# Create template dynamic index and multi mamping

**URL:** <https://discuss.elastic.co/t/create-template-dynamic-index-and-multi-mamping/169012>\
**Category:** Elasticsearch\
**Created:** [February 19, 2019, 11:23am UTC](https://discuss.elastic.co/t/create-template-dynamic-index-and-multi-mamping/169012 "2019-02-19T11:23:09Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![nurhambali](https://avatars.discourse-cdn.com/v4/letter/n/3ec8ea/32.png) [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Post date:** [February 19, 2019, 11:23am UTC](https://discuss.elastic.co/t/create-template-dynamic-index-and-multi-mamping/169012/1 "2019-02-19T11:23:10Z")

</div>

hi all,

i have a problem when be create dynamic index and dynamic mappings :

this is my \_templates

```
PUT _template/huawei
{
  "index_patterns": "huawei-*",
  "settings": {
    "index.refresh_interval": "5s",
    "number_of_shards": 1
  },
    "mappings" : {
      "attack" : {
        "properties":{
          "@timestamp":{"type":"date"},
          "hostname":{"type":"keyword"},
          "type":{"type":"keyword"},
          "host":{"type":"keyword"},
        },
        }

      },
      "ips" : {
        "properties":{
         "@timestamp":{"type":"date"},
         "hostname":{"type":"keyword"},
         "host":{"type":"keyword"},
         "action":{"type":"keyword"},
         "program":{"type":"keyword"}
        }
      },
      "ids" : {
        "properties":{
         "@timestamp":{"type":"date"},
         "hostname":{"type":"keyword"},
         "host":{"type":"keyword"},
         "action":{"type":"keyword"},
         "program":{"type":"keyword"},
                }
      },
      "vpn" : {
        "properties":{
          "@timestamp":{"type":"date"},
          "hostname":{"type":"keyword"},
          "type":{"type":"keyword"},
          "host":{"type":"keyword"},
          "program":{"type":"keyword"}
        }
      }
   }
}     

```

what is missing form my configuration ?

thanks,  
hambali

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 19, 2019, 11:33am UTC](https://discuss.elastic.co/t/create-template-dynamic-index-and-multi-mamping/169012/2 "2019-02-19T11:33:14Z")

</div>

Which version of Elasticsearch are you using? From version 6.0 onwards there can only be one document type per index.

---

<div class="post-metadata">

**Author:** ![nurhambali](https://avatars.discourse-cdn.com/v4/letter/n/3ec8ea/32.png) [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Post date:** [February 19, 2019, 11:39am UTC](https://discuss.elastic.co/t/create-template-dynamic-index-and-multi-mamping/169012/3 "2019-02-19T11:39:55Z")

</div>

i'm using Elsaticsearch version 6.5 is there a solution for the dynamic index?

please give me example dynamic index ?

thanks,  
hambali

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 19, 2019, 11:41am UTC](https://discuss.elastic.co/t/create-template-dynamic-index-and-multi-mamping/169012/4 "2019-02-19T11:41:23Z")

</div>

You can not have multiple document types in your mapping. What is it you are trying to achieve?

Why not add a new field that stores the type of document and use the default document type `_doc` for all documents?

```auto
PUT _template/huawei
{
  "index_patterns": "huawei-*",
  "settings": {
    "index.refresh_interval": "5s",
    "number_of_shards": 1
  },
  "mappings" : {
    "_doc" : {
      "properties":{
        "@timestamp":{"type":"date"},
        "hostname":{"type":"keyword"},
        "type":{"type":"keyword"},
        "host":{"type":"keyword"},
        "action":{"type":"keyword"},
        "program":{"type":"keyword"}
      }
    }
  }
}     

```

---

<div class="post-metadata">

**Author:** ![nurhambali](https://avatars.discourse-cdn.com/v4/letter/n/3ec8ea/32.png) [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Post date:** [February 19, 2019, 11:45am UTC](https://discuss.elastic.co/t/create-template-dynamic-index-and-multi-mamping/169012/5 "2019-02-19T11:45:19Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> You can not have multiple document types in your mapping. What is it you are trying to achieve?

how do I separate the different data apart from the document mapping, will the different fields of data separate the data?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 19, 2019, 11:47am UTC](https://discuss.elastic.co/t/create-template-dynamic-index-and-multi-mamping/169012/6 "2019-02-19T11:47:25Z")

</div>

You have a field named `type`. Why not use that? If that is for something else just add another field.

---

<div class="post-metadata">

**Author:** ![nurhambali](https://avatars.discourse-cdn.com/v4/letter/n/3ec8ea/32.png) [@nurhambali](https://discuss.elastic.co/u/nurhambali)\
**Post date:** [February 19, 2019, 11:49am UTC](https://discuss.elastic.co/t/create-template-dynamic-index-and-multi-mamping/169012/7 "2019-02-19T11:49:23Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> You have a field named `type` . Why not use that

thank you for the advice I will immediately try it 😄

thanks,  
hambali

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2019, 11:49am UTC](https://discuss.elastic.co/t/create-template-dynamic-index-and-multi-mamping/169012/8 "2019-03-19T11:49:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
