_ignored field
The _ignored field indexes and stores the names of every field in a document that has been ignored when the document was indexed. This can, for example, be the case:
- When the field was malformed and
ignore_malformedwas turned on. - When a
keywordfield’s value exceeds its optionalignore_abovesetting. - When
index.mapping.total_fields.limithas been reached andindex.mapping.total_fields.ignore_dynamic_beyond_limitis set totrue. -
When a field in a columnarindex configured withdoc_values.on_failure: ignorereceives a document that violates itsmulti_value: falseornullability: falseconstraint.
For more index setting details, refer to Mapping limit settings.
This field is searchable with term, terms and exists queries, and is returned as part of the search hits.
For instance the below query matches all documents that have one or more fields that got ignored:
GET _search
{
"query": {
"exists": {
"field": "_ignored"
}
}
}
Similarly, the below query finds all documents whose @timestamp field was ignored at index time:
GET _search
{
"query": {
"term": {
"_ignored": "@timestamp"
}
}
}
Since 8.15.0, the _ignored field supports aggregations as well. For example, the below query finds all fields that got ignored:
GET _search
{
"aggs": {
"ignored_fields": {
"terms": {
"field": "_ignored"
}
}
}
}