# Search terms and match\_all not working

**URL:** <https://discuss.elastic.co/t/search-terms-and-match-all-not-working/10604>\
**Category:** Elasticsearch\
**Created:** [February 2, 2013, 9:31pm UTC](https://discuss.elastic.co/t/search-terms-and-match-all-not-working/10604 "2013-02-02T21:31:30Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexis\_Okuwa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexis_okuwa/32/1983_2.png) [@Alexis\_Okuwa](https://discuss.elastic.co/u/Alexis_Okuwa)\
**Post date:** [February 2, 2013, 9:31pm UTC](https://discuss.elastic.co/t/search-terms-and-match-all-not-working/10604/1 "2013-02-02T21:31:30Z")

</div>

I am making a logging system in elasticsearch. I have different types of  
logs with different hosts. Because I am using different type's for the  
different type of logs its easy. When i try to get logs of just one host  
with term or terms it wont return anything, I think it has something to do  
with my mapping (default), but when I try to use match\_all, it returns  
things but its the same returns all hosts, so if i put a hostname for one  
node it will just return the other nodes regardless. I am trying to use  
filters as much as I can to make sure things are in cache.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 3, 2013, 3:23am UTC](https://discuss.elastic.co/t/search-terms-and-match-all-not-working/10604/2 "2013-02-03T03:23:37Z")

</div>

Can you gist an example of your docs, your queries and mapping, if you set one?

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 2 févr. 2013 à 22:31, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :

## I am making a logging system in elasticsearch. I have different types of logs with different hosts. Because I am using different type's for the different type of logs its easy. When i try to get logs of just one host with term or terms it wont return anything, I think it has something to do with my mapping (default), but when I try to use match\_all, it returns things but its the same returns all hosts, so if i put a hostname for one node it will just return the other nodes regardless. I am trying to use filters as much as I can to make sure things are in cache.

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Alexis\_Okuwa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexis_okuwa/32/1983_2.png) [@Alexis\_Okuwa](https://discuss.elastic.co/u/Alexis_Okuwa)\
**Post date:** [February 3, 2013, 6:35am UTC](https://discuss.elastic.co/t/search-terms-and-match-all-not-working/10604/3 "2013-02-03T06:35:24Z")

</div>

i think gist is broken but here is a link to a google doc

> **[es bug](https://docs.google.com/document/d/12b5NG-ZB_Pm1P-v4qrG4qzRBsJvKNRMctGbjoSY9Dfo/edit?usp=sharing)**
>
> This Doc is private

On Sat, Feb 2, 2013 at 7:23 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> Can you gist an example of your docs, your queries and mapping, if you set  
> one?
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 2 févr. 2013 à 22:31, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :
> 
> I am making a logging system in elasticsearch. I have different types of  
> logs with different hosts. Because I am using different type's for the  
> different type of logs its easy. When i try to get logs of just one host  
> with term or terms it wont return anything, I think it has something to do  
> with my mapping (default), but when I try to use match\_all, it returns  
> things but its the same returns all hosts, so if i put a hostname for one  
> node it will just return the other nodes regardless. I am trying to use  
> filters as much as I can to make sure things are in cache.
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Enjoy,  
Alexis Okuwa  
WojonsTech  
424.835.1223

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 3, 2013, 7:16am UTC](https://discuss.elastic.co/t/search-terms-and-match-all-not-working/10604/4 "2013-02-03T07:16:09Z")

</div>

Search with the lowercase value of "YdmAojXGSKGOqMBjvVRAXA"

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 3 févr. 2013 à 07:35, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :

i think gist is broken but here is a link to a google doc

> **[es bug](https://docs.google.com/document/d/12b5NG-ZB_Pm1P-v4qrG4qzRBsJvKNRMctGbjoSY9Dfo/edit?usp=sharing)**
>
> { "sort": \[{ "logTime": "desc" } \], "from": 0, "size": 60, "filter": { "and": \[ { "term": { "nodeId": "YdmAojXGSKGOqMBjvVRAXA" } ...

