# Specifying analyzer for \_all field

**URL:** <https://discuss.elastic.co/t/specifying-analyzer-for--all-field/7105>\
**Category:** Elasticsearch\
**Created:** [March 23, 2012, 2:28pm UTC](https://discuss.elastic.co/t/specifying-analyzer-for--all-field/7105 "2012-03-23T14:28:16Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Runar\_Myklebust\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/runar_myklebust_2/32/2047_2.png) [@Runar\_Myklebust\_2](https://discuss.elastic.co/u/Runar_Myklebust_2)\
**Post date:** [March 23, 2012, 2:28pm UTC](https://discuss.elastic.co/t/specifying-analyzer-for--all-field/7105/1 "2012-03-23T14:28:16Z")

</div>

Hi, Im having a bit of trouble to set the analyzer for the \_all - field to  
"keyword", and "not\_analyzed" isnt working either.

In this gist, I have store data as showed, executes the query but I get no  
results. If I execute query against the field "data\_textfield" directly, I  
get the result:

> <https://gist.github.com/runarmyklebust/2171055>

## mvh

Runar Myklebust

---

<div class="post-metadata">

**Author:** ![vineeth\_mohan](https://avatars.discourse-cdn.com/v4/letter/v/bc79bd/32.png) [@vineeth\_mohan](https://discuss.elastic.co/u/vineeth_mohan)\
**Post date:** [March 23, 2012, 6:22pm UTC](https://discuss.elastic.co/t/specifying-analyzer-for--all-field/7105/2 "2012-03-23T18:22:09Z")

</div>

You can set the global analyzer when you set the index. I guess that should  
set the behavior of \_all also.

curl -X PUT "localhost:9200/indexName" -d '{ "settings" : { "index" : {  
"number\_of\_shards" : 2, "number\_of\_replicas" : 1 },  
"analysis" : {"analyzer":{"my\_analyzer" : {  
"tokenizer" : "keyword" }}}  
}}'

Also can you try with  
index\_analyzer : keyword  
instead of just  
"analyzer":"keyword"

Thanks  
Vineeth

On Fri, Mar 23, 2012 at 7:58 PM, Runar Myklebust [runar@myklebust.me](mailto:runar@myklebust.me) wrote:

> Hi, Im having a bit of trouble to set the analyzer for the \_all - field to  
> "keyword", and "not\_analyzed" isnt working either.
> 
> In this gist, I have store data as showed, executes the query but I get no  
> results. If I execute query against the field "data\_textfield" directly, I  
> get the result:
> 
> [Elasticsearch setting all-field to analyzer keyword · GitHub](https://gist.github.com/2171055)
> 
> ## mvh
> 
> Runar Myklebust

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [March 25, 2012, 11:57am UTC](https://discuss.elastic.co/t/specifying-analyzer-for--all-field/7105/3 "2012-03-25T11:57:41Z")

</div>

You don't want to set the analyzer for \_all to be keyword, \_all is an  
aggregation of all the other fields int the doc, so you basically treat the  
whole aggregation of text as a single token.

On Fri, Mar 23, 2012 at 4:28 PM, Runar Myklebust [runar@myklebust.me](mailto:runar@myklebust.me) wrote:

> Hi, Im having a bit of trouble to set the analyzer for the \_all - field to  
> "keyword", and "not\_analyzed" isnt working either.
> 
> In this gist, I have store data as showed, executes the query but I get no  
> results. If I execute query against the field "data\_textfield" directly, I  
> get the result:
> 
> [Elasticsearch setting all-field to analyzer keyword · GitHub](https://gist.github.com/2171055)
> 
> ## mvh
> 
> Runar Myklebust

---

<div class="post-metadata">

**Author:** ![vineeth\_mohan](https://avatars.discourse-cdn.com/v4/letter/v/bc79bd/32.png) [@vineeth\_mohan](https://discuss.elastic.co/u/vineeth_mohan)\
**Post date:** [March 25, 2012, 3:06pm UTC](https://discuss.elastic.co/t/specifying-analyzer-for--all-field/7105/4 "2012-03-25T15:06:54Z")

</div>

Hello Shay ,

A doubt on this area.  
When we enable \_all , is there a different copy of all the fields stored ?  
Or is it just a referance to the other fields ?

