# Custom Filestream Integration - Adding mappings

**URL:** <https://discuss.elastic.co/t/custom-filestream-integration-adding-mappings/381316>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [August 25, 2025, 5:07pm UTC](https://discuss.elastic.co/t/custom-filestream-integration-adding-mappings/381316 "2025-08-25T17:07:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [August 25, 2025, 5:07pm UTC](https://discuss.elastic.co/t/custom-filestream-integration-adding-mappings/381316/1 "2025-08-25T17:07:30Z")

</div>

Hello,

I am having trouble with adding custom mapping to my data stream built from custom filestream input.  
It appears that once the data comes in and build the data stream, the data stream is “managed”.  
It doesn’t allow me the option to add any custom mappings?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/1/b12ab75b3c1b17313ae6baac1de0955e8aafc5e0.png)

ES/Kibana: 8.18.0  
Custom Filestream: 1.2.0

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [August 25, 2025, 5:16pm UTC](https://discuss.elastic.co/t/custom-filestream-integration-adding-mappings/381316/2 "2025-08-25T17:16:39Z")

</div>

Just to add,  
I have used Custom Azure Input Integration before and was able to add my custom mappings, this is now pointing to an issue with custom filestream input.

For example:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/1/d128514b4590c84e66ac465d6e406e8eddbe8198.png)

This creates its own index template:  
In which you can add your own component template, azure

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/9/190cc3e782febed72868d9567a0d9524596e9f7a.png)

I cannot edit the encompassing ‘logs’ index template in Custom Filestream Input, that would apply unnecessary component templates.

---

<div class="post-metadata">

**Author:** ![mmahacek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmahacek/32/133650_2.png) [@mmahacek](https://discuss.elastic.co/u/mmahacek)\
**Post date:** [August 25, 2025, 11:04pm UTC](https://discuss.elastic.co/t/custom-filestream-integration-adding-mappings/381316/3 "2025-08-25T23:04:29Z")

</div>

The `logs-azure_logs.*@custom` component template would the be place to put custom settings/mappings, not the `azure` template.

Any of the `@custom` templates and pipelines are not managed by the system and will persist your changes.

After making changes to the template to define mappings, you would need to rollover the data stream so it can make a new index with the updated mappings.

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [August 25, 2025, 11:15pm UTC](https://discuss.elastic.co/t/custom-filestream-integration-adding-mappings/381316/4 "2025-08-25T23:15:10Z")

</div>

> [@mmahacek](#):
>
> After making changes to the template to define mappings, you would need to rollo

Hey @mmahacek thanks for that clarification, I will fix that for my azure setup.

My main issue is how do I add the custom settings/mappings to the Custom Filestream Integration? There seems to be no **@custom** component template, just the default **logs**

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 26, 2025, 3:17am UTC](https://discuss.elastic.co/t/custom-filestream-integration-adding-mappings/381316/5 "2025-08-26T03:17:07Z")

</div>

Hi @erikg

Here is how it works.... and agree it is inconsistent between the different packages... the azure input sets up template scaffolding the filestream does not I am no sure why.

That said currently Custom File Stream Input does not generate a template specific to the `data_stream.dataset` that you define and thus just uses the default `logs-*`

You can fix / address this in about 5 minutes .... but if you want to do it really quick here it is I keep this around handy.

Assumes your datastream is `logs-mycustom.filestream-*`

- Put this in
- Rollover the data stream
- It will show up in the UI
- It will use all the logs-\* goodness and add your own.
- Its basically a clone then edit of the `logs` template

```auto
PUT _index_template/logs-mycustom.filestream
{
  "version": 1,
  "priority": 200, << MUST BE GREATER THAN 100 so it takes precendence 
  "template": {
    "mappings": {
      "_source": {
        "mode": "synthetic" 
      }
    },
    "settings": {
      "index": {
        "mode": "standard" <<< I set to logsdb if you want 
      }
    }
  },
  "index_patterns": [
    "logs-mycustom.filestream-*" <<< Your datastream name 
  ],
  "data_stream": {
    "hidden": false,
    "allow_custom_routing": false
  },
  "composed_of": [
    "logs@mappings",
    "logs@settings",
    "ecs@mappings",
    "logs-mycustom.filestream@custom", << ADD THIS
    "logs@custom"
  ],
  "ignore_missing_component_templates": [
    "logs-mycustom.filestream@custom", << ADD THIS
    "logs@custom"
  ],
  "allow_auto_create": true,
  "_meta": {
    "description": "custom filestream logs template",
    "managed": false <<< TURN OF MANAGED 
  },
  "deprecated": false
}

```

You can then add your custom mappings and settings to  
`logs-mycustom.filestream@custom` or  
`liga@custom`

---

<div class="post-metadata">

**Author:** ![mmahacek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mmahacek/32/133650_2.png) [@mmahacek](https://discuss.elastic.co/u/mmahacek)\
**Post date:** [August 26, 2025, 5:17pm UTC](https://discuss.elastic.co/t/custom-filestream-integration-adding-mappings/381316/6 "2025-08-26T17:17:16Z")

</div>

The `@custom` component templates aren’t created automatically. If you create a new component template that has that exact name, it will line up on work. The index template creates references with a `ignore_missing_component_templates` flag to skip it as long as it doesn’t exist.
