# Set field as not\_analyzed in Elastic Search

**URL:** <https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553>\
**Category:** Elasticsearch\
**Created:** [August 22, 2016, 7:31am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553 "2016-08-22T07:31:47Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Denis\_Wessels](https://avatars.discourse-cdn.com/v4/letter/d/2bfe46/32.png) [@Denis\_Wessels](https://discuss.elastic.co/u/Denis_Wessels)\
**Post date:** [August 22, 2016, 7:31am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/1 "2016-08-22T07:31:47Z")

</div>

I have a string field in my Elastic search index.When I view it in Kibana it splits it to form multiple words, I want to prevent this from happenening.

**This is the warning I get in Kibana:**

Careful! The field selected contains analyzed strings. Analyzed strings are highly unique and can use a lot of memory to visualize. Values such as foo-bar will be broken into foo and bar. See Mapping Types for more information on setting this field as not\_analyzed.

I use Elastic search for logging and I have a new log index created everyday which has the following mask - "log-YYYY.MM.DD".

When I run [http://localhost:9200/log-\*/\_mapping](http://localhost:9200/log-*/_mapping), i get the followin output:

{"log-2016.08.22":{"mappings":{"logEvent":{"properties":{"className":{"type":"string"},"domain":{"type":"string"},"exception":{"type":"object"},"fileName":{"type":"string"},"fix":{"type":"string"},"fullInfo":{"type":"string"},"hostName":{"type":"string"},"identity":{"type":"string"},"level":{"type":"string"},"lineNumber":{"type":"string"},"loggerName":{"type":"string"},"message":{"type":"string"},"messageObject":{"properties":{"ID":{"type":"long"},"Message":{"type":"string"},"Type":{"type":"string"}}},"methodName":{"type":"string"},"properties":{"properties":{"@timestamp":{"type":"date","format":"strict\_date\_optional\_time||epoch\_millis"},"log4net:HostName":{"type":"string"},"log4net:Identity":{"type":"string"},"log4net:UserName":{"type":"string"}}},"threadName":{"type":"string"},"timeStamp":{"type":"date","format":"strict\_date\_optional\_time||epoch\_millis"},"userName":{"type":"string"}}}}},"log-2016.08.19":{"mappings":{"logEvent":{"properties":{"className":{"type":"string"},"domain":{"type":"string"},"exception":{"type":"object"},"fileName":{"type":"string"},"fix":{"type":"string"},"fullInfo":{"type":"string"},"hostName":{"type":"string"},"identity":{"type":"string"},"level":{"type":"string"},"lineNumber":{"type":"string"},"loggerName":{"type":"string"},"message":{"type":"string"},"messageObject":{"properties":{"ID":{"type":"long"},"Message":{"type":"string"},"Type":{"type":"string"}}},"methodName":{"type":"string"},"properties":{"properties":{"@timestamp":{"type":"date","format":"strict\_date\_optional\_time||epoch\_millis"},"log4net:HostName":{"type":"string"},"log4net:Identity":{"type":"string"},"log4net:UserName":{"type":"string"}}},"threadName":{"type":"string"},"timeStamp":{"type":"date","format":"strict\_date\_optional\_time||epoch\_millis"},"userName":{"type":"string"}}}}}}

My question is how can I make **"Message":{"type":"string"}** not analyzed for all the indexes which start with **log-** \*?What command do I run to do this?Or how can I make ALL strings not\_analyzed?Can someone please show me a step-by-step example?

---

<div class="post-metadata">

**Author:** ![emperor](https://avatars.discourse-cdn.com/v4/letter/e/a8b319/32.png) [@emperor](https://discuss.elastic.co/u/emperor)\
**Post date:** [August 22, 2016, 7:33am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/2 "2016-08-22T07:33:36Z")

</div>

no step by step example,you should re-mapping your index to renew your filed into not analyzed

---

<div class="post-metadata">

**Author:** ![Denis\_Wessels](https://avatars.discourse-cdn.com/v4/letter/d/2bfe46/32.png) [@Denis\_Wessels](https://discuss.elastic.co/u/Denis_Wessels)\
**Post date:** [August 22, 2016, 7:34am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/3 "2016-08-22T07:34:13Z")

</div>

Ok and how do I do this?What command do I run to re-map my index?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 22, 2016, 7:42am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/4 "2016-08-22T07:42:07Z")

</div>

What version are you on?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 22, 2016, 7:42am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/5 "2016-08-22T07:42:48Z")

</div>

Use an index template to define the desired mappings for new indexes. You might want to use Logstash's index template for logstash-\* indexes as a starting point.

