# Dynamic template

**URL:** <https://discuss.elastic.co/t/dynamic-template/116000>\
**Category:** Elasticsearch\
**Created:** [January 18, 2018, 8:47am UTC](https://discuss.elastic.co/t/dynamic-template/116000 "2018-01-18T08:47:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![piingluo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piingluo/32/26051_2.png) [@piingluo](https://discuss.elastic.co/u/piingluo)\
**Post date:** [January 18, 2018, 8:47am UTC](https://discuss.elastic.co/t/dynamic-template/116000/1 "2018-01-18T08:47:12Z")

</div>

my dynamic template , as follow:  
"dynamic\_templates": [  
{  
"strings\_as\_keyword": {  
"match\_mapping\_type": "string",  
"match": "\*",  
"unmatch": ["message","\*id"],  
"mapping": {  
"type": "keyword"  
}  
}  
},  
{  
"message\_as\_text": {  
"match\_mapping\_type": "string",  
"match": "message",  
"mapping": {  
"type":"text"  
}  
}  
},  
{  
"prefix\_id\_as\_integer": {  
"match\_mapping\_type": "string",  
"match": ["\*id"],  
"mapping": {  
"type":"integer"  
}  
}  
}  
],

however， I get the /logstash-audit-_/audit/\_mapping  
"dynamic\_templates": [  
{  
"strings\_as\_keyword": {  
"match": "_",  
"unmatch": "[message, \*id]",  
"match\_mapping\_type": "string",  
"mapping": {  
"type": "keyword"  
}  
}  
},  
{  
"message\_as\_text": {  
"match": "message",  
"match\_mapping\_type": "string",  
"mapping": {  
"type": "text"  
}  
}  
},  
{  
"prefix\_id\_as\_integer": {  
"match": "[_id]",  
"match\_mapping\_type": "string",  
"mapping": {  
"type": "integer"  
}  
}  
},  
{  
"message\_field": {  
"path\_match": "message",  
"match\_mapping\_type": "string",  
"mapping": {  
"norms": false,  
"type": "text"  
}  
}  
},  
{  
"string\_fields": {  
"match": "_",  
"match\_mapping\_type": "string",  
"mapping": {  
"fields": {  
"keyword": {  
"ignore\_above": 256,  
"type": "keyword"  
}  
},  
"norms": false,  
"type": "text"  
}  
}  
}  
],  
I'm so confused, i never configured message\_field and string\_field.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 18, 2018, 8:48am UTC](https://discuss.elastic.co/t/dynamic-template/116000/2 "2018-01-18T08:48:18Z")

</div>

Please format your code using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will make your post more readable and will help us help you.

Alternatively use markdown style like this:

````
```
CODE
```
````

---

<div class="post-metadata">

**Author:** ![piingluo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piingluo/32/26051_2.png) [@piingluo](https://discuss.elastic.co/u/piingluo)\
**Post date:** [January 18, 2018, 9:09am UTC](https://discuss.elastic.co/t/dynamic-template/116000/4 "2018-01-18T09:09:26Z")

</div>

thanks for your reply, my dynamic template, as follow:

```auto
"dynamic_templates": [
{
"strings_as_keyword": {
"match_mapping_type": "string",
"match": "*",
"unmatch": ["message","*id"],
"mapping": {
"type": "keyword"
}
}
},
{
"message_as_text": {
"match_mapping_type": "string",
"match": "message",
"mapping": {
"type":"text"
}
}
},
{
"prefix_id_as_integer": {
"match_mapping_type": "string",
"match": ["*id"],
"mapping": {
"type":"integer"
}
}
}
],

```

however， I get the /logstash-audit-/audit/\_mapping

```auto
"dynamic_templates": [
{
"strings_as_keyword": {
"match": "",
"unmatch": "[message, *id]",
"match_mapping_type": "string",
"mapping": {
"type": "keyword"
}
}
},
{
"message_as_text": {
"match": "message",
"match_mapping_type": "string",
"mapping": {
"type": "text"
}
}
},
{
"prefix_id_as_integer": {
"match": "[id]",
"match_mapping_type": "string",
"mapping": {
"type": "integer"
}
}
},
{
"message_field": {
"path_match": "message",
"match_mapping_type": "string",
"mapping": {
"norms": false,
"type": "text"
}
}
},
{
"string_fields": {
"match": "",
"match_mapping_type": "string",
"mapping": {
"fields": {
"keyword": {
"ignore_above": 256,
"type": "keyword"
}
},
"norms": false,
"type": "text"
}
}
}
],

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 18, 2018, 9:11am UTC](https://discuss.elastic.co/t/dynamic-template/116000/5 "2018-01-18T09:11:10Z")

</div>

What's the question or problem you are trying to resolve?

---

<div class="post-metadata">

**Author:** ![piingluo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piingluo/32/26051_2.png) [@piingluo](https://discuss.elastic.co/u/piingluo)\
**Post date:** [January 18, 2018, 9:30am UTC](https://discuss.elastic.co/t/dynamic-template/116000/7 "2018-01-18T09:30:17Z")

</div>

i configure the dynamic template, including three fields: strings\_as\_keyword, message\_as\_text and prefix\_id\_as\_integer.  
but when i check the indice's mapping， it's dynamic template have five fields：strings\_as\_keyword, message\_as\_text，prefix\_id\_as\_integer， message\_field and string\_fields. i wonder why this happen

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 18, 2018, 8:19pm UTC](https://discuss.elastic.co/t/dynamic-template/116000/8 "2018-01-18T20:19:32Z")

</div>

You have dynamic mappings enabled, so if there are other fields that Elasticsearch see, it will automatically accept and create them, which means also adding to the mapping.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2018, 8:19pm UTC](https://discuss.elastic.co/t/dynamic-template/116000/9 "2018-02-15T20:19:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
