# What if I don't set index.query.default\_field?

**URL:** https://discuss.elastic.co/t/what-if-i-dont-set-index-query-default-field/299108
**Category:** Elasticsearch
**Created:** [March 8, 2022, 2:56pm UTC](https://discuss.elastic.co/t/what-if-i-dont-set-index-query-default-field/299108 "2022-03-08T14:56:34Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![mikewillis](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@mikewillis](https://discuss.elastic.co/u/mikewillis)
#### Post date: [March 8, 2022, 2:56pm UTC](https://discuss.elastic.co/t/what-if-i-dont-set-index-query-default-field/299108/1 "2022-03-08T14:56:34Z")

</div>

Our cluster is still running Elasticsearch 6.8, so I'm looking at getting it upgraded to Elasticsearch 7. The Kibana Upgrade Assistant is flagging a couple of hundred indices with this message

> This index has [4234] fields, which exceeds the automatic field expansion limit of 1024 and does not have [index.query.default\_field] set, which may cause queries which use automatic field expansion, such as query\_string, simple\_query\_string, and multi\_match to fail if fields are not explicitly specified in the query.

The warning message says that queries "may" fail. Which I take to mean they may not fail. I can't find information about what exactly failure means in this context, (unexpected results? an error message? both? other?) or what would determine if a search fails or not.

If, with Elasticsearch 7, someone tries to do a search in Kibana on an index with 4234 fields without specifying a field and `index.query.default_field` isn't set, what might happen?

Essentially, how about if instead of having conversations with people about what `index.query.default_field` should be set to on various indices, I just ignore the warning?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 8, 2022, 2:56pm UTC](https://discuss.elastic.co/t/what-if-i-dont-set-index-query-default-field/299108/2 "2022-03-08T14:56:35Z")

</div>

Elasticsearch 6.8 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [March 8, 2022, 10:40pm UTC](https://discuss.elastic.co/t/what-if-i-dont-set-index-query-default-field/299108/3 "2022-03-08T22:40:28Z")

</div>

> [@mikewillis](#):
>
> I can't find information about what exactly failure means in this context

Basically, you may get no results.

---

<div class="post-metadata">

### Author: ![mikewillis](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@mikewillis](https://discuss.elastic.co/u/mikewillis)
#### Post date: [March 10, 2022, 2:33pm UTC](https://discuss.elastic.co/t/what-if-i-dont-set-index-query-default-field/299108/4 "2022-03-10T14:33:49Z")

</div>

What determines whether you do or do not get results? Does Elasticsearch somehow choose 1024 out of however many fields there are and do the search on those and if what you'll looking for is in one of those 1024 you get results, otherwise you don't?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 7, 2022, 2:34pm UTC](https://discuss.elastic.co/t/what-if-i-dont-set-index-query-default-field/299108/5 "2022-04-07T14:34:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