---

<div class="post-metadata">

**Author:** ![Denis\_Wessels](https://avatars.discourse-cdn.com/v4/letter/d/2bfe46/32.png) [@Denis\_Wessels](https://discuss.elastic.co/u/Denis_Wessels)\
**Post date:** [August 22, 2016, 7:43am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/6 "2016-08-22T07:43:54Z")

</div>

2.3.5

---

<div class="post-metadata">

**Author:** ![Denis\_Wessels](https://avatars.discourse-cdn.com/v4/letter/d/2bfe46/32.png) [@Denis\_Wessels](https://discuss.elastic.co/u/Denis_Wessels)\
**Post date:** [August 22, 2016, 7:44am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/7 "2016-08-22T07:44:41Z")

</div>

Can you give me an example?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 22, 2016, 7:48am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/8 "2016-08-22T07:48:11Z")

</div>

> Can you give me an example?

Example of what, exactly?

---

<div class="post-metadata">

**Author:** ![Denis\_Wessels](https://avatars.discourse-cdn.com/v4/letter/d/2bfe46/32.png) [@Denis\_Wessels](https://discuss.elastic.co/u/Denis_Wessels)\
**Post date:** [August 22, 2016, 7:49am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/9 "2016-08-22T07:49:02Z")

</div>

Example of a command I can execute in the browser or using CURL to make the Message field not\_analyzed

---

<div class="post-metadata">

**Author:** ![emperor](https://avatars.discourse-cdn.com/v4/letter/e/a8b319/32.png) [@emperor](https://discuss.elastic.co/u/emperor)\
**Post date:** [August 22, 2016, 7:57am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/10 "2016-08-22T07:57:57Z")

</div>

curl -XPOST 'localhost:9200/myindex/\_close'

curl -XPUT 'localhost:9200/myindex/\_settings' -d '{  
"analysis" : {  
"analyzer":{  
"content":{  
"type":"custom",  
"tokenizer":"whitespace"  
}  
}  
}  
}'

---

<div class="post-metadata">

**Author:** ![emperor](https://avatars.discourse-cdn.com/v4/letter/e/a8b319/32.png) [@emperor](https://discuss.elastic.co/u/emperor)\
**Post date:** [August 22, 2016, 7:58am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/11 "2016-08-22T07:58:28Z")

</div>

[https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html)

---

<div class="post-metadata">

**Author:** ![Denis\_Wessels](https://avatars.discourse-cdn.com/v4/letter/d/2bfe46/32.png) [@Denis\_Wessels](https://discuss.elastic.co/u/Denis_Wessels)\
**Post date:** [August 22, 2016, 8:06am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/12 "2016-08-22T08:06:18Z")

</div>

> [@emperor](#):
>
> myindex

I can't use myindex it needs to be a wild card.As I've mentioned in my original post I have indexes created dynamically with the following names **"log-YYYY.MM.DD"** so the not\_analyzed needs to be applied to all indexes starting with **log-** I tried taking your code and changing it to **log-** and **log** but when I paste it in the curl console it says _\> } is not recognized as internal or external command_

---

<div class="post-metadata">

**Author:** ![emperor](https://avatars.discourse-cdn.com/v4/letter/e/a8b319/32.png) [@emperor](https://discuss.elastic.co/u/emperor)\
**Post date:** [August 22, 2016, 8:19am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/13 "2016-08-22T08:19:26Z")

</div>

1.how many index do you have now?  
2.reindex the data though as it is not possible to change mapping for an existing field.

