# Trying to set not\_analyzed to a field

**URL:** <https://discuss.elastic.co/t/trying-to-set-not-analyzed-to-a-field/23490>\
**Category:** Elasticsearch\
**Created:** [April 30, 2015, 12:57pm UTC](https://discuss.elastic.co/t/trying-to-set-not-analyzed-to-a-field/23490 "2015-04-30T12:57:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Darius\_Seroka](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@Darius\_Seroka](https://discuss.elastic.co/u/Darius_Seroka)\
**Post date:** [April 30, 2015, 12:57pm UTC](https://discuss.elastic.co/t/trying-to-set-not-analyzed-to-a-field/23490/1 "2015-04-30T12:57:17Z")

</div>

I have a setup where I am shipping windows eventlogs using nxlog in JSON  
format towards logstash which gets put into an elasticsearch cluster. The  
"Message" field is currently being analysed which means that if I want to  
visualise on Kibana all events sorted by Message the Message field gets  
split by whitespace. I have read several posts regarding this topic and the  
below docs  
like [http://www.elastic.co/guide/en/elasticsearch/reference/1.x/mapping.html](http://www.elastic.co/guide/en/elasticsearch/reference/1.x/mapping.html)  
and [http://www.elastic.co/guide/en/elasticsearch/reference/1.3/indices-templates.html](http://www.elastic.co/guide/en/elasticsearch/reference/1.3/indices-templates.html)  
but I still have issue.

I have modified my logstash template to this, hoping the new created index  
for today would not have this field analyzed anymore but its still not so.

curl -XPUT localhost:9200/\_template/logstash -d '  
{  
"order" : 0,  
"template" : "[logstash-]YYYY.MM.DD",  
"settings" : {  
"index.refresh\_interval" : "5s"  
},  
"mappings" : {  
"_default_" : {  
"dynamic\_templates" : [ {  
"string\_fields" : {  
"mapping" : {  
"index" : "analyzed",  
"omit\_norms" : true,  
"type" : "string",  
"fields" : {  
"raw" : {  
"index" : "not\_analyzed",  
"ignore\_above" : 256,  
"type" : "string"  
},  
"Message" : {  
"index" : "not\_analyzed",  
"type" : "string"  
}  
}  
},  
"match\_mapping\_type" : "string",  
"match" : "\*"  
}  
} ],  
"properties" : {  
"geoip" : {  
"dynamic" : true,  
"path" : "full",  
"properties" : {  
"location" : {  
"type" : "geo\_point"  
}  
},  
"type" : "object"  
},  
"@version" : {  
"index" : "not\_analyzed",  
"type" : "string"  
}  
},  
"\_all" : {  
"enabled" : true  
}  
}  
},  
"aliases" : { }  
}  
'

My mapping for today seems to have this field, but I must admit I now  
suspect I am adding this field definition the wrong way. Anyone have any  
pointers or a better way how to get the visualisation sorted out so the  
Message is not split by the whitespaces.

curl -XGET localhost:9200/\_mapping?pretty | less  
"logstash-2015.04.30" : {  
"mappings" : {  
"_default_" : {  
"dynamic\_templates" : [ {  
"string\_fields" : {  
"mapping" : {  
"index" : "analyzed",  
"omit\_norms" : true,  
"type" : "string",  
"fields" : {  
"raw" : {  
"index" : "not\_analyzed",  
"ignore\_above" : 256,  
"type" : "string"  
},  
"Message" : {  
"index" : "not\_analyzed",  
"type" : "string"  
}  
}  
},  
"match" : "\*",  
"match\_mapping\_type" : "string"  
}  
} ],  
"\_all" : {  
"enabled" : true  
},  
"properties" : {  
"@version" : {  
"type" : "string",  
"index" : "not\_analyzed"  
},  
"geoip" : {  
"dynamic" : "true",  
"properties" : {  
"location" : {  
"type" : "geo\_point"  
}  
}  
}  
}  
},

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/ac93ef48-3556-4e23-b733-05e9ae2c3b95%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ac93ef48-3556-4e23-b733-05e9ae2c3b95%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:16am UTC](https://discuss.elastic.co/t/trying-to-set-not-analyzed-to-a-field/23490/2 "2017-07-06T00:16:45Z")

</div>


