# Problem with raw field

**URL:** <https://discuss.elastic.co/t/problem-with-raw-field/28841>\
**Category:** Kibana\
**Created:** [September 8, 2015, 1:53pm UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841 "2015-09-08T13:53:49Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![peterbergman](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@peterbergman](https://discuss.elastic.co/u/peterbergman)\
**Post date:** [September 8, 2015, 1:53pm UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/1 "2015-09-08T13:53:49Z")

</div>

Hi,

I have a problem using a raw field for term aggregation in a data table visualization. Whenever I try to view the data for a specific raw field used in a search through the visualization, I get no results. However, if I use the same search in Discover, I get back a result with entries and the raw field that I wanted to show in the visualization is populated correctly.

Any ideas to why the raw field data isn't showing up in the visualization?

---

<div class="post-metadata">

**Author:** ![Pieter\_Agenbag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pieter_agenbag/32/4562_2.png) [@Pieter\_Agenbag](https://discuss.elastic.co/u/Pieter_Agenbag)\
**Post date:** [September 8, 2015, 3:19pm UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/2 "2015-09-08T15:19:02Z")

</div>

Can you post a screenshot of your visualization configuration /query ?

> [@peterbergman](#):
>
> using a raw field for term aggregation

I'm assuming you mean you have a .raw not\_analyzed mapping that you are using in your datatable ?  
And this shows no results ?  
You are linking this visualization to a saved search that Does yield results ?

---

<div class="post-metadata">

**Author:** ![peterbergman](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@peterbergman](https://discuss.elastic.co/u/peterbergman)\
**Post date:** [September 9, 2015, 7:09am UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/3 "2015-09-09T07:09:34Z")

</div>

Sure, see attached images.

Correct, I mean a .raw field.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/0084cdae3b99653c842f3187d327c827e84a7932.png) ![](https://us1.discourse-cdn.com/elastic/original/2X/4/4f8b766c9197b1126c46bcc68c69a4958b0ed7ae.png)

---

<div class="post-metadata">

**Author:** ![Pieter\_Agenbag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pieter_agenbag/32/4562_2.png) [@Pieter\_Agenbag](https://discuss.elastic.co/u/Pieter_Agenbag)\
**Post date:** [September 9, 2015, 7:42am UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/4 "2015-09-09T07:42:32Z")

</div>

That is rather befalling... the only reason I can think of , is that there is some kind of disconnect between your raw and analyzed field (that you are seeing in Discover page). Maybe a mapping error ?

On Discover; In the left pane , click in the settings (gear) next to Available Fields and uncheck the "Hide Missing Fields".  
Now find your detailedLogMessage.raw and click on it.

It will display something like

> This field is present in your elasticsearch mapping but not in any documents in the search results. You may still be able to visualize or search on it.

Click on the Visualize button just below the warning. Do you get any results back for that ?

---

<div class="post-metadata">

**Author:** ![peterbergman](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@peterbergman](https://discuss.elastic.co/u/peterbergman)\
**Post date:** [September 9, 2015, 10:16am UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/5 "2015-09-09T10:16:06Z")

</div>

I followed the steps that you suggested and sure enough, I got the message that you described. However, when I click the Visualize button, no results are found.

---

<div class="post-metadata">

**Author:** ![Pieter\_Agenbag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pieter_agenbag/32/4562_2.png) [@Pieter\_Agenbag](https://discuss.elastic.co/u/Pieter_Agenbag)\
**Post date:** [September 9, 2015, 10:19am UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/6 "2015-09-09T10:19:21Z")

</div>

Then there must be something wrong with your .raw mapping.  
Although I would have thought the field would be missing completely if the mapping was wrong :-/

Can you find and paste the mapping for the index ?

---

<div class="post-metadata">

**Author:** ![peterbergman](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@peterbergman](https://discuss.elastic.co/u/peterbergman)\
**Post date:** [September 9, 2015, 12:22pm UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/7 "2015-09-09T12:22:15Z")

</div>

Here is the mapping for that specific field:

```
"detailedLogMessage": {
  "type": "string",
  "norms": {
    "enabled": false
  },
  "fields": {
    "raw": {
      "type": "string",
      "index": "not_analyzed",
      "ignore_above": 256
    }
  }
}

```

Could it be the `ignore_above` property that causes issues? I just checked and the strings that doesn't show up in the visulization are indeed longer than 256 characters.

