# \*.raw fields

**URL:** <https://discuss.elastic.co/t/raw-fields/29943>\
**Category:** Kibana\
**Created:** [September 24, 2015, 8:49pm UTC](https://discuss.elastic.co/t/raw-fields/29943 "2015-09-24T20:49:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![treehouse](https://avatars.discourse-cdn.com/v4/letter/t/e9a140/32.png) [@treehouse](https://discuss.elastic.co/u/treehouse)\
**Post date:** [September 24, 2015, 8:49pm UTC](https://discuss.elastic.co/t/raw-fields/29943/1 "2015-09-24T20:49:30Z")

</div>

This question is similar to [https://discuss.elastic.co/t/kibana-this-field-is-present-in-your-elasticsearch-mapping-but-not-in-any-documents-in-the-search-results-you-may-still-be-able-to-visualize-or-search-on-it/25903](https://discuss.elastic.co/t/kibana-this-field-is-present-in-your-elasticsearch-mapping-but-not-in-any-documents-in-the-search-results-you-may-still-be-able-to-visualize-or-search-on-it/25903)

So all of the .raw fields in a particular index are hidden by default because Kibana thinks they don't show up in any document. Reference:

![](https://us1.discourse-cdn.com/elastic/original/2X/e/efb15ac42600fb8d0980d55d2c065abba3eb0ed8.png)

If I click on visualize here (I persist the same datetime range filter and any other filters/searches that currently apply), i see something like this

 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/0deb29e60f33d3cd59ec3faa9c8b0c58671a63ac.png)

So it seems like there is something in the clientip.raw field.

I checked out the mapping for this index and came across this (this may be getting into an Elasticsearch question, so direct me there if you must)

> ```
> "clientip": {
> "type": "string",
> "norms": {
> "enabled": false
> },
> "fields": {
> "raw": {
> "type": "string",
> "index": "not_analyzed",
> "ignore_above": 256
> }
> }
> } 
> 
> ```

So it seems like clientip.raw is not a completely new field, is it like a computed field that doesn't exist explicitly? The reason it as created is because in mappings =\> _default_ =\> we have this:

> ```
> {
> "string_fields": {
> "mapping": {
> "index": "analyzed",
> "omit_norms": true,
> "type": "string",
> "fields": {
> "raw": {
> "ignore_above": 256,
> "index": "not_analyzed",
> "type": "string"
> }
> }
> },
> "match": "*",
> "match_mapping_type": "string"
> }
> }
> 
> ```

So the question is, what exactly is going on here and how do I have \*.raw fields show up in the Kibana Discovery tab as a field?

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [September 26, 2015, 4:55am UTC](https://discuss.elastic.co/t/raw-fields/29943/2 "2015-09-26T04:55:13Z")

</div>

The way Kibana works right now, you can't get \*.raw fields show up in Discover. Discover only shows fields that are present in the \_source: [https://github.com/elastic/kibana/issues/1791](https://github.com/elastic/kibana/issues/1791)

\*.raw fields are mapped as a "multi field", so it is just another type mapped to the same value: [https://www.elastic.co/guide/en/elasticsearch/reference/0.90/mapping-multi-field-type.html](https://www.elastic.co/guide/en/elasticsearch/reference/0.90/mapping-multi-field-type.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:12pm UTC](https://discuss.elastic.co/t/raw-fields/29943/3 "2017-07-06T14:12:29Z")

</div>


