# Elastic Agent (fleet) change default mapping

**URL:** <https://discuss.elastic.co/t/elastic-agent-fleet-change-default-mapping/357212>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [April 11, 2024, 1:32pm UTC](https://discuss.elastic.co/t/elastic-agent-fleet-change-default-mapping/357212 "2024-04-11T13:32:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eran\_Hadad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eran_hadad/32/102407_2.png) [@Eran\_Hadad](https://discuss.elastic.co/u/Eran_Hadad)\
**Post date:** [April 11, 2024, 1:32pm UTC](https://discuss.elastic.co/t/elastic-agent-fleet-change-default-mapping/357212/1 "2024-04-11T13:32:46Z")

</div>

Hi,  
I'm using fleet agent to collect logs from Azure event hub.  
I'm simply trying to change mapping so one field would be a text instead of a keyword.  
To make a long story short, I found the Component Templates that is responsible for the mapping `logs-azure.eventhub@package`.  
It has a dynamic template that every string is converted to a keyword.  
So I tried adding a mapped field like so:

```auto
"azure": {
          "type": "object",
          "properties": {
            "eventhub": {
              "type": "object",
              "properties": {
                "properties": {
                  "type": "object",
                  "properties": {
                    "requestUri": {
                      "type": "text",
                      "fields": {
                        "requestUriKeyword": {
                          "type": "keyword",
                        }
                      }
                    }
                  }
                }
              }
            }
          }
        }

```

_ignore the parenthesis as I may copied it incorrectly_  
I have a new index created almost every day and yet `azure.eventhub.properties.requestUri` keeps remaining a keyword even if I recreate the data view.

What am I missing?  
I just can't seem to find the issue why the mapping isn't working.  
Any help would be much appreciated.

---

<div class="post-metadata">

**Author:** ![Julia\_Bardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julia_bardi/32/79463_2.png) [@Julia\_Bardi](https://discuss.elastic.co/u/Julia_Bardi)\
**Post date:** [May 21, 2024, 9:45am UTC](https://discuss.elastic.co/t/elastic-agent-fleet-change-default-mapping/357212/2 "2024-05-21T09:45:26Z")

</div>

Similar to this [Logs-azure.eventhub@custom - #2 by Julia\_Bardi](https://discuss.elastic.co/t/logs-azure-eventhub-custom/356775/2), you could try adding the mapping to `logs-azure.eventhub@custom` component template, that is not overwritten on package upgrades.
