# Unable to disable analyzed

**URL:** <https://discuss.elastic.co/t/unable-to-disable-analyzed/36083>\
**Category:** Elasticsearch\
**Created:** [December 1, 2015, 5:49pm UTC](https://discuss.elastic.co/t/unable-to-disable-analyzed/36083 "2015-12-01T17:49:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mc1392](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@mc1392](https://discuss.elastic.co/u/mc1392)\
**Post date:** [December 1, 2015, 5:49pm UTC](https://discuss.elastic.co/t/unable-to-disable-analyzed/36083/1 "2015-12-01T17:49:24Z")

</div>

I have field called 'PrimaryAssembly' that I don't want broken into tokens.  
For example, I don't want 'Allergy & Immunology' broken into 'Allergy' and 'Immunology'.  
I want those words whole for when I create a pie chart.

I tried using a custom index template by referencing it in my logstash config as so:

```
output{

        elasticsearch {
                index=>"assemblies"
                hosts => ["localhost:9200"]
                template => "/home/ubuntu/templates/assemblies_template.json"
        }

        stdout {codec=>rubydebug}

}

```

I tried setting my fields to "not\_analyzed", but this is not working.  
When I create a pie chart, my legend is still using tokenized words, 'allergy' and 'immunology'.

In addition, my raw fields are not showing up in Kibana.

Here is a portion of my template:  
{  
"template" : "assemblies",  
"settings" : {  
"index.refresh\_interval" : "5s"  
},  
"mappings" : {  
"_default_" : {  
"\_all" : {"enabled" : true, "omit\_norms" : true},  
"dynamic\_templates" : [ {  
"message\_field" : {  
"match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "string", "index" : "not\_analyzed", "omit\_norms" : true,  
"fielddata" : { "format" : "disabled" }  
}  
}  
}, {  
"string\_fields" : {  
"match" : "\*",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "string", "index" : "not\_analyzed", "omit\_norms" : true,  
"fielddata" : { "format" : "disabled" },  
"fields" : {  
"raw" : {"type": "string", "index" : "not\_analyzed", "doc\_values" : true, "ignore\_above" : 256}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 1, 2015, 5:57pm UTC](https://discuss.elastic.co/t/unable-to-disable-analyzed/36083/2 "2015-12-01T17:57:18Z")

</div>

Did you recreate and reindex the assemblies index? The index template only applies to new indexes.

---

<div class="post-metadata">

**Author:** ![mc1392](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@mc1392](https://discuss.elastic.co/u/mc1392)\
**Post date:** [December 1, 2015, 5:57pm UTC](https://discuss.elastic.co/t/unable-to-disable-analyzed/36083/3 "2015-12-01T17:57:53Z")

</div>

Yes, I did. both in elasticsearch and kibana.

---

<div class="post-metadata">

**Author:** ![mc1392](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@mc1392](https://discuss.elastic.co/u/mc1392)\
**Post date:** [December 1, 2015, 9:56pm UTC](https://discuss.elastic.co/t/unable-to-disable-analyzed/36083/4 "2015-12-01T21:56:48Z")

</div>

Ok, I realized I was doing this all wrong.  
What almost works is running a curl -XPUT command for the mapping I want.

I get better results, but I see my terms are getting grouped together.  
I get 'Term 1' , 'Term 2'. but some slices of the pie chart have 'Term 1, Term 2' merged together.

I got what I finally wanted by changing the metric from 'unique count' to count.  
I noticed the results and terms are different depending on how I 'Order by'

Thanks for the help! This seems to work!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:34pm UTC](https://discuss.elastic.co/t/unable-to-disable-analyzed/36083/5 "2017-07-05T23:34:19Z")

</div>


