# Template Elasticsearch about data

**URL:** <https://discuss.elastic.co/t/template-elasticsearch-about-data/96103>\
**Category:** Elasticsearch\
**Created:** [August 7, 2017, 12:30pm UTC](https://discuss.elastic.co/t/template-elasticsearch-about-data/96103 "2017-08-07T12:30:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [August 7, 2017, 12:30pm UTC](https://discuss.elastic.co/t/template-elasticsearch-about-data/96103/1 "2017-08-07T12:30:23Z")

</div>

Hello guys,

I want help to define my template elasticsearch 5.5.1

An example of line :

`90|336882106|2080159|12F6|1162|025C|03/08/201708:02:46|A1|LEGACY|CATCH|10001|258|request|01|000541|01|3585086414|00|apache2|CATCH_ALL|4652414631`

21 fields total.

Few questions before to look template :

1. What is the difference between not analyze a fied and enable false field ?
2. Numeric detection is really interesting ? Or it's better to define format (long, int,short...) myself

Also i not need a full text search, i use just key words for aggregate and visualize (sum, average...) what i can make that ?

Right now, my template.

I want :

Not full text search  
Disable or not analyze field (i don't know the difference)

So what do you think about my template currently :

```
{
  "order": 0,
  "template": "cra-dcb*",
  "settings": {
    "index": {
      "number_of_shards": "2",
      "number_of_replicas": "0",
      "refresh_interval": "59s"
      }
    },
  "mappings": {
    "_default_": {
      "dynamic_templates": [
        {
          "strings_as_keywords": {
            "match_mapping_type": "string",
            "mapping": {
              "type": "text",
              "norms": false,
              "fields": {
                "keyword": {
                  "type": "keyword",
                  "ignore_above": 256
                }
              }
            }
          }
        }
      ],
      "_all": {
        "enabled": false
      },
      "properties": {
      "cra_recordType": {
        "enabled": false
      },
      "cra_teleServ": {
        "enabled": false
      },
      "cra_ratingEvtType": {
        "enabled": false
      },
      "cra_zoneID": {
        "enabled": false
      }
      }
    }
  }
}

```

Thank you a lot for your help

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [August 7, 2017, 8:51pm UTC](https://discuss.elastic.co/t/template-elasticsearch-about-data/96103/2 "2017-08-07T20:51:26Z")

</div>

> What is the difference between not analyze a fied and enable false field ?

Disabling a field ("enabled": false) means that the field will not be indexed at  
all, so it won't be searchable and you cannot aggregate on it.

> Numeric detection is really interesting ? Or it’s better to define format  
> (long, int,short…) myself

If you know the potential range, it's better to define it yourself. For  
instance, if you know it's going to be a small number, you could use a `short`  
or `integer` rather than letting the detection handle it, in which case it will  
always pick either a `long` or `double` (depending on whether it has mantissa or  
not)

> Also i not need a full text search, i use just key words for aggregate and  
> visualize (sum, average…) what i can make that ?

In that case, just make the field a `keyword` field (for string data).

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [August 8, 2017, 1:39pm UTC](https://discuss.elastic.co/t/template-elasticsearch-about-data/96103/3 "2017-08-08T13:39:59Z")

</div>

Ok thank you @dakrone

> [@dakrone](#):
>
> What is the difference between not analyze a fied and enable false field ?
> 
> Disabling a field (“enabled”: false) means that the field will not be indexed at
> 
> all, so it won’t be searchable and you cannot aggregate on it.

I understand **enabled false field** mean it's save in database but it take small disk space because it's not searchable or aggre.  
But if i configure a **field =\> index : not\_analyze** , What is mean ?

> [@dakrone](#):
>
> Also i not need a full text search, i use just key words for aggregate and
> 
> visualize (sum, average…) what i can make that ?
> 
> In that case, just make the field a keyword field (for string data).

Ok, but what i can do it ? My currently template is well configured for that ? (string\_as\_keyword)

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [August 8, 2017, 3:13pm UTC](https://discuss.elastic.co/t/template-elasticsearch-about-data/96103/4 "2017-08-08T15:13:18Z")

</div>

> But if i configure a field =\> index : not\_analyze, What is mean ?

This was an older method of marking a field as a `keyword`, the new way is to  
simply use the `keyword` type in the mapping.

> Ok, but what i can do it ? My currently template is well configured for that ?  
> (string\_as\_keyword)

In your current template you are mapping the field as both `text` and `keyword`,  
so instead of

```auto
"mapping": {
  "type": "text",
  "norms": false,
  "fields": {
    "keyword": {
      "type": "keyword",
      "ignore_above": 256
    }
  }
}

```

you could do

```auto
"mapping": {
   "type": "keyword"
}

```

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [August 9, 2017, 1:01pm UTC](https://discuss.elastic.co/t/template-elasticsearch-about-data/96103/5 "2017-08-09T13:01:49Z")

</div>

Now all work good.

Thank you @dakrone

I would like to know, if i can define, only for one field, to map him a full text-search without keyword ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 6, 2017, 1:02pm UTC](https://discuss.elastic.co/t/template-elasticsearch-about-data/96103/6 "2017-09-06T13:02:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