i suggent you create new index(just alter the properties "not\_analyzed") ,and import the old data into the new index.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 22, 2016, 8:22am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/14 "2016-08-22T08:22:59Z")

</div>

> Example of a command I can execute in the browser or using CURL to make the Message field not\_analyzed

See [Index templates | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html) for more about index templates. Here's the template used by Logstash 2.3.4: [https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/v2.7.1/lib/logstash/outputs/elasticsearch/elasticsearch-template.json](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/v2.7.1/lib/logstash/outputs/elasticsearch/elasticsearch-template.json) See the definition of the `@version` for an example of how a string field can be made `not_analyzed`.

---

<div class="post-metadata">

**Author:** ![Denis\_Wessels](https://avatars.discourse-cdn.com/v4/letter/d/2bfe46/32.png) [@Denis\_Wessels](https://discuss.elastic.co/u/Denis_Wessels)\
**Post date:** [August 22, 2016, 8:24am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/15 "2016-08-22T08:24:50Z")

</div>

1)I have one at the moment and it's called - log-2016.08.22 tomorrow log-2016.08.23 will automatically be created and so on

2)How can I create a new index???My indexes are created dynamically and have have X number of properties.What I do know for a fact is that I will always have a field called **Message** in my index and I need some way to make this field not\_analyzed for any index called _log-\*_

---

<div class="post-metadata">

**Author:** ![Denis\_Wessels](https://avatars.discourse-cdn.com/v4/letter/d/2bfe46/32.png) [@Denis\_Wessels](https://discuss.elastic.co/u/Denis_Wessels)\
**Post date:** [August 22, 2016, 8:29am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/16 "2016-08-22T08:29:31Z")

</div>

> [@magnusbaeck](#):
>
> version

Ok so I took that JSON and changed the template field to be "log-\*" and I changed @version to be @Message because my field is called Message but when I copy and paste the JSON into the command prompt I get a message saying _} is not recognized as an internal or external command_ what am I doing wrong?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 22, 2016, 8:41am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/17 "2016-08-22T08:41:25Z")

</div>

> How can I create a new index?

With the [create index API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-create-index.html), for example.

> but when I copy and paste the JSON into the command prompt I get a message saying } is not recognized as an internal or external command

Perhaps you're not single-quoting the JSON string? See the previous example from @emperor.

---

<div class="post-metadata">

**Author:** ![Denis\_Wessels](https://avatars.discourse-cdn.com/v4/letter/d/2bfe46/32.png) [@Denis\_Wessels](https://discuss.elastic.co/u/Denis_Wessels)\
**Post date:** [August 22, 2016, 8:46am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/18 "2016-08-22T08:46:53Z")

</div>

I have wrapped my json in single quotes.Here is my batch file:

curl PUT /\_template/template\_1  
'{  
"template": "log-\*",  
"settings": {  
"number\_of\_shards": 1  
},  
"mappings": {  
"type1": {  
"\_source": {  
"enabled": false  
},  
"properties": {  
"Message": {  
"type": "string",  
"index": "not\_analyzed"  
},  
"created\_at": {  
"type": "date",  
"format": "EEE MMM dd HH:mm:ss Z YYYY"  
}  
}  
}  
}  
}'

pause

---

<div class="post-metadata">

**Author:** ![Denis\_Wessels](https://avatars.discourse-cdn.com/v4/letter/d/2bfe46/32.png) [@Denis\_Wessels](https://discuss.elastic.co/u/Denis_Wessels)\
**Post date:** [August 22, 2016, 8:48am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/19 "2016-08-22T08:48:17Z")

</div>

When I run the batch file it still says '}' is not recognized as an internal or external command

 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/488e2e49e5bef81036884d658be50dcb4d40a6a1.PNG)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 22, 2016, 8:56am UTC](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553/20 "2016-08-22T08:56:29Z")

</div>

Please follow @emperor's example. (It's `-XPUT` not `PUT` and you're missing `-d`. )

[Next page](https://discuss.elastic.co/t/set-field-as-not-analyzed-in-elastic-search/58553.md?page=2)