On Sat, Feb 2, 2013 at 7:23 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> Can you gist an example of your docs, your queries and mapping, if you set one?
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 2 févr. 2013 à 22:31, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :
> 
> ## I am making a logging system in elasticsearch. I have different types of logs with different hosts. Because I am using different type's for the different type of logs its easy. When i try to get logs of just one host with term or terms it wont return anything, I think it has something to do with my mapping (default), but when I try to use match\_all, it returns things but its the same returns all hosts, so if i put a hostname for one node it will just return the other nodes regardless. I am trying to use filters as much as I can to make sure things are in cache.
> 
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

## -- Enjoy, Alexis Okuwa WojonsTech 424.835.1223

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Alexis\_Okuwa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexis_okuwa/32/1983_2.png) [@Alexis\_Okuwa](https://discuss.elastic.co/u/Alexis_Okuwa)\
**Post date:** [February 3, 2013, 7:19am UTC](https://discuss.elastic.co/t/search-terms-and-match-all-not-working/10604/5 "2013-02-03T07:19:12Z")

</div>

That seems to work, that is kinda of a bummer because that node id is the  
one generated by elasticsearch, so thats the \_id of another document. so  
there is always a chance of two documents have the same characters but  
different case. anyway to fix this?

On Sat, Feb 2, 2013 at 11:16 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> Search with the lowercase value of "YdmAojXGSKGOqMBjvVRAXA"
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 3 févr. 2013 à 07:35, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :
> 
> i think gist is broken but here is a link to a google doc
> 
> [es bug - Google Docs](https://docs.google.com/document/d/12b5NG-ZB_Pm1P-v4qrG4qzRBsJvKNRMctGbjoSY9Dfo/edit?usp=sharing)
> 
> On Sat, Feb 2, 2013 at 7:23 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:
> 
> > Can you gist an example of your docs, your queries and mapping, if you  
> > set one?
> > 
> > --  
> > David 😉  
> > Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> > 
> > Le 2 févr. 2013 à 22:31, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :
> > 
> > I am making a logging system in elasticsearch. I have different types of  
> > logs with different hosts. Because I am using different type's for the  
> > different type of logs its easy. When i try to get logs of just one host  
> > with term or terms it wont return anything, I think it has something to do  
> > with my mapping (default), but when I try to use match\_all, it returns  
> > things but its the same returns all hosts, so if i put a hostname for one  
> > node it will just return the other nodes regardless. I am trying to use  
> > filters as much as I can to make sure things are in cache.
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> Enjoy,  
> Alexis Okuwa  
> WojonsTech  
> 424.835.1223
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Enjoy,  
Alexis Okuwa  
WojonsTech  
424.835.1223

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 3, 2013, 7:33am UTC](https://discuss.elastic.co/t/search-terms-and-match-all-not-working/10604/6 "2013-02-03T07:33:41Z")

</div>

You can change the mapping and set not\_analyzed for this kind of field.

That way, ES will index it without breaking in into tokens, lowercase it and ignore common english words (standard analyzer).

Or, you can search with matchQuery (analyzed) instead of termQuery (not analyzed) but for your use case, I recommend the first method.

--  
David 😉  
Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs

Le 3 févr. 2013 à 08:19, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :

That seems to work, that is kinda of a bummer because that node id is the one generated by elasticsearch, so thats the \_id of another document. so there is always a chance of two documents have the same characters but different case. anyway to fix this?

