# Dealing with no timestamp (Bro integration)

**URL:** <https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419>\
**Category:** Elasticsearch\
**Created:** [September 13, 2016, 7:17pm UTC](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419 "2016-09-13T19:17:57Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [September 13, 2016, 7:17pm UTC](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/1 "2016-09-13T19:17:57Z")

</div>

So I'm currently testing using bro's [bro](https://github.com/bro/bro) ES integration plugin. My first challenge is the ts field, timestamp, isn't anything ES knows. Example:  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/41dfbccc593df588f3fec388bf792bbba1f83613.jpg)

How do I create a mapping to make ES see ts as a timestamp? Thank you.

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [September 13, 2016, 7:29pm UTC](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/2 "2016-09-13T19:29:48Z")

</div>

The first example on the [date mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/date.html) page should do it.

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [September 13, 2016, 7:37pm UTC](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/3 "2016-09-13T19:37:55Z")

</div>

Thanks Nik that's helpful. A question I've always wanted to know...a lot of the examples show things like:

```
PUT my_index
{
  "mappings": {
    "my_type": {
      "properties": {
        "date": {
          "type": "date" 
        }
      }
    }
  }
}

```

but exactly HOW does one input that? Using a curl command? Is there no front-end that would allow making these changes? Thanks again.

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [September 13, 2016, 7:48pm UTC](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/4 "2016-09-13T19:48:39Z")

</div>

Examples that look like that **should** have two links under them - one that says "view in Sense" or "view in Console" which pops open the snippet in [sense](https://github.com/elastic/sense) (being renamed to console) which is a fancy Kibana/browser app with nice stuff like autocomplete. The other link says "copy as curl" and it ought turn the that sense syntax into valid bash/curl syntax and stick it on your clipboard.

We like the sense syntax because:

1. It is pretty.
2. It pushes folks to Sense which is a fairly friendly interface.
3. It is reasonably easy to turn it into testable code, which we do in 5.0.
4. The syntax highlighter does a decent job of highlighting it. So long as you don't have Privacy Badger on for the site. I haven't figured out why Privacy Badger is blocking the syntax highlighter. Something to do with the CDN....

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [September 13, 2016, 8:24pm UTC](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/5 "2016-09-13T20:24:17Z")

</div>

Thanks again Nik. So OK I got Sense installed (neat tool). It appear that I can't modify an already existing index yes? How do I create a mapping and apply it to current and future indexes? Thank you.

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [September 13, 2016, 8:33pm UTC](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/6 "2016-09-13T20:33:09Z")

</div>

For the most part you can't modify a field that has already been created. You can add new fields or new [properties](https://www.elastic.co/guide/en/elasticsearch/reference/current/properties.html) to existing fields.

You can use [templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html) to control the mappings for new indexes. I never use them myself though. I prefer manually creating indexes with the mappings that I want for everything except testing.

You can modify some stuff about an existing index easily (`number_of_replicas`) or through special processes (`number_of_shards` through [`_shrink`](https://www.elastic.co/guide/en/elasticsearch/reference/master/indices-shrink-index.html) which is 5.0+). The rules are all about what is efficient to do for large indexes. If you don't like your index you can always create a new index and use the [`_reindex`](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html) to copy all the docs to it.

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [September 13, 2016, 8:45pm UTC](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/7 "2016-09-13T20:45:26Z")

</div>

Awesome thanks so much again Nik. Bro creates its indexes every 3 hours, so uh yea I think templates will be the way to go 🙂 I'll post my results once I'm done. Sense is pretty cool all in all.

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [September 13, 2016, 9:02pm UTC](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/8 "2016-09-13T21:02:25Z")

</div>

> [@DigiAngel](#):
>
> Bro creates its indexes every 3 hours

I hope it doesn't plan on keeping them for very long then. There are practical limits on the number of indexes you can have in Elasticsearch cluster. You start to notice somethings (mapping changes, moving indexes from one node to another) start to take longer when you have too many. If used to be a couple thousand in 1.x, it is higher in 2.x but I'm not sure anyone is exactly sure how much higher.

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [September 13, 2016, 9:42pm UTC](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/9 "2016-09-13T21:42:46Z")

</div>

Yea this is just testing and they are really small (like...187k). So here's my line:

```
PUT /_template/bro_template
{
  "template": "bro-*",
    "mappings": {
        "bro_ts": {
          "properties": {
            "ts": {
              "type": "date",
              "format": "epoch_millis"
            }
        }
      }  
  }
}

```

Fingers crossed that this works!

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [September 13, 2016, 9:53pm UTC](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/10 "2016-09-13T21:53:07Z")

</div>

WOOT:  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/dee44b7a9cea7d8470226b52b60430448266be75.jpg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:20pm UTC](https://discuss.elastic.co/t/dealing-with-no-timestamp-bro-integration/60419/11 "2017-07-05T22:20:28Z")

</div>


