# Before Mapping

**URL:** <https://discuss.elastic.co/t/before-mapping/241837>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 20, 2020, 5:15am UTC](https://discuss.elastic.co/t/before-mapping/241837 "2020-07-20T05:15:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [July 20, 2020, 5:15am UTC](https://discuss.elastic.co/t/before-mapping/241837/1 "2020-07-20T05:15:56Z")

</div>

I am using filebeat and i would like to know that to create a mapping do i need to know the field name or should i start the filebeat and analyse that these the fields are coming i can see in kibana discover and after that i start with mapping

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [July 20, 2020, 9:28am UTC](https://discuss.elastic.co/t/before-mapping/241837/2 "2020-07-20T09:28:25Z")

</div>

Hi @Aniket_Pant 🙂

If you know your input data, it's always better to define your own mapping for 2 main reasons:

- You can leave out fields that you aren't going to query later hence saving disk space.
- You can define multi-field mapping in fields where you feel like you may need it. This is very common in fields where you need a text and a keyword mapping, a date field or when you define a geo point which isn't captured by the automatic mapping.

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [July 20, 2020, 10:55am UTC](https://discuss.elastic.co/t/before-mapping/241837/3 "2020-07-20T10:55:37Z")

</div>

Thank you so much for your reply but my strategy to this mapping is that i have to install beat in my system then in kibana i analysed which fields are coming then i create mapping but this is not a good way. Sometime i install packetbeat and think that whatever the beat i installed they have common field agen.type ,agent.name,host.ip etc, i can create mapping for those field but what about other fields

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [July 21, 2020, 10:52am UTC](https://discuss.elastic.co/t/before-mapping/241837/4 "2020-07-21T10:52:29Z")

</div>

Beats comes with their own mappings that are usually "installed" into Elasticsearch with the `setup` commands like `metricbeat setup`. If it's just to use Beats, you should not be worried about mappings at all.

Just to clarify, you should not be mixing your own data with the Beats data in the same index. Create an index for your business data (which is where you should care most about the mappings)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2020, 12:52pm UTC](https://discuss.elastic.co/t/before-mapping/241837/5 "2020-08-18T12:52:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