Thanks  
Vineeth

On Sun, Mar 25, 2012 at 5:27 PM, Shay Banon [kimchy@gmail.com](mailto:kimchy@gmail.com) wrote:

> You don't want to set the analyzer for \_all to be keyword, \_all is an  
> aggregation of all the other fields int the doc, so you basically treat the  
> whole aggregation of text as a single token.
> 
> On Fri, Mar 23, 2012 at 4:28 PM, Runar Myklebust [runar@myklebust.me](mailto:runar@myklebust.me)wrote:
> 
> > Hi, Im having a bit of trouble to set the analyzer for the \_all - field  
> > to "keyword", and "not\_analyzed" isnt working either.
> > 
> > In this gist, I have store data as showed, executes the query but I get  
> > no results. If I execute query against the field "data\_textfield" directly,  
> > I get the result:
> > 
> > [Elasticsearch setting all-field to analyzer keyword · GitHub](https://gist.github.com/2171055)
> > 
> > ## mvh
> > 
> > Runar Myklebust

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [March 25, 2012, 6:21pm UTC](https://discuss.elastic.co/t/specifying-analyzer-for--all-field/7105/5 "2012-03-25T18:21:54Z")

</div>

Its a copy of all the fields "aggregated" into the \_all field.

On Sun, Mar 25, 2012 at 5:06 PM, Vineeth Mohan [vineethmohan@algotree.com](mailto:vineethmohan@algotree.com)wrote:

> Hello Shay ,
> 
> A doubt on this area.  
> When we enable \_all , is there a different copy of all the fields stored ?  
> Or is it just a referance to the other fields ?
> 
> Thanks  
> Vineeth
> 
> On Sun, Mar 25, 2012 at 5:27 PM, Shay Banon [kimchy@gmail.com](mailto:kimchy@gmail.com) wrote:
> 
> > You don't want to set the analyzer for \_all to be keyword, \_all is an  
> > aggregation of all the other fields int the doc, so you basically treat the  
> > whole aggregation of text as a single token.
> > 
> > On Fri, Mar 23, 2012 at 4:28 PM, Runar Myklebust [runar@myklebust.me](mailto:runar@myklebust.me)wrote:
> > 
> > > Hi, Im having a bit of trouble to set the analyzer for the \_all - field  
> > > to "keyword", and "not\_analyzed" isnt working either.
> > > 
> > > In this gist, I have store data as showed, executes the query but I get  
> > > no results. If I execute query against the field "data\_textfield" directly,  
> > > I get the result:
> > > 
> > > [Elasticsearch setting all-field to analyzer keyword · GitHub](https://gist.github.com/2171055)
> > > 
> > > ## mvh
> > > 
> > > Runar Myklebust

---

<div class="post-metadata">

**Author:** ![Runar\_Myklebust\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/runar_myklebust_2/32/2047_2.png) [@Runar\_Myklebust\_2](https://discuss.elastic.co/u/Runar_Myklebust_2)\
**Post date:** [March 26, 2012, 9:24am UTC](https://discuss.elastic.co/t/specifying-analyzer-for--all-field/7105/6 "2012-03-26T09:24:54Z")

</div>

Ok, that make sense. My problem then is that in our existing solution, we  
have a search where contains with texts matches the exact sentence part,  
e.g

\_all = "_part of a sentence_"

Where all of these will match:

"This is a part of a sentence"  
"bigpart of a sentence-that-is-big"

but this will not match:

"A sentence part this is of"

I can use text-query to match that all the phrases are present, but then  
the order part of the query disappears. Is there another way I can achieve  
this when matching against all fields?

On Sun, Mar 25, 2012 at 1:57 PM, Shay Banon [kimchy@gmail.com](mailto:kimchy@gmail.com) wrote:

> You don't want to set the analyzer for \_all to be keyword, \_all is an  
> aggregation of all the other fields int the doc, so you basically treat the  
> whole aggregation of text as a single token.
> 
> On Fri, Mar 23, 2012 at 4:28 PM, Runar Myklebust [runar@myklebust.me](mailto:runar@myklebust.me)wrote:
> 
> > Hi, Im having a bit of trouble to set the analyzer for the \_all - field  
> > to "keyword", and "not\_analyzed" isnt working either.
> > 
> > In this gist, I have store data as showed, executes the query but I get  
> > no results. If I execute query against the field "data\_textfield" directly,  
> > I get the result:
> > 
> > [Elasticsearch setting all-field to analyzer keyword · GitHub](https://gist.github.com/2171055)
> > 
> > ## mvh
> > 
> > Runar Myklebust

## -- mvh

Runar Myklebust

---

<div class="post-metadata">

**Author:** ![Runar\_Myklebust\_2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/runar_myklebust_2/32/2047_2.png) [@Runar\_Myklebust\_2](https://discuss.elastic.co/u/Runar_Myklebust_2)\
**Post date:** [March 28, 2012, 5:51am UTC](https://discuss.elastic.co/t/specifying-analyzer-for--all-field/7105/7 "2012-03-28T05:51:33Z")

</div>

An update; I solved it by disabling the default \_all-field and creating a  
custom all field of type multi-field with both analyzed and not-analyzed  
and adding data manually to this field.

## mvh

Runar Myklebust

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:34am UTC](https://discuss.elastic.co/t/specifying-analyzer-for--all-field/7105/8 "2017-07-06T03:34:28Z")

</div>


