwm0rRn-0eJGxWKPdKw 2 1 0 0 920b 460b

```

I've have tried every permutation of mapping I can find and it behaves exactly the same. This is my latest template:

```
{
  "template": "*",
  "settings": {
               "number_of_shards": 2,
               "number_of_replicas": 1,
               "analysis": {
                            "analyzer": {
		                         "TargetUserNameAnalyzer": {
    		               	    	         		    "type": "custom",
    				         		            "tokenizer": "keyword"
					           	           }
		                        }
                           }
              },
  "mappings": {
               "_doc": {
                        "dynamic_templates": [
	    			             {
                                              "TargetUserNameField": {
                                                                      "match_mapping_type": "string",
                                                                      "match": "event_data.TargetUserName",
                                                                      "mapping": {
                                                                                  "type": "text",
                                                                                  "analyzer": "TargetUserNameAnalyzer"
                                                                                 }
                                                                     }
                                             }
				             ]
                       }
              }
}

```

I have tried this without a match\_mapping\_type and also used the whitespace tokenizer, all to no avail.

Can anyone see what the problem is?

Thanks.

---

<div class="post-metadata">

**Author:** ![AccordISSupport](https://avatars.discourse-cdn.com/v4/letter/a/e9a140/32.png) [@AccordISSupport](https://discuss.elastic.co/u/AccordISSupport)\
**Post date:** [April 26, 2018, 7:25am UTC](https://discuss.elastic.co/t/problem-creating-custom-analyzer/129257/2 "2018-04-26T07:25:43Z")

</div>

Being as everybody is obviously stumped by this I've found a simple solution:

I can't filter special characters on the 'event\_data.TargetUserName' field without ridiculous messing about but I CAN filter on special characters using the 'event\_data.TargetUserName._keyword_' field, which for some reason took quite a while to appear in the index pattern. Maybe I didn't refresh enough!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2018, 7:29am UTC](https://discuss.elastic.co/t/problem-creating-custom-analyzer/129257/3 "2018-05-24T07:29:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