On Sat, Feb 2, 2013 at 11:16 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> Search with the lowercase value of "YdmAojXGSKGOqMBjvVRAXA"
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 3 févr. 2013 à 07:35, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :
> 
> i think gist is broken but here is a link to a google doc
> 
> [es bug - Google Docs](https://docs.google.com/document/d/12b5NG-ZB_Pm1P-v4qrG4qzRBsJvKNRMctGbjoSY9Dfo/edit?usp=sharing)
> 
> On Sat, Feb 2, 2013 at 7:23 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:
> 
> > Can you gist an example of your docs, your queries and mapping, if you set one?
> > 
> > --  
> > David 😉  
> > Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> > 
> > Le 2 févr. 2013 à 22:31, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :
> > 
> > ## I am making a logging system in elasticsearch. I have different types of logs with different hosts. Because I am using different type's for the different type of logs its easy. When i try to get logs of just one host with term or terms it wont return anything, I think it has something to do with my mapping (default), but when I try to use match\_all, it returns things but its the same returns all hosts, so if i put a hostname for one node it will just return the other nodes regardless. I am trying to use filters as much as I can to make sure things are in cache.
> > 
> > You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> ## -- Enjoy, Alexis Okuwa WojonsTech 424.835.1223
> 
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

## -- Enjoy, Alexis Okuwa WojonsTech 424.835.1223

You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Alexis\_Okuwa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexis_okuwa/32/1983_2.png) [@Alexis\_Okuwa](https://discuss.elastic.co/u/Alexis_Okuwa)\
**Post date:** [February 3, 2013, 7:36am UTC](https://discuss.elastic.co/t/search-terms-and-match-all-not-working/10604/7 "2013-02-03T07:36:16Z")

</div>

How do i change the mapping and are there other things i should be changing  
the mapping for, I really have not been able to understand what mapping is  
in es can you explain it to me.

On Sat, Feb 2, 2013 at 11:33 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:

> You can change the mapping and set not\_analyzed for this kind of field.
> 
> That way, ES will index it without breaking in into tokens, lowercase it  
> and ignore common english words (standard analyzer).
> 
> Or, you can search with matchQuery (analyzed) instead of termQuery (not  
> analyzed) but for your use case, I recommend the first method.
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 3 févr. 2013 à 08:19, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :
> 
> That seems to work, that is kinda of a bummer because that node id is the  
> one generated by elasticsearch, so thats the \_id of another document. so  
> there is always a chance of two documents have the same characters but  
> different case. anyway to fix this?
> 
> On Sat, Feb 2, 2013 at 11:16 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:
> 
> > Search with the lowercase value of "YdmAojXGSKGOqMBjvVRAXA"
> > 
> > --  
> > David 😉  
> > Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> > 
> > Le 3 févr. 2013 à 07:35, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :
> > 
> > i think gist is broken but here is a link to a google doc
> > 
> > [es bug - Google Docs](https://docs.google.com/document/d/12b5NG-ZB_Pm1P-v4qrG4qzRBsJvKNRMctGbjoSY9Dfo/edit?usp=sharing)
> > 
> > On Sat, Feb 2, 2013 at 7:23 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:
> > 
> > > Can you gist an example of your docs, your queries and mapping, if you  
> > > set one?
> > > 
> > > --  
> > > David 😉  
> > > Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> > > 
> > > Le 2 févr. 2013 à 22:31, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :
> > > 
> > > I am making a logging system in elasticsearch. I have different types of  
> > > logs with different hosts. Because I am using different type's for the  
> > > different type of logs its easy. When i try to get logs of just one host  
> > > with term or terms it wont return anything, I think it has something to do  
> > > with my mapping (default), but when I try to use match\_all, it returns  
> > > things but its the same returns all hosts, so if i put a hostname for one  
> > > node it will just return the other nodes regardless. I am trying to use  
> > > filters as much as I can to make sure things are in cache.
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > Enjoy,  
> > Alexis Okuwa  
> > WojonsTech  
> > 424.835.1223
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> Enjoy,  
> Alexis Okuwa  
> WojonsTech  
> 424.835.1223
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Enjoy,  
Alexis Okuwa  
WojonsTech  
424.835.1223

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 3, 2013, 6:22pm UTC](https://discuss.elastic.co/t/search-terms-and-match-all-not-working/10604/8 "2013-02-03T18:22:24Z")

</div>

Do something like:  
$ curl -XPUT '[http://localhost:9200/twitter/tweet/\_mapping](http://localhost:9200/twitter/tweet/_mapping)' -d '  
{  
"tweet" : {  
"properties" : {  
"message" : {"type" : "string", "index" : "not\_analyzed"}  
}  
}  
}  
'  
You have to define it before indexing the first document.

