# When i use analyzer default as type keyword then it not search uppercase data

**URL:** <https://discuss.elastic.co/t/when-i-use-analyzer-default-as-type-keyword-then-it-not-search-uppercase-data/53933>\
**Category:** Elasticsearch\
**Created:** [June 25, 2016, 7:02am UTC](https://discuss.elastic.co/t/when-i-use-analyzer-default-as-type-keyword-then-it-not-search-uppercase-data/53933 "2016-06-25T07:02:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajay\_rathod](https://avatars.discourse-cdn.com/v4/letter/a/c77e96/32.png) [@ajay\_rathod](https://discuss.elastic.co/u/ajay_rathod)\
**Post date:** [June 25, 2016, 7:02am UTC](https://discuss.elastic.co/t/when-i-use-analyzer-default-as-type-keyword-then-it-not-search-uppercase-data/53933/1 "2016-06-25T07:02:23Z")

</div>

this is my index with settings and mapping

```auto
PUT /demo?update_all_types=true
{
  "settings": {
         "index": {
            "indices": {
               "fielddata": {
                  "cache": {
                     "cleanup_interval": "1h"
                  }
               }
            },
            "mappings": {
               "motadata_type": {
                  "dynamic_templates": [
                     {
                        "not_analyzed": {
                           "match": "*",
                           "match_mapping_type": "string",
                           "mapping": {
                              "type": "string",
                              "analyzer": "not_analyzed"
                           }
                        }
                     }
                  ]
               }
            },
            "compound_on_flush": "false",
            "refresh_interval": "-1",
            "number_of_shards": "4",
            "compound_format": "false",
            "creation_date": "1466404451223",
            "analysis": {
               "analyzer": {
                  "default": {
                     "type": "keyword"
                  }
               }
            },
            "number_of_replicas": "1",
            "uuid": "hbjUgpNvQkGn-uXyjppCXw",
            "version": {
               "created": "2030199"
            }
         }
      },
  "mappings": {
      "syslog-parser": {
            "_routing": {
               "required": true
            },
            "properties": {
               "raw-message": {
                  "type": "string",
                  "analyzer": "standard"
               }
            }
         },
         "linux-metric-collector": {
            "_routing": {
               "required": true
            },
            "properties": {
               "network-in-traffic": {
                  "type": "long"
               },
               "os-name": {
                  "type": "string"
               },
               "raw-message": {
                  "type": "string",
                  "analyzer": "standard"
               },
               "sec-dept-id": {
                  "type": "string"
               },
               "source-type": {
                  "type": "string"
               },
               "status": {
                  "type": "string"
               },
               "status-code": {
                  "type": "long"
               },
              
               "timestamp": {
                  "type": "date",
                  "format": "strict_date_optional_time||epoch_millis"
               },
               "timezone": {
                  "type": "string"
               },
               "uptime": {
                  "type": "string"
               },
               "vendor ": {
                  "type": "string"
               }
            }
         }
   }
}

```

this is my data

```auto
PUT demo/linux-metric-collector/1?routing=192.168.1.117
{
               "memory": 81,
               "timezone": "-12:00",
               "os-name": "GNU/Linux",
               "cpu-cores": 2,
               "network-in-traffic": 0,
               "vendor ": "GenuineIntel",
               "uptime": "0 days 5 hours 2 minutes",
               "status": "up"
}

```

in this data i want to search in os-name is GNU/Linux but it not search any thing

my query

```auto
GET demo/_search
{
    "query": {
        "query_string": {

           "query": "os-name:Linux"

        }
    },
    "aggs":
    {
        "demo1":{
            "terms":{
                "field":"os-name"
            }
        }
    }
}

```

it will return this

```auto
{
   "took": 8,
   "timed_out": false,
   "_shards": {
      "total": 4,
      "successful": 4,
      "failed": 0
   },
   "hits": {
      "total": 0,
      "max_score": null,
      "hits": []
   },
   "aggregations": {
      "demo1": {
         "doc_count_error_upper_bound": 0,
         "sum_other_doc_count": 0,
         "buckets": []
      }
   }
}

```

im not able to search uppercase letter why?

in my mapping or setting have any problem

please give me solution .

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 25, 2016, 8:19am UTC](https://discuss.elastic.co/t/when-i-use-analyzer-default-as-type-keyword-then-it-not-search-uppercase-data/53933/2 "2016-06-25T08:19:53Z")

</div>

Please format your code.

You defined a keyword analyzer so your string "GNU/Linux" has been indexed as "GNU/Linux" which is not "Linux".

That's why it does not match.

---

<div class="post-metadata">

**Author:** ![ajay\_rathod](https://avatars.discourse-cdn.com/v4/letter/a/c77e96/32.png) [@ajay\_rathod](https://discuss.elastic.co/u/ajay_rathod)\
**Post date:** [June 25, 2016, 11:48am UTC](https://discuss.elastic.co/t/when-i-use-analyzer-default-as-type-keyword-then-it-not-search-uppercase-data/53933/3 "2016-06-25T11:48:45Z")

</div>

sir,

when i write GNU/Linux or any uppercase word it not return any answer

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 27, 2016, 7:44am UTC](https://discuss.elastic.co/t/when-i-use-analyzer-default-as-type-keyword-then-it-not-search-uppercase-data/53933/4 "2016-06-27T07:44:09Z")

</div>

This example gives the expected result:

```auto
DELETE demo
PUT demo/linux-metric-collector/1
{
 "os-name": "GNU/Linux"
}
GET demo/_search
{
    "query": {
        "query_string": {
          "query": "os-name:Linux"
        }
    }
}

```

```auto
{
  "took": 5,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "failed": 0
  },
  "hits": {
    "total": 1,
    "max_score": 0.625,
    "hits": [
      {
        "_index": "demo",
        "_type": "linux-metric-collector",
        "_id": "1",
        "_score": 0.625,
        "_source": {
          "os-name": "GNU/Linux"
        }
      }
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:40pm UTC](https://discuss.elastic.co/t/when-i-use-analyzer-default-as-type-keyword-then-it-not-search-uppercase-data/53933/5 "2017-07-05T22:40:21Z")

</div>


