# Severity/protocol etc keywords are not working with ES?

**URL:** <https://discuss.elastic.co/t/severity-protocol-etc-keywords-are-not-working-with-es/40241>\
**Category:** Elasticsearch\
**Created:** [January 27, 2016, 1:37pm UTC](https://discuss.elastic.co/t/severity-protocol-etc-keywords-are-not-working-with-es/40241 "2016-01-27T13:37:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![adhamelia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adhamelia/32/7409_2.png) [@adhamelia](https://discuss.elastic.co/u/adhamelia)\
**Post date:** [January 27, 2016, 1:37pm UTC](https://discuss.elastic.co/t/severity-protocol-etc-keywords-are-not-working-with-es/40241/1 "2016-01-27T13:37:04Z")

</div>

Hi ES Team,

we are severity/protocol etc keywords for fields and while using them, none of queries work???

let's say,

severity:Error or protocol:tcp

if i rename protocol to protocol-name or something else then it works.

may i know why ?

are they reserved keywords ? if yes then kindly let me know the list of all reserved keywords .

---

<div class="post-metadata">

**Author:** ![tanguy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanguy/32/6030_2.png) [@tanguy](https://discuss.elastic.co/u/tanguy)\
**Post date:** [January 27, 2016, 1:54pm UTC](https://discuss.elastic.co/t/severity-protocol-etc-keywords-are-not-working-with-es/40241/2 "2016-01-27T13:54:23Z")

</div>

Hi,

No reserved keywords. If you want to match keywords, you need to set the fields as `not_analyzed` in your mapping and then query the exact original value for a field using a `term` query.

---

<div class="post-metadata">

**Author:** ![adhamelia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adhamelia/32/7409_2.png) [@adhamelia](https://discuss.elastic.co/u/adhamelia)\
**Post date:** [January 27, 2016, 2:06pm UTC](https://discuss.elastic.co/t/severity-protocol-etc-keywords-are-not-working-with-es/40241/3 "2016-01-27T14:06:29Z")

</div>

i know but only concern is that why field name protocol is not working for any search query but if i rename protocol to something else then it works like a charm..

same as severity keyword

no clue what's going on ???

---

<div class="post-metadata">

**Author:** ![tanguy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanguy/32/6030_2.png) [@tanguy](https://discuss.elastic.co/u/tanguy)\
**Post date:** [January 27, 2016, 3:08pm UTC](https://discuss.elastic.co/t/severity-protocol-etc-keywords-are-not-working-with-es/40241/4 "2016-01-27T15:08:19Z")

</div>

Do you have different document types within the same index that have a "protocol" or "severity" field?

Can you please post your mappings?

---

<div class="post-metadata">

**Author:** ![adhamelia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adhamelia/32/7409_2.png) [@adhamelia](https://discuss.elastic.co/u/adhamelia)\
**Post date:** [February 5, 2016, 8:15am UTC](https://discuss.elastic.co/t/severity-protocol-etc-keywords-are-not-working-with-es/40241/5 "2016-02-05T08:15:44Z")

</div>

Thanks, Problem has been fixed.

Your were right.same fields having diff. data types suck 🙂

tanguy,you are so smart !!! 😉

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:18pm UTC](https://discuss.elastic.co/t/severity-protocol-etc-keywords-are-not-working-with-es/40241/6 "2017-07-05T23:18:41Z")

</div>


