# Dynamically adding fields with ES field mapping template enabled

**URL:** <https://discuss.elastic.co/t/dynamically-adding-fields-with-es-field-mapping-template-enabled/89634>\
**Category:** Logstash\
**Created:** [June 15, 2017, 10:35pm UTC](https://discuss.elastic.co/t/dynamically-adding-fields-with-es-field-mapping-template-enabled/89634 "2017-06-15T22:35:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![krishna\_chaitanya](https://avatars.discourse-cdn.com/v4/letter/k/b5a626/32.png) [@krishna\_chaitanya](https://discuss.elastic.co/u/krishna_chaitanya)\
**Post date:** [June 15, 2017, 10:35pm UTC](https://discuss.elastic.co/t/dynamically-adding-fields-with-es-field-mapping-template-enabled/89634/1 "2017-06-15T22:35:38Z")

</div>

I am unable to decide between dynamic mapping and giving a template before hand.

I have configured logstash with file input and ES output.

Say, ES output plugin is configured with field mapping template. Currently, I have defined 20 fields and their data types in the template. But, in the future, if I want to add new fields on the fly into my log files, is it possible? Do I have to edit my mapping ? or is Logstash able to recognize these newly fields datatypes through dynamic template?

The problem I have is with nested types. I have doc like this:

```
{
field1 : value1,
field2: [{... }, {...}]
}

```

So, `field2` is essentially a nested type, which if not defined in template (dynamic template enabled), is just like an object with no datatype. In Kibana, I am unable to access this `field2` from Kibana scripted field.

`doc['field2'].value` throws me this error: `No field found for [field2] in mapping with types []`.  
If I map it to `nested_type` using pre-defined template, then I could access this field, but I do not know if this new template will not allow me to add new fields in the future to my documents.

Any help appreciated !!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 19, 2017, 5:33am UTC](https://discuss.elastic.co/t/dynamically-adding-fields-with-es-field-mapping-template-enabled/89634/2 "2017-06-19T05:33:05Z")

</div>

This is more of an Elasticsearch question so you'll probably get better answers in that group.

Having an index template and allowing dynamic mapping isn't contradictory. Unless you explicitly disable dynamic mapping, new fields can be added without changes to the template and the index's mappings.

---

<div class="post-metadata">

**Author:** ![krishna\_chaitanya](https://avatars.discourse-cdn.com/v4/letter/k/b5a626/32.png) [@krishna\_chaitanya](https://discuss.elastic.co/u/krishna_chaitanya)\
**Post date:** [June 19, 2017, 4:58pm UTC](https://discuss.elastic.co/t/dynamically-adding-fields-with-es-field-mapping-template-enabled/89634/3 "2017-06-19T16:58:05Z")

</div>

Thanks @magnusbaeck That's exactly what I wanted.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2017, 4:58pm UTC](https://discuss.elastic.co/t/dynamically-adding-fields-with-es-field-mapping-template-enabled/89634/4 "2017-07-17T16:58:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
