# Confused about the "properties" and "fields" in my index template

**URL:** <https://discuss.elastic.co/t/confused-about-the-properties-and-fields-in-my-index-template/87502>\
**Category:** Elasticsearch\
**Created:** [May 30, 2017, 3:34am UTC](https://discuss.elastic.co/t/confused-about-the-properties-and-fields-in-my-index-template/87502 "2017-05-30T03:34:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![red888](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@red888](https://discuss.elastic.co/u/red888)\
**Post date:** [May 30, 2017, 3:34am UTC](https://discuss.elastic.co/t/confused-about-the-properties-and-fields-in-my-index-template/87502/1 "2017-05-30T03:34:23Z")

</div>

I used the default logstash template as a starting point and its working but Im confused about 2 things:

```
{
  "template": "logstash-myindex*",
  "settings": {
    "number_of_shards": 4,
    "number_of_replicas": 1
  },
  "order": 11,
  "mappings": {
    "_default_": {
      "dynamic": false,
      "_all": {
        "enabled": false
      },
      "properties": {
        "@timestamp": {
          "type": "date",
          "include_in_all": false
        },
        "@version": {
          "type": "keyword",
          "include_in_all": false
        },
        "myfield": {
          "type": "text",
          "norms": false,
          "fields": {
            "keyword": {
              "type": "keyword"
            }
          }
        },
        ... etc

```

I have all of the mappings for my fields nested under "properties" is this necessary? I'm not sure when I would use properties and when I would not.

Also, the "fields" setting under "myfield" is making "myfield" a "keyword" type in addition to a "text" type right? Is writing it this way just less verbose then defining it twice with each type?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 30, 2017, 3:37am UTC](https://discuss.elastic.co/t/confused-about-the-properties-and-fields-in-my-index-template/87502/2 "2017-05-30T03:37:24Z")

</div>

> [@red888](#):
>
> I have all of the mappings for my fields nested under "properties" is this necessary? I'm not sure when I would use properties and when I would not.

Yes you should, it refers to the properties of the type (the `_default_` part).

> [@red888](#):
>
> Also, the "fields" setting under "myfield" is making "myfield" a "keyword" type in addition to a "text" type right? Is writing it this way just less verbose then defining it twice with each type?

If you want it across multiple types and you don't want to define it separately in each type, yes.

Though be aware we are changing type in 6.0 - [Indices, types, and parent / child: current status and upcoming changes in Elasticsearch | Elastic Blog](https://www.elastic.co/blog/index-type-parent-child-join-now-future-in-elasticsearch)

---

<div class="post-metadata">

**Author:** ![red888](https://avatars.discourse-cdn.com/v4/letter/r/ecae2f/32.png) [@red888](https://discuss.elastic.co/u/red888)\
**Post date:** [May 30, 2017, 2:23pm UTC](https://discuss.elastic.co/t/confused-about-the-properties-and-fields-in-my-index-template/87502/3 "2017-05-30T14:23:04Z")

</div>

Awesome thanks!

Just so I understand how this works, when I look at my events I see a "myfield" and a "myfield.keyword".

If I want to do a full text search on the field I use "myfield" which is analyzed (tokenized).  
If there is a specific value I am looking for ( or to filter on ) I can use myfield.keyword.

I realized I have a bunch of my fields defined as "type": "text" AND "type": "keyword", but many of them are just ID fields that I would never need to do a full text search on. I could save space and indexing time by changing them to just keyword right?

If I did change it I would just change it to this right:

```
"myfield": {
  "type": "keyword",
  "norms": false,
  }

```

Also, I can still do wildcard searches on keyword fields right?

Sorry for all the questions thanks again.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 30, 2017, 11:29pm UTC](https://discuss.elastic.co/t/confused-about-the-properties-and-fields-in-my-index-template/87502/4 "2017-05-30T23:29:48Z")

</div>

> [@red888](#):
>
> If I want to do a full text search on the field I use "myfield" which is analyzed (tokenized).  
> If there is a specific value I am looking for ( or to filter on ) I can use myfield.keyword.

Yes, as long as the specific value is a 100% match (case and all).

> [@red888](#):
>
> I realized I have a bunch of my fields defined as "type": "text" AND "type": "keyword", but many of them are just ID fields that I would never need to do a full text search on. I could save space and indexing time by changing them to just keyword right?

Potentially, yes.

> [@red888](#):
>
> Also, I can still do wildcard searches on keyword fields right?

Yep - [Wildcard query | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-wildcard-query.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2017, 11:30pm UTC](https://discuss.elastic.co/t/confused-about-the-properties-and-fields-in-my-index-template/87502/5 "2017-06-27T23:30:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
