# Unanalyzed fields

**URL:** <https://discuss.elastic.co/t/unanalyzed-fields/37272>\
**Category:** Kibana\
**Created:** [December 15, 2015, 7:08pm UTC](https://discuss.elastic.co/t/unanalyzed-fields/37272 "2015-12-15T19:08:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![OscarCrespo](https://avatars.discourse-cdn.com/v4/letter/o/3da27b/32.png) [@OscarCrespo](https://discuss.elastic.co/u/OscarCrespo)\
**Post date:** [December 15, 2015, 7:08pm UTC](https://discuss.elastic.co/t/unanalyzed-fields/37272/1 "2015-12-15T19:08:21Z")

</div>

hi, i need help to correct kibana field. when I try to visualizing the fields, shown me the following warning:

> "Careful! The field contains Analyzed selected strings. Analyzed strings are highly unique and can use a lot of memory to visualize. Values: such as bar will be foo-foo and bar broken into. See Core Mapping Types for more information on setting esta field Analyzed as not "

someone know how fix this problem?

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [December 15, 2015, 7:44pm UTC](https://discuss.elastic.co/t/unanalyzed-fields/37272/2 "2015-12-15T19:44:09Z")

</div>

Can you share the Elasticsearch mapping for the index pattern you are using in Kibana? And what is the name of the field you are trying to use here?

---

<div class="post-metadata">

**Author:** ![OscarCrespo](https://avatars.discourse-cdn.com/v4/letter/o/3da27b/32.png) [@OscarCrespo](https://discuss.elastic.co/u/OscarCrespo)\
**Post date:** [December 15, 2015, 8:06pm UTC](https://discuss.elastic.co/t/unanalyzed-fields/37272/3 "2015-12-15T20:06:33Z")

</div>

Well, all fields have this warning....

i'll upload the notepad because they are many lines

[txt of mapping](https://www.dropbox.com/s/8hjhabr36djeh5l/mapping.txt?dl=0)

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [December 16, 2015, 12:09am UTC](https://discuss.elastic.co/t/unanalyzed-fields/37272/4 "2015-12-16T00:09:05Z")

</div>

It looks like you need to index the string fields you want to use in Kibana as `not_analyzed`. You can do this in one of two ways:

- Change each string field mapping to `{ "type": "string", "index": "not_analyzed" }`. Then you can use these fields in Kibana.

OR

- Change each string field mapping to `{ "type": "string", "fields": { "raw": { "type": "string", "index": "not_analyzed" } } }`. This will analyze the original field (say `foo`) in the index but also create a new field, `foo.raw` which will not be analyzed. You would then use the `foo.raw` field in Kibana.

Either way, you will probably want to reindex your data after updating the mapping so the changes are applied to old data as well as future data.

Also, it looks like you are using time-based indices (based on the index names, firewall-YYYY.MM.DD). This means you are probably using an index template. Make sure any mapping changes you make are made to that template.

---

<div class="post-metadata">

**Author:** ![OscarCrespo](https://avatars.discourse-cdn.com/v4/letter/o/3da27b/32.png) [@OscarCrespo](https://discuss.elastic.co/u/OscarCrespo)\
**Post date:** [January 18, 2016, 8:40pm UTC](https://discuss.elastic.co/t/unanalyzed-fields/37272/5 "2016-01-18T20:40:33Z")

</div>

thank you, solved

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:04pm UTC](https://discuss.elastic.co/t/unanalyzed-fields/37272/6 "2017-07-06T14:04:44Z")

</div>


