# Data allways stack in field.keyword than field

**URL:** <https://discuss.elastic.co/t/data-allways-stack-in-field-keyword-than-field/311937>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [August 11, 2022, 2:48pm UTC](https://discuss.elastic.co/t/data-allways-stack-in-field-keyword-than-field/311937 "2022-08-11T14:48:18Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 12, 2022, 1:59pm UTC](https://discuss.elastic.co/t/data-allways-stack-in-field-keyword-than-field/311937/7 "2022-08-12T13:59:19Z")

</div>

@JLeysens @Dreinale

Actually if you are using modules + logstash + datastreams + 8.x the output is a little different our docs are wrong and there is a tiny bug

Please look at this thread

> [@Only write ops with an op\_type of create are allowed in data streams"}}}}](https://discuss.elastic.co/t/only-write-ops-with-an-op-type-of-create-are-allowed-in-data-streams/308182/2):
>
> Try this there is an error in the docs... Clean up the data stream and try again... output { if [@metadata][pipeline] { elasticsearch { hosts =\> "http://localhost:9200" pipeline =\> "%{[@metadata][pipeline]}" user =\> "elastic" password =\> "password" manage\_template =\> false index =\> "%{[@metadata][beat]}-%{[@metadata][version]}" action =\> "create" } } else { elasticsearch { hosts =\> "http://localhost:9200" user =\> "elastic" …

```auto
output {
  if [@metadata][pipeline] {
    elasticsearch {
      hosts => "http://localhost:9200"
      pipeline => "%{[@metadata][pipeline]}"
      user => "elastic"
      password => "password"
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}"
      action => "create" <!--- Important
    }
  } else {
    elasticsearch {
      hosts => "http://localhost:9200"
      user => "elastic"
      password => "password"
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}"
      action => "create"
    }
  }
} 

```

I think I explain why somewhere in there... 🙂

---

_[View the full topic](https://discuss.elastic.co/t/data-allways-stack-in-field-keyword-than-field/311937)._
