# Default dynamic mapping template

**URL:** <https://discuss.elastic.co/t/default-dynamic-mapping-template/59653>\
**Category:** Elasticsearch\
**Created:** [September 2, 2016, 10:54am UTC](https://discuss.elastic.co/t/default-dynamic-mapping-template/59653 "2016-09-02T10:54:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![YuWatanabe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuwatanabe/32/13259_2.png) [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Post date:** [September 2, 2016, 10:54am UTC](https://discuss.elastic.co/t/default-dynamic-mapping-template/59653/1 "2016-09-02T10:54:33Z")

</div>

I understand that elasticsearch automatically creates mapping definition when it is not preconfigured.

[https://www.elastic.co/guide/en/elasticsearch/reference/master/docs-index\_.html#index-creation](https://www.elastic.co/guide/en/elasticsearch/reference/master/docs-index_.html#index-creation)

For example below field is automatically created when I insert data from logstash.

```
      "src_ip": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },

```

Is there a way to check the default dynamic mapping template?

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [September 2, 2016, 11:18am UTC](https://discuss.elastic.co/t/default-dynamic-mapping-template/59653/2 "2016-09-02T11:18:01Z")

</div>

Logstash register the template to Elasticsearch by [this name.](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-template_name)

You can see the template using [`_template` API](https://www.elastic.co/guide/en/elasticsearch/reference/2.4/indices-templates.html#getting)

---

<div class="post-metadata">

**Author:** ![YuWatanabe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuwatanabe/32/13259_2.png) [@YuWatanabe](https://discuss.elastic.co/u/YuWatanabe)\
**Post date:** [September 12, 2016, 12:48pm UTC](https://discuss.elastic.co/t/default-dynamic-mapping-template/59653/3 "2016-09-12T12:48:10Z")

</div>

Hi Ohtani-san.

Thank you for the reply.

Is this still the case when the index name does not match the **logstash-**?

I have stored log using filebeat through logstash and index name is filebeat-2016.09.12 and some fields includes multi fields. I did not manually import any json setting packaged inside filebeat.

I use **filebeat 1.3.0 -1** and **logstash 5.0.0 alpha 5**.

```
{
  "filebeat-2016.09.12": {
    "mappings": {
      "log": {
        "properties": {
          "@timestamp": {
            "type": "date"
          },
          "@version": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "beat": {
            "properties": {
              "hostname": {
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              },
              "name": {
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              }
            }
          },
          "count": {
            "type": "long"
          },
          "host": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "input_type": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "message": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "offset": {
            "type": "long"
          },
          "source": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "tags": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "type": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:21pm UTC](https://discuss.elastic.co/t/default-dynamic-mapping-template/59653/4 "2017-07-05T22:21:05Z")

</div>


