# Run not\_analyzed querries on index populated with Logstash

**URL:** <https://discuss.elastic.co/t/run-not-analyzed-querries-on-index-populated-with-logstash/84106>\
**Category:** Logstash\
**Created:** [April 30, 2017, 6:19am UTC](https://discuss.elastic.co/t/run-not-analyzed-querries-on-index-populated-with-logstash/84106 "2017-04-30T06:19:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![GuillaumeN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guillaumen/32/81960_2.png) [@GuillaumeN](https://discuss.elastic.co/u/GuillaumeN)\
**Post date:** [April 30, 2017, 6:19am UTC](https://discuss.elastic.co/t/run-not-analyzed-querries-on-index-populated-with-logstash/84106/1 "2017-04-30T06:19:38Z")

</div>

Hi,

I'm a newbie with the ELK stack and although I've extensively searched Google for this, I just can't find the solution to my problem.  
I'm running ELK 5.3 on RHEL 7.3.

I need to use the ELK stack to search in received syslogs. These syslogs are read from archive files, they are not received directly by logstash..  
The logs are loaded properly in elasticsearch but when I run searches with strings containing hyphens, I'm not getting the expected results. I'm loading the syslogs messages in an index named with the pattern: logstash-%{+YYYY.MM.dd}

So far, I've been able to determine that:

- Elasticsearch tokenizes search terms when they are separated by hyphens.
- When using logstash to load content to elasticsearch, using indexes named "logstash-\*" allows to use the default logstash elasticsearch template, which should include .raw fields, configured to allow not\_analyzed queries.
- message.raw was removed in 2014 from the default template.

Now I'm kinda stuck, I don't know what to try next to be able to do my searches.

Do you have any idea what I should do next?

Thanks!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 30, 2017, 10:11am UTC](https://discuss.elastic.co/t/run-not-analyzed-querries-on-index-populated-with-logstash/84106/2 "2017-04-30T10:11:55Z")

</div>

In Elasticsearch 5.x the `.raw` field has been replaced by a `.keyword` field that allows not-analysed queries.

---

<div class="post-metadata">

**Author:** ![GuillaumeN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guillaumen/32/81960_2.png) [@GuillaumeN](https://discuss.elastic.co/u/GuillaumeN)\
**Post date:** [May 1, 2017, 9:21pm UTC](https://discuss.elastic.co/t/run-not-analyzed-querries-on-index-populated-with-logstash/84106/4 "2017-05-01T21:21:52Z")

</div>

Thanks Christian!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2017, 9:33pm UTC](https://discuss.elastic.co/t/run-not-analyzed-querries-on-index-populated-with-logstash/84106/5 "2017-05-29T21:33:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