---

<div class="post-metadata">

**Author:** ![Pieter\_Agenbag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pieter_agenbag/32/4562_2.png) [@Pieter\_Agenbag](https://discuss.elastic.co/u/Pieter_Agenbag)\
**Post date:** [September 9, 2015, 12:49pm UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/8 "2015-09-09T12:49:39Z")

</div>

Yes, that seems to be the case. I initially thought ignore\_above ignores the bits of text longer than specified value (i.e. truncates down to the specified length) - but in reality (and according to the [docs](https://www.elastic.co/guide/en/elasticsearch/reference/1.6/mapping-core-types.html#string)) the value is completely ignored if above that length.

See this thread.

> [@String mapping: ignore\_above for not\_analyzed fields](https://discuss.elastic.co/t/string-mapping-ignore-above-for-not-analyzed-fields/26511):
>
> I have some string fields in ES with mappings like so: { "index": "analyzed", "type": "string", "fields": { "raw": { "index": "not\_analyzed", "ignore\_above": 256, "type": "string", "doc\_values": true } } } From [the docs](https://www.elastic.co/guide/en/elasticsearch/reference/1.6/mapping-core-types.html#string "the docs"), for the ignore\_above setting: The analyzer will ignore strings larger than this size. Useful for generic not\_analyzed fields that should ignore long text. What exactly does this mean? If my field is 257 characters, will the field.raw not be searchable…

😮 - I'll have to go review all My mappings now.

---

<div class="post-metadata">

**Author:** ![peterbergman](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@peterbergman](https://discuss.elastic.co/u/peterbergman)\
**Post date:** [September 9, 2015, 12:59pm UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/9 "2015-09-09T12:59:09Z")

</div>

Thanks a lot for helping out getting to the bottom with this. I also thought that it would just truncate the string but now its quite clear why I am missing some values in the reports...

---

<div class="post-metadata">

**Author:** ![peterbergman](https://avatars.discourse-cdn.com/v4/letter/p/919ad9/32.png) [@peterbergman](https://discuss.elastic.co/u/peterbergman)\
**Post date:** [September 9, 2015, 1:10pm UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/10 "2015-09-09T13:10:47Z")

</div>

Follow up question: the index is created by Logstash, can I somehow control the `ignore_above` for specific fields?

Edit: Changed the property in the index template used by logstash which solved the problem.

---

<div class="post-metadata">

**Author:** ![Pieter\_Agenbag](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pieter_agenbag/32/4562_2.png) [@Pieter\_Agenbag](https://discuss.elastic.co/u/Pieter_Agenbag)\
**Post date:** [September 9, 2015, 1:39pm UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/11 "2015-09-09T13:39:00Z")

</div>

If the mapping specifies `ignore_above` then there's not much you can do afterwards to rectify the situation.  
Kibana only displays whats already indexed by elasticsearch.

Unfortunately I have no experience with logstash (I index my documents directly from my own c++ program) - but I'm sure you should be able to change the way logstash maps the index... maybe ask the question in the logstash group ?

---

<div class="post-metadata">

**Author:** ![augustman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/augustman/32/16676_2.png) [@augustman](https://discuss.elastic.co/u/augustman)\
**Post date:** [November 21, 2015, 7:31am UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/12 "2015-11-21T07:31:10Z")

</div>

How you get so many properties for mapping for a field ?

My mapping only looks like this

> GET [http://localhost:9200/logindex/\_mapping/logtype/field/host?pretty](http://localhost:9200/logindex/_mapping/logtype/field/host?pretty)  
> {  
> "logindex" : {  
> "mappings" : {  
> "logtype" : {  
> "host" : {  
> "full\_name" : "host",  
> "mapping" : {  
> "host" : {  
> "type" : "string"  
> }  
> }  
> }  
> }  
> }  
> }  
> }

How "norms" and "fields" show up in yours and not mine. I push my logs to ES using logstash only. Why my mapping looks different. because of this I am not able to follow some posts. Are you using some other endpoint ?  
any help appreciated.  
thanks

---

<div class="post-metadata">

**Author:** ![ayasha88](https://avatars.discourse-cdn.com/v4/letter/a/d6d6ee/32.png) [@ayasha88](https://discuss.elastic.co/u/ayasha88)\
**Post date:** [December 2, 2015, 3:05pm UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/13 "2015-12-02T15:05:02Z")

</div>

Hi

I have the same problem but my ignore\_above is only 2

`"page": { "type": "string", "norms": { "enabled": false }, "fields": { "raw": { "type": "string", "index": "not_analyzed", "ignore_above": 2 } } },`

why is that?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:07pm UTC](https://discuss.elastic.co/t/problem-with-raw-field/28841/14 "2017-07-06T14:07:36Z")

</div>


