# The \_ignored field not working?

**URL:** https://discuss.elastic.co/t/the-ignored-field-not-working/310460
**Category:** Elasticsearch
**Created:** [July 23, 2022, 6:35pm UTC](https://discuss.elastic.co/t/the-ignored-field-not-working/310460 "2022-07-23T18:35:36Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![rokcarl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokcarl/32/53239_2.png) [@rokcarl](https://discuss.elastic.co/u/rokcarl)
#### Post date: [July 23, 2022, 6:35pm UTC](https://discuss.elastic.co/t/the-ignored-field-not-working/310460/1 "2022-07-23T18:35:36Z")

</div>

**Summary**  
I'm using [`ignore_malformed`](https://www.elastic.co/guide/en/elasticsearch/reference/current/ignore-malformed.html#ignore-malformed-setting), but get no results when searching for the [`_ignored`](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-ignored-field.html) field.

**Details**

I've isolated the problem to a small example. I:

1. Create the index with `ignore_malformed` set to `true`.
2. Insert a couple of documents with invalid values.
3. Observe that both documents are in the index as expected.
4. Search for the ignored fields, but I expected some results and got none.

Here's the test code:

```auto
PUT /test_points
{
  "settings": {
    "index.mapping.ignore_malformed": true
  },
  "mappings": {
    "properties": {
      "timestamp": { "type": "date" },
      "start_point": { "type": "geo_point" }
    }
  }
}

POST /test_points/_doc/
{
  "timestamp": "2022-07-23T11:42:00",
  "start_point": "120.0,120.0"
}

POST /test_points/_doc/
{
  "timestamp": "2022-07-23T11:43:00",
  "start_point": [130.0, 130.0]
}

```

Here are the unexpected results mentioned above:

```auto
GET /test_points/_search

```

```auto
{
  "took" : 1,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 2,
      "relation" : "eq"
    },
    "max_score" : 1.0,
    "hits" : [
      {
        "_index" : "test_points",
        "_id" : "p2QvLIIBVKX1Q3v1B-HR",
        "_score" : 1.0,
        "_source" : {
          "timestamp" : "2022-07-23T11:42:00",
          "start_point" : "120.0,120.0"
        }
      },
      {
        "_index" : "test_points",
        "_id" : "qGQvLIIBVKX1Q3v1EOGC",
        "_score" : 1.0,
        "_source" : {
          "timestamp" : "2022-07-23T11:43:00",
          "start_point" : [
            130.0,
            130.0
          ]
        }
      }
    ]
  }
}

```

The `start_point` for one document is returned as `"120.0,120.0"` and for the other `[130.0, 130.0]`. While this is what I sent over, I would expect Elasticsearch to do some normalization on values?

Not a big deal though, the bigger problem is this:

```auto
GET /test_points/_search
{
  "query": {
    "exists": {
      "field": "_ignored"
    }
  }
}

```

```auto
{
  "took" : 0,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 0,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : []
  }
}

```

No hits. Shouldn't I get something as mentioned in the [docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-ignored-field.html)?

---

<div class="post-metadata">

### Author: ![RabBit\_BR](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rabbit_br/32/82261_2.png) [@RabBit\_BR](https://discuss.elastic.co/u/RabBit_BR)
#### Post date: [July 23, 2022, 8:35pm UTC](https://discuss.elastic.co/t/the-ignored-field-not-working/310460/2 "2022-07-23T20:35:50Z")

</div>

Hi @rokcarl

> [@rokcarl](#):
>
> ```auto
> POST /test_points/_doc/
> {
> "timestamp": "2022-07-23T11:42:00",
> "start_point": "120.0,120.0"
> }
> 
> POST /test_points/_doc/
> {
> "timestamp": "2022-07-23T11:43:00",
> "start_point": [130.0, 130.0]
> }
> 
> ```

it is not working because in both documents the start\_point supports both the coordinate array and the string.

"start\_point": "120.0,120.0"

> Geopoint expressed as a string with the format: "lat,lon".

"start\_point": [130.0, 130.0]

> Geopoint expressed as an array with the format: [`lon`, `lat`]

Try this index:

```auto
POST /test_points/_doc/
{
  "timestamp": "2022-07-23T11:42:00",
  "start_point": 10
}

```

The query below will works:

```auto
GET test_points/_search
{
  "_source": false, 
  "query": {
    "exists": {
      "field": "_ignored"
    }
  }
}

```

Read more in [Geopoint Type](https://www.elastic.co/guide/en/elasticsearch/reference/current/geo-point.html#geo-point).

---

<div class="post-metadata">

### Author: ![rokcarl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokcarl/32/53239_2.png) [@rokcarl](https://discuss.elastic.co/u/rokcarl)
#### Post date: [July 25, 2022, 4:40pm UTC](https://discuss.elastic.co/t/the-ignored-field-not-working/310460/3 "2022-07-25T16:40:30Z")

</div>

Hmmm not sure if we're on the same page.

I wasn't surprised that Elasticsearch allowed me to index both documents, I was surprised that the search results returned values for the `start_point` in different format, but more importantly, that the values even got saved and that it didn't show up in the `_ignored` search, reason being that the actual value is not a valid point because `120.0` is not a valid latitude value.  
See here:

```auto
DELETE /test_points_reject

PUT /test_points_reject
{
  "settings": {
  },
  "mappings": {
    "properties": {
      "timestamp": { "type": "date" },
      "start_point": { "type": "geo_point" }
    }
  }
}

POST /test_points_reject/_doc/
{
  "timestamp": "2022-07-22T15:31:00",
  "start_point": "120.0,120.0"
}

```

Result:

```json
{
  "error" : {
    "root_cause" : [
      {
        "type" : "mapper_parsing_exception",
        "reason" : "failed to parse field [start_point] of type [geo_point]"
      }
    ],
    "type" : "mapper_parsing_exception",
    "reason" : "failed to parse field [start_point] of type [geo_point]",
    "caused_by" : {
      "type" : "illegal_argument_exception",
      "reason" : "illegal latitude value [120.0] for start_point"
    }
  },
  "status" : 400
}

```

---

<div class="post-metadata">

### Author: ![rokcarl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokcarl/32/53239_2.png) [@rokcarl](https://discuss.elastic.co/u/rokcarl)
#### Post date: [August 3, 2022, 10:07am UTC](https://discuss.elastic.co/t/the-ignored-field-not-working/310460/4 "2022-08-03T10:07:42Z")

</div>

Do you know what might be happening here?

---

<div class="post-metadata">

### Author: ![rokcarl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rokcarl/32/53239_2.png) [@rokcarl](https://discuss.elastic.co/u/rokcarl)
#### Post date: [August 15, 2022, 8:16am UTC](https://discuss.elastic.co/t/the-ignored-field-not-working/310460/5 "2022-08-15T08:16:18Z")

</div>

Anyone?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 12, 2022, 8:16am UTC](https://discuss.elastic.co/t/the-ignored-field-not-working/310460/6 "2022-09-12T08:16:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
