# Problem with analyzed fields in indexes

**URL:** https://discuss.elastic.co/t/problem-with-analyzed-fields-in-indexes/1330
**Category:** Logstash
**Created:** [May 26, 2015, 5:02pm UTC](https://discuss.elastic.co/t/problem-with-analyzed-fields-in-indexes/1330 "2015-05-26T17:02:12Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![paul](https://avatars.discourse-cdn.com/v4/letter/p/bbe5ce/32.png) [@paul](https://discuss.elastic.co/u/paul)
#### Post date: [May 26, 2015, 5:02pm UTC](https://discuss.elastic.co/t/problem-with-analyzed-fields-in-indexes/1330/1 "2015-05-26T17:02:13Z")

</div>

I am trying to stop the field 'host' from being set to analyzed. Even when I can get it to say 'false' in the index description, it is still pulling apart the hostnames using '.' as a separator. I am using logstash 1.4.2 and kibana 4.0.2. I have tried using a json template for my index and setting host index to not\_analyzed, but that isn't working. I am new to ELK, so any help is appreciated.

---

<div class="post-metadata">

### Author: ![Ron\_Kass](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ron_kass/32/20427_2.png) [@Ron\_Kass](https://discuss.elastic.co/u/Ron_Kass)
#### Post date: [May 26, 2015, 6:36pm UTC](https://discuss.elastic.co/t/problem-with-analyzed-fields-in-indexes/1330/2 "2015-05-26T18:36:59Z")

</div>

to have a field set to be not analyzed you define it this way...

```
"host": {"type":"string", "index":"not_analyzed"}

```

If that doesn't work for you, it is best if you paste here the mapping you are trying to use, and a sample document you are trying to index.

---

<div class="post-metadata">

### Author: ![tylerjl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylerjl/32/44965_2.png) [@tylerjl](https://discuss.elastic.co/u/tylerjl)
#### Post date: [May 26, 2015, 7:03pm UTC](https://discuss.elastic.co/t/problem-with-analyzed-fields-in-indexes/1330/3 "2015-05-26T19:03:49Z")

</div>

If you are using the default logstash index template, it configures a `.raw` non-analyzed field for each field that elasticsearch sees. If you use that template, check for whether that field exists - if you're using your own template, you can reference the [logstash index tempalte](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template.json) for an example of how to do it in your own template.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/problem-with-analyzed-fields-in-indexes/1330/4 "2017-07-06T05:39:20Z")

</div>


