# Why would you use the '\_all' field?

**URL:** <https://discuss.elastic.co/t/why-would-you-use-the--all-field/1011>\
**Category:** Elasticsearch\
**Created:** [May 20, 2015, 5:45pm UTC](https://discuss.elastic.co/t/why-would-you-use-the--all-field/1011 "2015-05-20T17:45:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![spuder](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spuder/32/44895_2.png) [@spuder](https://discuss.elastic.co/u/spuder)\
**Post date:** [May 20, 2015, 5:45pm UTC](https://discuss.elastic.co/t/why-would-you-use-the--all-field/1011/1 "2015-05-20T17:45:32Z")

</div>

According to the documentation, the \_all field is useful if you want to search without knowing exactly which field to search on.

> The idea of the \_all field is that it includes the text of one or more other fields within the document indexed. It can come very handy especially for search requests, where we want to execute a search query against the content of a document, without knowing which fields to search on.

[https://www.elastic.co/guide/en/elasticsearch/reference/1.4//mapping-all-field.html](https://www.elastic.co/guide/en/elasticsearch/reference/1.4//mapping-all-field.html)

Under what circumstances would you want to turn this off?

The reason I ask, is I am using ELK for logging and [I'm having performance problems](http://stackoverflow.com/questions/29926637/elasticsearch-kibana-field-data-too-large), and an apache solr expert recommended that I turn '\_all' off. I want to understand before I make any changes.

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [May 20, 2015, 9:36pm UTC](https://discuss.elastic.co/t/why-would-you-use-the--all-field/1011/2 "2015-05-20T21:36:58Z")

</div>

In short, `_all` makes your index a bit larger and slower to index. However at search time it makes it convenient to not have to know which field to search on, it is also likely faster to search on the `_all` field than running a multi-match query on several fields.

That said, `_all` is mostly about ease of use of elasticsearch. If you know what you are doing, you can disable it and specify explicitly fields that you want to search on.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:12am UTC](https://discuss.elastic.co/t/why-would-you-use-the--all-field/1011/3 "2017-07-06T00:12:54Z")

</div>


