# \[SOLVED\] A little question regarding Kibana search

**URL:** <https://discuss.elastic.co/t/solved-a-little-question-regarding-kibana-search/48661>\
**Category:** Kibana\
**Created:** [April 28, 2016, 9:57am UTC](https://discuss.elastic.co/t/solved-a-little-question-regarding-kibana-search/48661 "2016-04-28T09:57:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![axelfelix](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@axelfelix](https://discuss.elastic.co/u/axelfelix)\
**Post date:** [April 28, 2016, 9:57am UTC](https://discuss.elastic.co/t/solved-a-little-question-regarding-kibana-search/48661/1 "2016-04-28T09:57:51Z")

</div>

Hi all,

I'm reading "Apache Lucene - Query Parser Syntax" [official documentation](https://lucene.apache.org/core/2_9_4/queryparsersyntax.html).

I can see in Terms section:

_`Note: The analyzer used to create the index will be used on the terms and phrases in the query string. So it is important to choose an analyzer that will not interfere with the terms used in the query string.`_

I try to figure out how it works exactly. In my elasticsearch mapping I have a lot of fields that have their own custom analyzer. So when I make a terms query like "toto tata" in Kibana toolbar, how lucene choose the right analyzer if I didn't specified the field ? It tries with all analyzer from all fields ?

Thanks in advance for your answer.  
Alex

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 28, 2016, 2:37pm UTC](https://discuss.elastic.co/t/solved-a-little-question-regarding-kibana-search/48661/2 "2016-04-28T14:37:36Z")

</div>

If you don't specify the field name in the query, the `_all` field is used. This is a string field that contains a concatenation of values from all other fields in the document. By default the `_all` field uses the `standard` analyzer but this can be overridden in the mapping.

You can read a bit more about the `_all` field over here: [https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-all-field.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-all-field.html)

---

<div class="post-metadata">

**Author:** ![axelfelix](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@axelfelix](https://discuss.elastic.co/u/axelfelix)\
**Post date:** [April 28, 2016, 3:09pm UTC](https://discuss.elastic.co/t/solved-a-little-question-regarding-kibana-search/48661/3 "2016-04-28T15:09:54Z")

</div>

Thanks for your reply.

In my environment the \_all field is disable...

So in that case, it means that it will use the \_source field ? If yes, with which analyzer ?

Thanks,  
Alex

---

<div class="post-metadata">

**Author:** ![axelfelix](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@axelfelix](https://discuss.elastic.co/u/axelfelix)\
**Post date:** [May 10, 2016, 12:09pm UTC](https://discuss.elastic.co/t/solved-a-little-question-regarding-kibana-search/48661/4 "2016-05-10T12:09:22Z")

</div>

I get the answer in the [official doc](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-all-field.html):

`"If the _all field is disabled, then URI search requests and the query_string and simple_query_string queries will not be able to use it for queries (see Using the _all field in queries). You can configure them to use a different field with the index.query.default_field."`

Have a nice day,  
Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:53pm UTC](https://discuss.elastic.co/t/solved-a-little-question-regarding-kibana-search/48661/5 "2017-07-06T13:53:50Z")

</div>


