In order to control how fields are mapped you need to create an index template.
Logstash configuration can change how the data being sent to Elasticsearch is structured, but does not control how the fields are mapped once Elasticsearch receives the data.