# Elasticsearch field mapping, dynamic\_templates

**URL:** <https://discuss.elastic.co/t/elasticsearch-field-mapping-dynamic-templates/17996>\
**Category:** Elasticsearch\
**Created:** [June 9, 2014, 2:45pm UTC](https://discuss.elastic.co/t/elasticsearch-field-mapping-dynamic-templates/17996 "2014-06-09T14:45:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sirkubax](https://avatars.discourse-cdn.com/v4/letter/s/f0a364/32.png) [@sirkubax](https://discuss.elastic.co/u/sirkubax)\
**Post date:** [June 9, 2014, 2:45pm UTC](https://discuss.elastic.co/t/elasticsearch-field-mapping-dynamic-templates/17996/1 "2014-06-09T14:45:05Z")

</div>

As I did mention here  
[https://groups.google.com/forum/#!topic/elasticsearch/7Bn5Pc6TSgs](https://groups.google.com/forum/#!topic/elasticsearch/7Bn5Pc6TSgs)  
I have some sorting issue when date is stored in string format.

_I did try to set field format as date, but it is overide when date is  
inserted into index.The mapping was:_

curl -XPUT localhost:9200/\*/\_mapping/loglog -d '  
{  
"loglog" : {  
"properties" : {  
"testdate7" : {"type" : "date", "format" : "yyyy-MM-dd  
HH:mm:ss.SSSSSS", "store" : true }  
}  
}  
}  
'

_but after while it become:_

"properties" : {  
"testdate7" : {  
"type" : "string",  
"norms" : {  
"enabled" : false  
},

\*I guess it may be caused by \*

"dynamic\_templates" : [ {  
"_string_\__fields_" : {  
"mapping" : {  
"type" : "multi\_field",  
"fields" : {  
"raw" : {  
"index" : "not\_analyzed",  
"ignore\_above" : 256,  
"type" : "string"  
},  
"{name}" : {  
"index" : "analyzed",  
"omit\_norms" : true,  
"type" : "string"  
}  
}  
},  
"match" : "\*",  
"match\_mapping\_type" : "string"  
}  
} ],

_So the question os, how create mappint that would cover that issue.The  
message that is insterted looks like:_  
"ANYTHING (pid: 23291, thread: 4131280592) \*\*\*\*\*\*\*_] [_ aa.xx:555: MSG(3)  
2014-06-09 10:50:08.255111 ... "

_I did try to set_  
"dynamic\_date\_formats" : ["date\_optional\_time", "yyyy-MM-dd  
HH:mm:ss.SSSSSS"],  
_but I think I did not set it properly._

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/bf31ea3f-292b-451b-aa14-0ef2f3632f44%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/bf31ea3f-292b-451b-aa14-0ef2f3632f44%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 16, 2014, 1:39pm UTC](https://discuss.elastic.co/t/elasticsearch-field-mapping-dynamic-templates/17996/2 "2014-06-16T13:39:37Z")

</div>

Hey,

using your curl call you only set the mapping for existing indices, but not  
for newly created ones. You may want to consider using index templates for  
this specific field.

--Alex

On Mon, Jun 9, 2014 at 4:45 PM, sirkubax [jakubxmuszynski@googlemail.com](mailto:jakubxmuszynski@googlemail.com)  
wrote:

> As I did mention here  
> [Redirecting to Google Groups](https://groups.google.com/forum/#!topic/elasticsearch/7Bn5Pc6TSgs)  
> I have some sorting issue when date is stored in string format.
> 
> _I did try to set field format as date, but it is overide when date is  
> inserted into index.The mapping was:_
> 
> curl -XPUT localhost:9200/\*/\_mapping/loglog -d '  
> {  
> "loglog" : {  
> "properties" : {  
> "testdate7" : {"type" : "date", "format" : "yyyy-MM-dd  
> HH:mm:ss.SSSSSS", "store" : true }  
> }  
> }  
> }  
> '
> 
> _but after while it become:_
> 
> "properties" : {  
> "testdate7" : {  
> "type" : "string",  
> "norms" : {  
> "enabled" : false  
> },
> 
> \*I guess it may be caused by \*
> 
> "dynamic\_templates" : [ {  
> "_string_\__fields_" : {  
> "mapping" : {  
> "type" : "multi\_field",  
> "fields" : {  
> "raw" : {  
> "index" : "not\_analyzed",  
> "ignore\_above" : 256,  
> "type" : "string"  
> },  
> "{name}" : {  
> "index" : "analyzed",  
> "omit\_norms" : true,  
> "type" : "string"  
> }  
> }  
> },  
> "match" : "\*",  
> "match\_mapping\_type" : "string"  
> }  
> } ],
> 
> _So the question os, how create mappint that would cover that issue.The  
> message that is insterted looks like:_  
> "ANYTHING (pid: 23291, thread: 4131280592) \*\*\*\*\*\*\*_] [_ aa.xx:555: MSG(3)  
> 2014-06-09 10:50:08.255111 ... "
> 
> _I did try to set_  
> "dynamic\_date\_formats" : ["date\_optional\_time", "yyyy-MM-dd  
> HH:mm:ss.SSSSSS"],  
> _but I think I did not set it properly._
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/bf31ea3f-292b-451b-aa14-0ef2f3632f44%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/bf31ea3f-292b-451b-aa14-0ef2f3632f44%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/bf31ea3f-292b-451b-aa14-0ef2f3632f44%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/bf31ea3f-292b-451b-aa14-0ef2f3632f44%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGCwEM8cXo\_Hx7-UszUWcWsE51k0q4AMKNamr-6Zq1%2BLAVMMzg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGCwEM8cXo_Hx7-UszUWcWsE51k0q4AMKNamr-6Zq1%2BLAVMMzg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![sirkubax](https://avatars.discourse-cdn.com/v4/letter/s/f0a364/32.png) [@sirkubax](https://discuss.elastic.co/u/sirkubax)\
**Post date:** [June 17, 2014, 7:14am UTC](https://discuss.elastic.co/t/elasticsearch-field-mapping-dynamic-templates/17996/3 "2014-06-17T07:14:49Z")

