# \[SOLVED\] Raw field

**URL:** <https://discuss.elastic.co/t/solved-raw-field/49175>\
**Category:** Elasticsearch\
**Created:** [May 4, 2016, 1:09pm UTC](https://discuss.elastic.co/t/solved-raw-field/49175 "2016-05-04T13:09:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![axelfelix](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@axelfelix](https://discuss.elastic.co/u/axelfelix)\
**Post date:** [May 4, 2016, 1:09pm UTC](https://discuss.elastic.co/t/solved-raw-field/49175/1 "2016-05-04T13:09:34Z")

</div>

Hi all,

I have a field that I analyze but I want to keep it to a single string too.

To deal with that I use the nested field "raw" as below:

> "mappings" : {  
> "my\_log" : {  
> "\_all": {  
> "enabled": false  
> },  
> "properties" : {  
> "@source\_host" : {  
> "type" : "string",  
> "index" : "analyzed",  
> "analyzer" : "custom-analyzer",  
> "fields": {  
> "raw": {  
> "type": "string",  
> "index": "not\_analyzed"  
> }  
> }  
> },  
> ...

When I make a search, I didn't get the field "@source\_host.raw":

> ```
> curl -XGET localhost:9200/log/my_log/_search?pretty
> "hits" : {
> "total" : 57937,
> "max_score" : 1.0,
> "hits" : [ {
> "_index" : "log",
> "_type" : "my_log",
> "_id" : "AVR7oRjdhtVrl161Rr1y",
> "_score" : 1.0,
> "_source" : {
> "message" : "2016-05-04T13:55:51+02:00 10.126.14.137 err 2016 May 4 13:55:51.905 CEST: %ETHPORT-3-IF_UP: Interface Ethernet103/1/16
> "@version" : "1",
> "@timestamp" : "2016-05-04T11:55:51.905Z",
> "host" : "127.0.0.1:34439",
> "type" : "test_log",
> "syslog_host_time" : "2016-05-04T13:55:51+02:00",
> "client" : "192.168.1.1",
> "severity" : "err",
> "client_date" : "2016 May 4 13:55:51.905 CEST",
> "facility" : "ETHPORT",
> "int_severity" : "3",
> "mnemonic" : "IF_UP",
> "short_message" : "Interface Ethernet103/1/16 is up in mode access",
> "tags" : ["test-log"],
> "@source_host" : "test-toto-1.fr.prs.corp"
> }
> 
> ```

Do you have any idea why ?

Thanks in advance,  
Alex

---

<div class="post-metadata">

**Author:** ![axelfelix](https://avatars.discourse-cdn.com/v4/letter/a/5fc32e/32.png) [@axelfelix](https://discuss.elastic.co/u/axelfelix)\
**Post date:** [May 10, 2016, 11:57am UTC](https://discuss.elastic.co/t/solved-raw-field/49175/2 "2016-05-10T11:57:04Z")

</div>

I found why, I didn't read the offical doc in depth.

Regarding the doc: [https://www.elastic.co/guide/en/elasticsearch/reference/2.3/multi-fields.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.3/multi-fields.html)

`Multi-fields do not change the original _source field`

That's why I didn't get the nested field but I can make a search on it.

Have a nice day,  
Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:52pm UTC](https://discuss.elastic.co/t/solved-raw-field/49175/3 "2017-07-05T22:52:48Z")

</div>


