# Understanding ELK Analyzer

**URL:** <https://discuss.elastic.co/t/understanding-elk-analyzer/83322>\
**Category:** Elasticsearch\
**Created:** [April 23, 2017, 12:44pm UTC](https://discuss.elastic.co/t/understanding-elk-analyzer/83322 "2017-04-23T12:44:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![boCyrill](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bocyrill/32/17114_2.png) [@boCyrill](https://discuss.elastic.co/u/boCyrill)\
**Post date:** [April 23, 2017, 12:44pm UTC](https://discuss.elastic.co/t/understanding-elk-analyzer/83322/1 "2017-04-23T12:44:05Z")

</div>

Hi all,  
Am newby to ELK 5.1.1 stack and I have a few questions just for my understanding.  
I have setup this stack basicaly with standard analyzers / filters and everything works great.  
My data source is a MySQL backend that I index using Logstash.  
I would like to deal with queries containing accents and hopefully `asciifolding` token filter can help achieve this.

First I learned out how to create custom analyzer and save as template.  
Right now when I query this url `http://localhost:9200/_template?pretty` I have 2 templates: the logstash default template named `logstash` and my custom template which settings are:

```
"custom_template" : {
    "order" : 1,
    "template" : "doo*",
    "settings" : {
        "index" : {
            "analysis" : {
                "analyzer" : {
                    "myCustomAnalyzer" : {
                        "filter" : [
                            "standard",
                            "lowercase",
                            "asciifolding"
                        ],
                        "tokenizer" : "standard"
                   }
               }
         },
        "refresh_interval" : "5s"
     }
    },
    "mappings" : { },
    "aliases" : { }
}

```

Searching for the keyword `Yaoundé` returns 70 hits but when I search for `Yaounde` I keep having no hit.  
Below is my query for the second case

```
{
"query": {
    "query_string": {
        "query": "yaounde",
        "fields": [
            "title"
        ]
    }
},
"from": 0,
"size": 10
}

```

Please can somebody help me guess what am doing wrong here?  
Also knowing that my data is analyzed by Logstash during the index process do I really have to specify that the analyzer `myCustomAnalyzer` should be applied during the research as per this second query ?

```
{
     "query": {
    "query_string": {
        "query": "yaounde",
        "fields": [
            "title"
        ],
        "analyzer": "myCustomAnalyzer"
    }
},
"from": 0,
"size": 10
}

```

Here is a sample of the output part of my logstash config file

```
output {
stdout { codec => json_lines }
if [type] == "announces" {
    elasticsearch {  
        hosts => "localhost:9200"
        document_id => "%{job_id}"
        index => "dooone"
	document_type => "%{type}"
    }
} else {
    elasticsearch {  
        hosts => "localhost:9200"
	document_id => "%{uid}"
	index => "dootwo"
	document_type => "%{type}"
    }
}
}

```

Thank You

---

<div class="post-metadata">

**Author:** ![boCyrill](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bocyrill/32/17114_2.png) [@boCyrill](https://discuss.elastic.co/u/boCyrill)\
**Post date:** [April 24, 2017, 4:04pm UTC](https://discuss.elastic.co/t/understanding-elk-analyzer/83322/2 "2017-04-24T16:04:23Z")

</div>

My problem is finally solved.  
Just for those that could have the same problem, the solution was to define the field settings in the mapping section of the template `"mapping" : {#here}`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2017, 4:11pm UTC](https://discuss.elastic.co/t/understanding-elk-analyzer/83322/3 "2017-05-22T16:11:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
