# Understand "enable: false" mapping setting

**URL:** <https://discuss.elastic.co/t/understand-enable-false-mapping-setting/270084>\
**Category:** Elasticsearch\
**Created:** [April 14, 2021, 7:46am UTC](https://discuss.elastic.co/t/understand-enable-false-mapping-setting/270084 "2021-04-14T07:46:02Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [April 14, 2021, 7:46am UTC](https://discuss.elastic.co/t/understand-enable-false-mapping-setting/270084/1 "2021-04-14T07:46:02Z")

</div>

Hello all !

I'm trying to understand "enable: false" mapping setting

I don't want to index a specific field : **syslog\_timestamp**

To achieve this, I mapped this field with "enabled: false" like this (extract of Index management -\> index -\> Mappings in Kibana) :

```
{
  "mappings": {
    "_doc": {
      "dynamic": "false",
      "properties": {
        "@timestamp": {
          "type": "date"
        },
        "syslog_timestamp": {
          "type": "object",
          "enabled": false
        },
        "type": {
          "type": "keyword"
        }
      }
    }
  }
}

```

When looking at my log in Kibana, I can see this field :

 ![enabled](https://us1.discourse-cdn.com/elastic/original/3X/4/9/49ffae577aab41a927bb19d7e8fe8005ed09d017.png)

**Question** : Is it normal I still can see this field as he is not enabled ?

Documentation says that :

> The JSON can still be retrieved from the [`_source`](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping-source-field.html) field, but it is not searchable or stored in any other way

For me, "not stored" means field can't be retrived in Kibana

Thanks for your help !

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 14, 2021, 8:19am UTC](https://discuss.elastic.co/t/understand-enable-false-mapping-setting/270084/2 "2021-04-14T08:19:57Z")

</div>

What happens if you refresh the mapping there in Kibana, does that warning go away?

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [April 14, 2021, 8:25am UTC](https://discuss.elastic.co/t/understand-enable-false-mapping-setting/270084/3 "2021-04-14T08:25:25Z")

</div>

No...I refreshed and still there. I deleted index pattern and re created it but still there too  
In index pattern, I can't see the field but I can see it in Discover

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 14, 2021, 8:27am UTC](https://discuss.elastic.co/t/understand-enable-false-mapping-setting/270084/4 "2021-04-14T08:27:22Z")

</div>

I may be wrong, but I guess Kibana is parsing the `_source` and showing it. And even after refreshing it shows that warning as it has no mapping for it.

So it's stored in `_source`, but not mapped and not searchable.

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [April 14, 2021, 8:30am UTC](https://discuss.elastic.co/t/understand-enable-false-mapping-setting/270084/5 "2021-04-14T08:30:50Z")

</div>

Yes indeed he is not seachable I tested it.

I guees there is no way to tell to Kibana to not show fields which are not enbabled ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 14, 2021, 8:31am UTC](https://discuss.elastic.co/t/understand-enable-false-mapping-setting/270084/6 "2021-04-14T08:31:48Z")

</div>

I am not sure. It might be worth creating a new topic in #elastic-stack:kibana and asking the team there.

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [April 14, 2021, 8:34am UTC](https://discuss.elastic.co/t/understand-enable-false-mapping-setting/270084/7 "2021-04-14T08:34:55Z")

</div>

Ok I will do that. Thank you @warkolm ! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2021, 8:35am UTC](https://discuss.elastic.co/t/understand-enable-false-mapping-setting/270084/8 "2021-05-12T08:35:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
