# Search over all fields with all\_fields and default\_field differ

**URL:** <https://discuss.elastic.co/t/search-over-all-fields-with-all-fields-and-default-field-differ/100217>\
**Category:** Kibana\
**Created:** [September 12, 2017, 1:29pm UTC](https://discuss.elastic.co/t/search-over-all-fields-with-all-fields-and-default-field-differ/100217 "2017-09-12T13:29:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![WimmerELO](https://avatars.discourse-cdn.com/v4/letter/w/5fc32e/32.png) [@WimmerELO](https://discuss.elastic.co/u/WimmerELO)\
**Post date:** [September 12, 2017, 1:29pm UTC](https://discuss.elastic.co/t/search-over-all-fields-with-all-fields-and-default-field-differ/100217/1 "2017-09-12T13:29:30Z")

</div>

Hi,

we are using Kibana 5.4.1 (and so ES) and we need to search over all fields without the \_all field in Kibana Discover.

As solution we thought that we could set the Kibana option: "query:queryString:options" to  
{ "analyze\_wildcard": true,  
"all\_fields" : true,  
"lenient": true,  
"default\_operator": "and" }

This search configuration works well (e.g. search for a simple string consisting of multiple words like My Company 1) and has the correct search results. Unfortunately, the "all\_fields" is deprecated as of 6.0.0, and we want to be future-proof.  
[https://www.elastic.co/guide/en/elasticsearch/reference/6.x/query-dsl-query-string-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.x/query-dsl-query-string-query.html)

Therefore, we used instead of "all\_fields" the property "default\_field", as suggested by the documentation above, like this:

```
{ "analyze_wildcard": true,
"default_field": "*",
"lenient": true, 
"default_operator": "and" }

```

The query (excerpt) that Kibana is sending (al\_fields is automatically added and set to false):

{ "query\_string": {  
"all\_fields":false,  
"analyze\_wildcard":true,  
"default\_field":"\*",  
"default\_operator":"and",  
"lenient":true,  
"query":"My Company 1"}  
}

Unfortunately, the search result is completely different. It finds nearly every entity in our database (like searching for everything) instead of a sub set.

So, is there a solution to this search so we are compatibile with the 6.0 version? Or do we need to change from "all\_fields" to "default\_field" only if using Kibana/ES 6.0 ?

Thanks  
Christian Wimmer

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [September 12, 2017, 3:40pm UTC](https://discuss.elastic.co/t/search-over-all-fields-with-all-fields-and-default-field-differ/100217/2 "2017-09-12T15:40:10Z")

</div>

Hi @WimmerELO

You shouldn't need to set `all_fields` manually in the `query:queryString:options` setting. If you're querying against an index without an \_all field, `all_fields` mode will be used automatically (unless you specify a default\_field either in the index settings or the query). Is there some reason this didn't work for you?

The same will be true once `all_fields` is removed. `default_field: *` will become the default and will work the same way `all_fields: true` did. Again, this shouldn't require any changes on your part, it should work automatically.

If you were testing `default_field: *` in 5.x it likely returned errors or poor results. This was only fixed in 6.0: [https://github.com/elastic/elasticsearch/pull/25726](https://github.com/elastic/elasticsearch/pull/25726).

Note that `all_fields` was only deprecated in 6.0, it won't be removed until 7.0.

---

<div class="post-metadata">

**Author:** ![WimmerELO](https://avatars.discourse-cdn.com/v4/letter/w/5fc32e/32.png) [@WimmerELO](https://discuss.elastic.co/u/WimmerELO)\
**Post date:** [September 13, 2017, 7:26am UTC](https://discuss.elastic.co/t/search-over-all-fields-with-all-fields-and-default-field-differ/100217/3 "2017-09-13T07:26:36Z")

</div>

Thanks for your answer !

After some investigation:  
We cannot leave out all\_fields : true because existing ES indexes have empty \_all field in its mapping already. Due to big data it is not convenient to reindex only for this.

default\_field and fields with value of "\*" return to many results because a lot more fields are checked than when using all\_fields, it seems (the explain syntax shows this).

When version 7 is near release, we will check for compatibility.

Thanks  
Christian Wimmer

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [September 13, 2017, 2:03pm UTC](https://discuss.elastic.co/t/search-over-all-fields-with-all-fields-and-default-field-differ/100217/4 "2017-09-13T14:03:58Z")

</div>

> [@WimmerELO](#):
>
> We cannot leave out all\_fields : true because existing ES indexes have empty \_all field in its mapping already. Due to big data it is not convenient to reindex only for this.

Do you actually need `all_fields` for the indices that have an `_all` field? If you don't specify `all_fields` in your query Elasticsearch will automatically use `_all` for indices where it exists and `all_fields` where it does not.

Nothing wrong with setting `all_fields` if that's what you want though. Please do try `default_field: *` in 6.0 and let us know if you run into problems.

---

<div class="post-metadata">

**Author:** ![WimmerELO](https://avatars.discourse-cdn.com/v4/letter/w/5fc32e/32.png) [@WimmerELO](https://discuss.elastic.co/u/WimmerELO)\
**Post date:** [September 14, 2017, 10:51am UTC](https://discuss.elastic.co/t/search-over-all-fields-with-all-fields-and-default-field-differ/100217/5 "2017-09-14T10:51:10Z")

</div>

We do not want to use \_all fields at all, but due to not knowing beforehand, we accidentally added the \_all field earlier, and now the field is always included in our data but empty. We could reindex, but this takes a lot of time for some customers.

We use all\_fields for now and keep the issue in mind for later releases.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 12, 2017, 10:51am UTC](https://discuss.elastic.co/t/search-over-all-fields-with-all-fields-and-default-field-differ/100217/6 "2017-10-12T10:51:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
