# Searching non-indexed fields

**URL:** <https://discuss.elastic.co/t/searching-non-indexed-fields/327033>\
**Category:** Elasticsearch\
**Created:** [March 6, 2023, 6:09am UTC](https://discuss.elastic.co/t/searching-non-indexed-fields/327033 "2023-03-06T06:09:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kpachar](https://avatars.discourse-cdn.com/v4/letter/k/c4cdca/32.png) [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Post date:** [March 6, 2023, 6:09am UTC](https://discuss.elastic.co/t/searching-non-indexed-fields/327033/1 "2023-03-06T06:09:35Z")

</div>

Hi everyone,

Contrary to popular opinion, I'm able to search non-indexed fields in Elasticsearch. I'm wondering if this is is a bug or a newly introduced feature. I'm on Elasticsearch 8.6.2.

The documentation says "Fields that are not indexed are typically not queryable". Does it mean Elasticsearch will decide at query-time whether to allow a non-indexed field to be queried or not?

I create below an index with one field which is not indexed:

```auto
$ curl -X PUT "localhost:9200/test?pretty" -H 'Content-Type: application/json' -d'
{
  "settings": {
    "number_of_shards": 1
  },
  "mappings": {
    "properties": {
      "field1": { "type": "keyword", "index": false }
    }
  }
}
'

{
  "acknowledged" : true,
  "shards_acknowledged" : true,
  "index" : "test"
}

```

I then write one document

```auto
$ curl -X POST "localhost:9200/test/_doc/?pretty" -H 'Content-Type: application/json' -d'
{
    "field1": "elastic"
}'

{
  "_index" : "test",
  "_id" : "nVJ_tYYB_ZjVXqJjQjyB",
  "_version" : 1,
  "result" : "created",
  "_shards" : {
    "total" : 2,
    "successful" : 1,
    "failed" : 0
  },
  "_seq_no" : 0,
  "_primary_term" : 1
}

```

Then I search for that document:

```auto
$ curl -X POST -H 'Content-Type: application/json' --data '{"query":{"bool":{"must":[{"match":{"field1":"elastic"}}]}}}' localhost:9200/test/_search
{"took":1,"timed_out":false,"_shards":{"total":1,"successful":1,"skipped":0,"failed":0},"hits":{"total":{"value":1,"relation":"eq"},"max_score":1.0,"hits":[{"_index":"test","_id":"nVJ_tYYB_ZjVXqJjQjyB","_score":1.0,"_source":
{
    "field1": "elastic"
}}]}}%

```

Thank you

---

<div class="post-metadata">

**Author:** ![kpachar](https://avatars.discourse-cdn.com/v4/letter/k/c4cdca/32.png) [@kpachar](https://discuss.elastic.co/u/kpachar)\
**Post date:** [March 6, 2023, 8:40am UTC](https://discuss.elastic.co/t/searching-non-indexed-fields/327033/2 "2023-03-06T08:40:00Z")

</div>

Found it.  
Looks like this is an "expensive query" that is enabled by default, but can be disabled.

"queries on [numeric](https://www.elastic.co/guide/en/elasticsearch/reference/current/number.html), [date](https://www.elastic.co/guide/en/elasticsearch/reference/current/date.html), [boolean](https://www.elastic.co/guide/en/elasticsearch/reference/current/boolean.html), [ip](https://www.elastic.co/guide/en/elasticsearch/reference/current/ip.html), [geo\_point](https://www.elastic.co/guide/en/elasticsearch/reference/current/geo-point.html) or [keyword](https://www.elastic.co/guide/en/elasticsearch/reference/current/keyword.html) fields that are not indexed but have [doc values](https://www.elastic.co/guide/en/elasticsearch/reference/current/doc-values.html) enabled"

> **[Query DSL | Elasticsearch Guide \[8.6\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl.html)**

Since 8.1 [What’s new in 8.1 | Elasticsearch Guide [8.1] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.1/release-highlights.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2023, 8:40am UTC](https://discuss.elastic.co/t/searching-non-indexed-fields/327033/3 "2023-04-03T08:40:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
