# Dynamic field type in template

**URL:** <https://discuss.elastic.co/t/dynamic-field-type-in-template/288568>\
**Category:** Elasticsearch\
**Created:** [November 7, 2021, 4:45pm UTC](https://discuss.elastic.co/t/dynamic-field-type-in-template/288568 "2021-11-07T16:45:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![anna.kuranda](https://avatars.discourse-cdn.com/v4/letter/a/9e8a1a/32.png) [@anna.kuranda](https://discuss.elastic.co/u/anna.kuranda)\
**Post date:** [November 7, 2021, 4:45pm UTC](https://discuss.elastic.co/t/dynamic-field-type-in-template/288568/1 "2021-11-07T16:45:15Z")

</div>

I use template and alias to manage my insert data  
The issue :  
I have field that have different types , so I failed on field type inconsistency  
the field can be of String type or Nested JSON Object  
For example :  
**String type**  
"descr":"hello word"

**Object type**  
"descr":{  
"user" : "anna",  
"account":{  
"id":33333,  
"det":"bla"  
...........  
}  
}

Please ,is there way to solve the issue with dynamic field type

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 7, 2021, 7:29pm UTC](https://discuss.elastic.co/t/dynamic-field-type-in-template/288568/2 "2021-11-07T19:29:16Z")

</div>

Dynamic mapping just means it is assigned when the field is first encountered - the mapping still need to be consistent within an index.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 7, 2021, 8:13pm UTC](https://discuss.elastic.co/t/dynamic-field-type-in-template/288568/3 "2021-11-07T20:13:29Z")

</div>

Hi @anna.kuranda

This is one of the tough little issues with ingesting logs that are different.

Building on what @Christian_Dahlqvist described that in the end the mapping / data type still needs to be consistent below is a pattern that I have seen used

Create a Mapping that contains all the information etc. and then use an ingest pipeline to create the consistent mapping / document. If there is another field in the log that can help you identify the type that will make it easier

Here is a little sample code to get you thinking

```auto
DELETE discuss

PUT discuss
{
  "mappings": {
    "properties": {
      "log_type": {
        "type": "keyword"
      },
      "desc": {
        "properties": {
          "general_description": {
            "type": "text"
          },
          "other_data": {
            "type": "text"
          },
          "id": {
            "type": "keyword"
          }
        }
      }
    }
  }
}

POST /_ingest/pipeline/_simulate
{
  "pipeline": {
    "description": "string to object",
    "version": 0,
    "processors": [
      {
        "set": {
          "if": "ctx.log_type != null && ctx.log_type == 'type1'",
          "field": "temp_desc",
          "value": "{{{desc}}}"
        }
      },
      {
        "remove": {
          "if": "ctx.log_type != null && ctx.log_type == 'type1'",
          "field": "desc"
        }
      },
      {
        "set": {
          "if": "ctx.log_type != null && ctx.log_type == 'type1'",
          "field": "desc.general_desc",
          "value": "{{{temp_desc}}}"
        }
      },
      {
        "remove": {
          "if": "ctx.log_type != null && ctx.log_type == 'type1'",
          "field": "temp_desc"
        }
      }
    ]
  },
  "docs": [
    {
      "_index": "m-index",
      "_id": "kMpUTHoBr7SFhhL5-98P",
      "_source": {
        "log_type": "type1",
        "desc": "my description"
      }
    },
    {
      "_index": "m-index",
      "_id": "kMpUTHoBr7SFhhL5-98P",
      "_source": {
        "desc": {
          "other_data": "my other data"
        }
      }
    }
  ]
}

```

the result of this is that it can handle both types of data

```auto
{
  "docs" : [
    {
      "doc" : {
        "_index" : "m-index",
        "_type" : "_doc",
        "_id" : "kMpUTHoBr7SFhhL5-98P",
        "_source" : {
          "log_type" : "type1",
          "desc" : {
            "general_desc" : "my description"
          }
        },
        "_ingest" : {
          "timestamp" : "2021-11-07T20:15:15.2747358Z"
        }
      }
    },
    {
      "doc" : {
        "_index" : "m-index",
        "_type" : "_doc",
        "_id" : "kMpUTHoBr7SFhhL5-98P",
        "_source" : {
          "desc" : {
            "other_data" : "my other data"
          }
        },
        "_ingest" : {
          "timestamp" : "2021-11-07T20:15:15.2747568Z"
        }
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![anna.kuranda](https://avatars.discourse-cdn.com/v4/letter/a/9e8a1a/32.png) [@anna.kuranda](https://discuss.elastic.co/u/anna.kuranda)\
**Post date:** [November 8, 2021, 6:17am UTC](https://discuss.elastic.co/t/dynamic-field-type-in-template/288568/4 "2021-11-08T06:17:04Z")

</div>

Thank you for the answer

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 6, 2021, 6:17am UTC](https://discuss.elastic.co/t/dynamic-field-type-in-template/288568/5 "2021-12-06T06:17:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
