ignore_above
Strings longer than the ignore_above setting will not be indexed or stored. For arrays of strings, ignore_above will be applied for each array element separately and string elements longer than ignore_above will not be indexed or stored.
All strings/array elements will still be present in the _source field, if the latter is enabled which is the default in Elasticsearch.
ignore_above has no effect. Columnar _source is reconstructed from doc values, so a dropped value would be lost entirely; every value is stored regardless of length, whether or not the field is indexed. This covers the field-level parameter, the index.mapping.ignore_above setting, and index-mode defaults. The parameter is still accepted and echoed back by GET _mapping, over-limit values remain searchable and retrievable, and the field is not added to _ignored. Because nothing is dropped, ignore_above no longer shields you from Lucene's term byte-length limit: a value longer than 32766 bytes fails the indexing request. Columnar indices created before 9.6 keep the previous behavior.
PUT my-index-000001
{
"mappings": {
"properties": {
"message": {
"type": "keyword",
"ignore_above": 20
}
}
}
}
PUT my-index-000001/_doc/1
{
"message": "Syntax error"
}
PUT my-index-000001/_doc/2
{
"message": "Syntax error with some long stacktrace"
}
GET my-index-000001/_search
{
"aggs": {
"messages": {
"terms": {
"field": "message"
}
}
}
}
- This field will ignore any string longer than 20 characters.
- This document is indexed successfully.
- This document will be indexed, but without indexing the
messagefield. - Search returns both documents, but only the first is present in the terms aggregation.
The ignore_above setting can be updated on existing fields using the update mapping API.
Outside columnar index modes, this option is also useful for protecting against Lucene’s term byte-length limit of 32766.
The value for ignore_above is the character count, but Lucene counts bytes. If you use UTF-8 text with many non-ASCII characters, you may want to set the limit to 32766 / 4 = 8191 since UTF-8 characters may occupy at most 4 bytes.