# Why do terms\_stats split my key\_field "url"?

**URL:** <https://discuss.elastic.co/t/why-do-terms-stats-split-my-key-field-url/8969>\
**Category:** Elasticsearch\
**Created:** [September 10, 2012, 5:17am UTC](https://discuss.elastic.co/t/why-do-terms-stats-split-my-key-field-url/8969 "2012-09-10T05:17:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![chenryn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chenryn/32/44917_2.png) [@chenryn](https://discuss.elastic.co/u/chenryn)\
**Post date:** [September 10, 2012, 5:17am UTC](https://discuss.elastic.co/t/why-do-terms-stats-split-my-key-field-url/8969/1 "2012-09-10T05:17:35Z")

</div>

hello everyone.  
I use elasticsearch to store my access.log.and I want to get count/avg etc group by request url.  
the JSON to index as follow(created by logstash):  
{  
"@timestamp" : "2012-09-04T13:38:59.496888Z",  
"@tags" : [],  
"@fields" : {  
"reqtime" : [  
0.016  
],  
"req" : [  
"/fmn056/20120812/1645/tiny\_r3N9\_236f000036ad118d.jpg"  
],  
"version" : [  
"1.1"  
],  
"useragent" : [  
""Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)""  
],  
"port" : [  
"80"  
],  
"size" : [  
2360  
],  
"client" : [  
"210.56.223.176"  
],  
"upstream" : [  
"10.9.18.50"  
],  
"method" : [  
"GET"  
],  
"referer" : [  
"[photo.renren.com](http://photo.renren.com)",  
"/photo/420723228/photo-6408408309?psource=3&fromVIP=false"  
],  
"ZONE" : [  
"+0800"  
],  
"code" : [  
200  
],  
"upstime" : [  
0.016  
]  
},  
"@source\_path" : "//data/nginx/logs/access.log",  
"@source" : "file://DBLYD5-32.opi.com//data/nginx/logs/access.log",  
"@message" : "[04/Sep/2012:21:38:59 +0800] 200 210.56.223.176 [fmn.rrimg.com](http://fmn.rrimg.com) GET /fmn056/20120812/1645/tiny\_r3N9\_236f000036ad118d.jpg HTTP/1.1 10.9.18.50:80 0.016 0.016 2360 "[http://photo.renren.com/photo/420723228/photo-6408408309?psource=3&fromVIP=false](http://photo.renren.com/photo/420723228/photo-6408408309?psource=3&fromVIP=false)" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)" "-"",  
"@source\_host" : "[DBLYD5-32.opi.com](http://DBLYD5-32.opi.com)",  
"@type" : "nginx"  
}

```
And I wrote request as follow(use perl module ElasticSearch.pm):

```

$elsearch-\>search(  
index =\> 'logstash',  
type =\> 'nginx',  
query =\> {  
text =\> { code =\> '200' }  
},  
facets =\> {  
"request" =\> {  
"terms\_stats" =\> {  
"value\_field" =\> "reqtime",  
"key\_field" =\> "req",  
}  
}  
}  
);

But I got a splited response like:  
'terms' =\> [  
{  
'count' =\> 740364,  
'min' =\> '0.016',  
'max' =\> '0.016',  
'mean' =\> '0.0159999999999977',  
'total' =\> '11845.8239999983',  
'total\_count' =\> 740364,  
'term' =\> 'tiny\_r3n9\_236f000036ad118d.jpg'  
},  
{  
'count' =\> 740364,  
'min' =\> '0.016',  
'max' =\> '0.016',  
'mean' =\> '0.0159999999999977',  
'total' =\> '11845.8239999983',  
'total\_count' =\> 740364,  
'term' =\> 'fmn056'  
},  
{  
'count' =\> 740364,  
'min' =\> '0.016',  
'max' =\> '0.016',  
'mean' =\> '0.0159999999999977',  
'total' =\> '11845.8239999983',  
'total\_count' =\> 740364,  
'term' =\> '20120812'  
},  
{  
'count' =\> 740364,  
'min' =\> '0.016',  
'max' =\> '0.016',  
'mean' =\> '0.0159999999999977',  
'total' =\> '11845.8239999983',  
'total\_count' =\> 740364,  
'term' =\> '1645'  
}  
],  
the "req\_url" is splited with '/'.  
Anyone can help me?

---

<div class="post-metadata">

**Author:** ![chenryn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chenryn/32/44917_2.png) [@chenryn](https://discuss.elastic.co/u/chenryn)\
**Post date:** [September 10, 2012, 10:41am UTC](https://discuss.elastic.co/t/why-do-terms-stats-split-my-key-field-url/8969/2 "2012-09-10T10:41:02Z")

</div>

well, I learn analyzer now.And after reindex with analyzer:"whitespace", I can terms\_stat whole "url" field now.  
But, can I change analyzer of the exist index mapper? And can I disable all analyzer by configure? Because I can't change the create post in logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:13am UTC](https://discuss.elastic.co/t/why-do-terms-stats-split-my-key-field-url/8969/3 "2017-07-06T03:13:23Z")

</div>


