# Search for any word without mappings using URI query

**URL:** <https://discuss.elastic.co/t/search-for-any-word-without-mappings-using-uri-query/107487>\
**Category:** Elasticsearch\
**Created:** [November 14, 2017, 5:22am UTC](https://discuss.elastic.co/t/search-for-any-word-without-mappings-using-uri-query/107487 "2017-11-14T05:22:57Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticuser1](https://avatars.discourse-cdn.com/v4/letter/e/a3d4f5/32.png) [@elasticuser1](https://discuss.elastic.co/u/elasticuser1)\
**Post date:** [November 14, 2017, 5:22am UTC](https://discuss.elastic.co/t/search-for-any-word-without-mappings-using-uri-query/107487/1 "2017-11-14T05:22:57Z")

</div>

Hi,

I am indexing very big json and it do not have mappings defined. My requirement is to search for any word in this json.

I have created nGram tokenizer like below -

```
{
  "index": {
    "index": "my_idx",
    "type": "my_type",
    "analysis": {
      "index_analyzer": {
        "my_index_analyzer": {
          "type": "custom",
          "tokenizer": "standard",
          "filter": [
            "lowercase",
            "mynGram"
          ]
        }
      },
      "search_analyzer": {
        "my_search_analyzer": {
          "type": "custom",
          "tokenizer": "standard",
          "filter": [
            "standard",
            "lowercase",
            "mynGram"
          ]
        }
      },
      "filter": {
        "mynGram": {
          "type": "nGram",
          "min_gram": 2,
          "max_gram": 50
        }
      }
    }
  }

```

}

When I do this query, it do not return anything.

http://es\_host:9200/apihub-\*/\_search?pretty=true&q=findByStatus

I think URI query looks into \_all field and it do not have ngrams..

Please suggest how to do this. Is there any other query I can use to search.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 14, 2017, 5:38am UTC](https://discuss.elastic.co/t/search-for-any-word-without-mappings-using-uri-query/107487/2 "2017-11-14T05:38:12Z")

</div>

You did not apply your analyzer to \_all field.

[https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-all-field.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-all-field.html)

---

<div class="post-metadata">

**Author:** ![elasticuser1](https://avatars.discourse-cdn.com/v4/letter/e/a3d4f5/32.png) [@elasticuser1](https://discuss.elastic.co/u/elasticuser1)\
**Post date:** [November 14, 2017, 5:58pm UTC](https://discuss.elastic.co/t/search-for-any-word-without-mappings-using-uri-query/107487/3 "2017-11-14T17:58:50Z")

</div>

Thanks @dadoonet. How do we apply analyzer to \_all field? I could not find online...

Is there any other best way to achieve my requirements?

Thanks

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [November 14, 2017, 6:13pm UTC](https://discuss.elastic.co/t/search-for-any-word-without-mappings-using-uri-query/107487/4 "2017-11-14T18:13:02Z")

</div>

> How do we apply analyzer to \_all field? I could not find online...

The link I gave you says:

> The \_all field is just a text field, and accepts the same parameters that other string fields accept, including **analyzer** , term\_vectors, index\_options, and store.

So like any normal text field.

> Is there any other best way to achieve my requirements?

I always prefer using `copy_to` feature. As explained in the same doc: [Mapping | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-all-field.html#custom-all-fields)

---

<div class="post-metadata">

**Author:** ![elasticuser1](https://avatars.discourse-cdn.com/v4/letter/e/a3d4f5/32.png) [@elasticuser1](https://discuss.elastic.co/u/elasticuser1)\
**Post date:** [November 14, 2017, 7:14pm UTC](https://discuss.elastic.co/t/search-for-any-word-without-mappings-using-uri-query/107487/5 "2017-11-14T19:14:32Z")

</div>

Thanks again. I tried like this but getting "Field [\_all] is defined twice in [main]" error..

```
curl -XPUT 'es_host:9200/_template/sapihub_template?pretty' -H 'Content-Type: application/json' -d'
{
  "template": "sapihub-*",
  "settings": {
  "index": {
    "number_of_shards": 1,
    "number_of_replicas" : 2,
	"mapping.total_fields.limit": 4000	
  },
  "analysis": {
      "index_analyzer": {
        "my_index_analyzer": {
          "type": "custom",
          "tokenizer": "keyword",
          "filter": [
            "lowercase",
            "mynGram"
          ]
        }
      },
      "analyzer": {
        "my_search_analyzer": {
          "type": "custom",
          "tokenizer": "keyword",
          "filter": [
            "lowercase",
            "mynGram"
          ]
        }
      },
      "filter": {
        "mynGram": {
          "type": "nGram",
          "min_gram": 2,
          "max_gram": 50
        }
      }
    }
	},
    "mappings": {
      "main": {
        "properties": {
          "_all": {
			"type": "text",
            "analyzer": "my_search_analyzer"
          }
        }
      }
    }
}
'
```

---

<div class="post-metadata">

**Author:** ![elasticuser1](https://avatars.discourse-cdn.com/v4/letter/e/a3d4f5/32.png) [@elasticuser1](https://discuss.elastic.co/u/elasticuser1)\
**Post date:** [November 14, 2017, 8:12pm UTC](https://discuss.elastic.co/t/search-for-any-word-without-mappings-using-uri-query/107487/6 "2017-11-14T20:12:13Z")

</div>

Finally I came up with below template but when I query, it is returning all documents for every string. What am I doing wrong? Thanks

http://es\_host:9200/sapihub-\*/\_search?pretty=true&q=internal

curl -XPUT 'es\_host:9200/\_template/sapihub\_template?pretty' -H 'Content-Type: application/json' -d'  
{  
"template": "sapihub-\*",  
"settings": {  
"index": {  
"number\_of\_shards": 1,  
"number\_of\_replicas" : 2,  
"mapping.total\_fields.limit": 4000   
},  
"analysis": {  
"filter": {  
"mynGram": {  
"type": "nGram",  
"min\_gram": 2,  
"max\_gram": 50  
}  
},  
"analyzer": {  
"index\_ngram\_analyzer": {  
"type": "custom",  
"tokenizer": "standard",  
"filter": [  
"lowercase",  
"mynGram"  
]  
},  
"search\_ngram\_analyzer": {  
"type": "custom",  
"tokenizer": "standard",  
"filter": [  
"standard",  
"lowercase",  
"mynGram"  
]  
}  
}  
}  
},  
"mappings": {  
"main": {  
"\_all": {  
"type": "text",  
"search\_analyzer": "search\_ngram\_analyzer",  
"analyzer": "index\_ngram\_analyzer"  
}  
}  
}  
}  
'

---

<div class="post-metadata">

**Author:** ![elasticuser1](https://avatars.discourse-cdn.com/v4/letter/e/a3d4f5/32.png) [@elasticuser1](https://discuss.elastic.co/u/elasticuser1)\
**Post date:** [November 15, 2017, 6:37pm UTC](https://discuss.elastic.co/t/search-for-any-word-without-mappings-using-uri-query/107487/7 "2017-11-15T18:37:24Z")

</div>

Hi, any help is greatly appreciated. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2017, 6:37pm UTC](https://discuss.elastic.co/t/search-for-any-word-without-mappings-using-uri-query/107487/8 "2017-12-13T18:37:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
