SkillByAIOpen interactive version →

Lesson 5 / 25

Field Types: text, keyword and Friends

The type decides what queries can do.

Choosing field types

text fields are analysed into terms for full-text search (match) but are not used for sorting or terms aggregations by default. keyword fields are indexed as a single exact value and are right for ids, statuses, tags, email addresses, sorting and aggregations. Numbers (integer, long, float, scaled_float, ...), date (with a format), boolean, ip and geo_point behave as you would expect. An object field flattens inner fields; a nested field indexes each array element as a hidden document so that conditions on one element stay together. Multi-fields (fields) index the same value in more than one way, the classic example being text with a .keyword sub-field.

A product mapping with multi-fields

Kibana Dev Tools console syntax; send the same requests with curl or a client library.

PUT /products
{
  "mappings": {
    "properties": {
      "sku":        { "type": "keyword" },
      "name": {
        "type": "text",
        "fields": { "raw": { "type": "keyword", "ignore_above": 256 } }
      },
      "description": { "type": "text" },
      "brand":      { "type": "keyword" },
      "price":      { "type": "scaled_float", "scaling_factor": 100 },
      "in_stock":   { "type": "boolean" },
      "created_at": { "type": "date", "format": "strict_date_optional_time||epoch_millis" },
      "variants": {
        "type": "nested",
        "properties": {
          "color": { "type": "keyword" },
          "size":  { "type": "keyword" }
        }
      }
    }
  }
}

text for searching, keyword for filtering

Search name with match; filter, sort and aggregate on name.raw or brand. Running a term query against a text field is a classic bug, because the stored terms are lower-cased tokens, not the original string.

Quick check: Which field type fits a status value used for exact filters and terms aggregations?

  • text
  • keyword
  • nested
  • dense_vector
Answer

keyword — keyword stores the exact value and supports aggregations via doc values.