HTH

Le 3 févr. 2013 à 08:36, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :

> How do i change the mapping and are there other things i should be changing the mapping for, I really have not been able to understand what mapping is in es can you explain it to me.
> 
> On Sat, Feb 2, 2013 at 11:33 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:  
> You can change the mapping and set not\_analyzed for this kind of field.
> 
> That way, ES will index it without breaking in into tokens, lowercase it and ignore common english words (standard analyzer).
> 
> Or, you can search with matchQuery (analyzed) instead of termQuery (not analyzed) but for your use case, I recommend the first method.
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 3 févr. 2013 à 08:19, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :
> 
> That seems to work, that is kinda of a bummer because that node id is the one generated by elasticsearch, so thats the \_id of another document. so there is always a chance of two documents have the same characters but different case. anyway to fix this?
> 
> On Sat, Feb 2, 2013 at 11:16 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:  
> Search with the lowercase value of "YdmAojXGSKGOqMBjvVRAXA"
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 3 févr. 2013 à 07:35, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :
> 
> i think gist is broken but here is a link to a google doc
> 
> [https://docs.google.com/document/d/12b5NG-ZB\_Pm1P-v4qrG4qzRBsJvKNRMctGbjoSY9Dfo/edit?usp=sharing](https://docs.google.com/document/d/12b5NG-ZB_Pm1P-v4qrG4qzRBsJvKNRMctGbjoSY9Dfo/edit?usp=sharing)
> 
> On Sat, Feb 2, 2013 at 7:23 PM, David Pilato [david@pilato.fr](mailto:david@pilato.fr) wrote:  
> Can you gist an example of your docs, your queries and mapping, if you set one?
> 
> --  
> David 😉  
> Twitter : @dadoonet / @elasticsearchfr / @scrutmydocs
> 
> Le 2 févr. 2013 à 22:31, Wojons Tech [wojonstech@gmail.com](mailto:wojonstech@gmail.com) a écrit :
> 
> I am making a logging system in elasticsearch. I have different types of logs with different hosts. Because I am using different type's for the different type of logs its easy. When i try to get logs of just one host with term or terms it wont return anything, I think it has something to do with my mapping (default), but when I try to use match\_all, it returns things but its the same returns all hosts, so if i put a hostname for one node it will just return the other nodes regardless. I am trying to use filters as much as I can to make sure things are in cache.
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> Enjoy,  
> Alexis Okuwa  
> WojonsTech  
> 424.835.1223
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> Enjoy,  
> Alexis Okuwa  
> WojonsTech  
> 424.835.1223
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> 
> --  
> Enjoy,  
> Alexis Okuwa  
> WojonsTech  
> 424.835.1223
> 
> --  
> You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [February 3, 2013, 7:45pm UTC](https://discuss.elastic.co/t/search-terms-and-match-all-not-working/10604/9 "2013-02-03T19:45:23Z")

</div>

The field mapping defines what Lucene analyzers and fields attributes  
should be assigned to a field in your source for a document you index.

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

I you want to disable mapping completey and index your data analyzed by  
keyword, you can create an index with

curl -XPUT localhost:9200/test -d '{  
"index" : {  
"analysis" : {  
"analyzer" : {  
"default" : {  
"type" : "keyword"  
}  
}  
}  
}  
}'

Best regards,

Jörg

Am 03.02.13 08:36, schrieb Wojons Tech:

> How do i change the mapping and are there other things i should be  
> changing the mapping for, I really have not been able to understand  
> what mapping is in es can you explain it to me.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:53am UTC](https://discuss.elastic.co/t/search-terms-and-match-all-not-working/10604/10 "2017-07-06T02:53:13Z")

</div>


