# Create properties with wildcard

**URL:** <https://discuss.elastic.co/t/create-properties-with-wildcard/142685>\
**Category:** Elasticsearch\
**Created:** [August 2, 2018, 6:28am UTC](https://discuss.elastic.co/t/create-properties-with-wildcard/142685 "2018-08-02T06:28:23Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![lvinyes](https://avatars.discourse-cdn.com/v4/letter/l/e95f7d/32.png) [@lvinyes](https://discuss.elastic.co/u/lvinyes)\
**Post date:** [August 2, 2018, 6:28am UTC](https://discuss.elastic.co/t/create-properties-with-wildcard/142685/1 "2018-08-02T06:28:23Z")

</div>

Hi,  
In a log from CISCO SFR there are two IP (source and destination) and I want to send with logstash to elasticsearch with geoip information.  
The logstash template in elasticsearch has only one property named geoip, and thus for to map a .location to geo\_point, I need to crate new mappings for the two geoip\_src and geoip\_dst properties.  
It's possible to create a template with a property like:  
"geoip\_\*" : {  
"dynamic" : true,  
"properties" : {  
"ip" : {  
"type" : "ip"  
},  
"location" : {  
"type" : "geo\_point"  
},  
"latitude" : {  
"type" : "half\_float"  
},  
"longitude" : {  
"type" : "half\_float"  
}  
}  
that can be used for all properties like geoip\_src, geoip\_dst, geoip\_whatever... without the need of creating mappings for all the geoip\_ variants,

Thank you.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 2, 2018, 6:46am UTC](https://discuss.elastic.co/t/create-properties-with-wildcard/142685/2 "2018-08-02T06:46:15Z")

</div>

Have a look at [https://www.elastic.co/guide/en/elasticsearch/reference/6.3/dynamic-templates.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/dynamic-templates.html)

---

<div class="post-metadata">

**Author:** ![lvinyes](https://avatars.discourse-cdn.com/v4/letter/l/e95f7d/32.png) [@lvinyes](https://discuss.elastic.co/u/lvinyes)\
**Post date:** [August 2, 2018, 7:04am UTC](https://discuss.elastic.co/t/create-properties-with-wildcard/142685/3 "2018-08-02T07:04:46Z")

</div>

Thank you, I used before this information for create single properties with wildcards but I do not know how to use for create complex properties like geoip.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 2, 2018, 7:19am UTC](https://discuss.elastic.co/t/create-properties-with-wildcard/142685/4 "2018-08-02T07:19:54Z")

</div>

I believe you need to apply it to each individual field with a name like `geoip_*.type`, `geoip_*.location`, ...

---

<div class="post-metadata">

**Author:** ![lvinyes](https://avatars.discourse-cdn.com/v4/letter/l/e95f7d/32.png) [@lvinyes](https://discuss.elastic.co/u/lvinyes)\
**Post date:** [August 2, 2018, 7:24am UTC](https://discuss.elastic.co/t/create-properties-with-wildcard/142685/5 "2018-08-02T07:24:06Z")

</div>

Thank you, I will try in a couple of hours.

---

<div class="post-metadata">

**Author:** ![lvinyes](https://avatars.discourse-cdn.com/v4/letter/l/e95f7d/32.png) [@lvinyes](https://discuss.elastic.co/u/lvinyes)\
**Post date:** [August 2, 2018, 8:40am UTC](https://discuss.elastic.co/t/create-properties-with-wildcard/142685/6 "2018-08-02T08:40:15Z")

</div>

I tried this, and does not works:  
{  
"_location\_as\_geopoint": {  
"match\_mapping\_type": "\*",  
"match": "geoip_\*.location",  
"mapping": {  
"type": "geo\_point"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![lvinyes](https://avatars.discourse-cdn.com/v4/letter/l/e95f7d/32.png) [@lvinyes](https://discuss.elastic.co/u/lvinyes)\
**Post date:** [August 3, 2018, 8:25am UTC](https://discuss.elastic.co/t/create-properties-with-wildcard/142685/7 "2018-08-03T08:25:09Z")

</div>

I changed to:

```
      {
		"location_as_geopoint": {
		  "match_mapping_type": "*",
          "path_match": "geoip_*.location",
          "mapping": {
            "type": "geo_point"
          }
        }
      }	  

```

And now works as desired.

---

<div class="post-metadata">

**Author:** ![lvinyes](https://avatars.discourse-cdn.com/v4/letter/l/e95f7d/32.png) [@lvinyes](https://discuss.elastic.co/u/lvinyes)\
**Post date:** [August 3, 2018, 12:32pm UTC](https://discuss.elastic.co/t/create-properties-with-wildcard/142685/8 "2018-08-03T12:32:14Z")

</div>

Thank you dadoonet for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2018, 12:32pm UTC](https://discuss.elastic.co/t/create-properties-with-wildcard/142685/9 "2018-08-31T12:32:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
