# Does filebeat.yml setup.template.append\_fields support multi-fields for elasticsearch index template?

**URL:** <https://discuss.elastic.co/t/does-filebeat-yml-setup-template-append-fields-support-multi-fields-for-elasticsearch-index-template/172207>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 13, 2019, 7:11pm UTC](https://discuss.elastic.co/t/does-filebeat-yml-setup-template-append-fields-support-multi-fields-for-elasticsearch-index-template/172207 "2019-03-13T19:11:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![PSM](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@PSM](https://discuss.elastic.co/u/PSM)\
**Post date:** [March 13, 2019, 7:11pm UTC](https://discuss.elastic.co/t/does-filebeat-yml-setup-template-append-fields-support-multi-fields-for-elasticsearch-index-template/172207/1 "2019-03-13T19:11:47Z")

</div>

I'm configuring the filebeat filebeat.yml to load elasticsearch index [templates](https://www.elastic.co/guide/en/beats/filebeat/master/configuration-template.html).

I have a few fields that I'd like to index as both type `keyword` and type `text` so I can use them for sorting and aggregation as well as for case-insensitive full-text search. This is supported using [multi-fields](https://www.elastic.co/guide/en/elasticsearch/reference/master/multi-fields.html) but I can't figure out if filebeat supports creating templates for multi-fields.

For example, I'd like the field copr.service to have both `keyword` and `text` types.

```
setup.template.name: "filebeat-6.6.1-application"
setup.template.fields: "fields.yml"
setup.template.overwrite: true
setup.template.settings:
  index.number_of_shards: 8
  index.number_of_replicas: 2
  index.number_of_routing_shards: 16
  index.codec: best_compression
  _source.enabled: true
setup.template.append_fields:
- name: corp.environment
  type: keyword
- name: corp.service
  type: text
- name: corp.role
  type: keyword
- name: corp.log.ingestedTimestamp
  type: date

```

Thanks!

Peter

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 16, 2019, 8:17pm UTC](https://discuss.elastic.co/t/does-filebeat-yml-setup-template-append-fields-support-multi-fields-for-elasticsearch-index-template/172207/2 "2019-03-16T20:17:08Z")

</div>

The keyword `multi_fields`is supported by the fields.yml format and `append_fields`option.  
You can define the field the following way as in the example in the documentation:

```auto
setup.template.append_fields:
- name: corp.service
  type: text
  multiple_fields:
    - type: keyword
      name: raw

```

---

<div class="post-metadata">

**Author:** ![PSM](https://avatars.discourse-cdn.com/v4/letter/p/a9adbd/32.png) [@PSM](https://discuss.elastic.co/u/PSM)\
**Post date:** [March 19, 2019, 5:44pm UTC](https://discuss.elastic.co/t/does-filebeat-yml-setup-template-append-fields-support-multi-fields-for-elasticsearch-index-template/172207/3 "2019-03-19T17:44:59Z")

</div>

Thanks very much.

It took a bit to test because there is a typo in the code portion of your response. It should be `multi_fields:` not `multiple_fields:` in the `filebeat.yml`, as you put in the text portion of your response.

This configuration is working for me:

```
setup.template.append_fields:
- name: corp.service
  type: text
  multi_fields:
    - type: keyword
      name: raw

```

You hooked me up, I really appreciate it!!

p

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 16, 2019, 5:45pm UTC](https://discuss.elastic.co/t/does-filebeat-yml-setup-template-append-fields-support-multi-fields-for-elasticsearch-index-template/172207/4 "2019-04-16T17:45:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