</div>

_Hi Alex, That's more or less what I did:_

curl -XGET localhost:9200/\_template?pretty \> template\_all

edit template\_all

and put it back:  
curl -XPUT localhost:9200/\_template/\* -d @template\_all

- By ES is 1.0.1, I've seen that there is major change in templates in ES  
1.2. Do you think my task could be achieved faster? I had to dump config,  
edit id, and put it back. I'd wish to upload only "testdate"  
dynamic\_templates in one step. the file: \*  
cat template\_all  
{  
"template" : "logstash-_",  
"settings" : {  
"index.analysis.analyzer.default.stopwords" : "none",  
"index.refresh\_interval" : "5s",  
"index.analysis.analyzer.default.type" : "standard"  
},  
"mappings" : {  
"default" : {  
"dynamic\_templates" : [  
{ "testdate": {  
"match": "testdate_",  
"mapping": {  
"type": "date",  
"format" : "yyyy-MM-dd HH:mm:ss.SSSSSS"  
}  
}  
},  
{  
"string\_fields" : {  
"mapping" : {  
"type" : "multi\_field",  
"fields" : {  
"raw" : {  
"index" : "not\_analyzed",  
"ignore\_above" : 256,  
"type" : "string"  
},  
"{name}" : {  
"index" : "analyzed",  
"omit\_norms" : true,  
"type" : "string"  
}  
}  
},  
"match\_mapping\_type" : "string",  
"match" : "\*"  
}  
} ],  
"properties" : {  
"geoip" : {  
"dynamic" : true,  
"path" : "full",  
"properties" : {  
"location" : {  
"type" : "geo\_point"  
}  
},  
"type" : "object"  
},  
"@version" : {  
"index" : "not\_analyzed",  
"type" : "string"  
}  
},  
"\_all" : {  
"enabled" : true  
}  
}  
}  
}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/917d10ec-63b3-4d94-858a-2f2deeeba604%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/917d10ec-63b3-4d94-858a-2f2deeeba604%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![sirkubax](https://avatars.discourse-cdn.com/v4/letter/s/f0a364/32.png) [@sirkubax](https://discuss.elastic.co/u/sirkubax)\
**Post date:** [August 3, 2014, 7:24pm UTC](https://discuss.elastic.co/t/elasticsearch-field-mapping-dynamic-templates/17996/4 "2014-08-03T19:24:53Z")

</div>

I dod migrate to ES 1.3.1

I did try to do the same trick, but it's fail to PUT oryginal, just dumped  
settings.  
Any ideas?

curl -XGET localhost:9200/\_template?pretty \> template\_all

curl -XPUT localhost:9200/\_template/\*?pretty -d @template\_all

_{_

- "error" : "ActionRequestValidationException[Validation Failed: 1:  
template is missing;]",\*
- "status" : 500\*  
_}_

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b0981737-8788-4e90-8f2d-e8afc345c1a3%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b0981737-8788-4e90-8f2d-e8afc345c1a3%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![sirkubax](https://avatars.discourse-cdn.com/v4/letter/s/f0a364/32.png) [@sirkubax](https://discuss.elastic.co/u/sirkubax)\
**Post date:** [August 4, 2014, 2:01pm UTC](https://discuss.elastic.co/t/elasticsearch-field-mapping-dynamic-templates/17996/5 "2014-08-04T14:01:47Z")

</div>

> I did migrate to ES 1.3.1
> 
> I did try to do the same trick as before, but it's fail to PUT oryginal,  
> just dumped settings.  
> Any ideas?
> 
> curl -XGET localhost:9200/\_template?pretty \> template\_all
> 
> curl -XPUT localhost:9200/\_template/\*?pretty -d @template\_all
> 
> _{_
> 
> - "error" : "ActionRequestValidationException[Validation Failed: 1:  
> template is missing;]",\*
> - "status" : 500\*  
> _}_

I did not see any bigger change in dynamic\_templates recently so I guess it  
should work just like before.  
Can You replicate this issue on your cluster?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/82e516e4-6308-4676-b0f9-e213d0650986%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/82e516e4-6308-4676-b0f9-e213d0650986%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![sirkubax](https://avatars.discourse-cdn.com/v4/letter/s/f0a364/32.png) [@sirkubax](https://discuss.elastic.co/u/sirkubax)\
**Post date:** [August 4, 2014, 3:30pm UTC](https://discuss.elastic.co/t/elasticsearch-field-mapping-dynamic-templates/17996/6 "2014-08-04T15:30:22Z")

</div>

_Ok, got it:_

_I did it template by template_  
_When you capture template (for example: logstash_

curl -XGET localhost:9200/\_template/logstash?pretty \> template\_logstash

_you get:_

cat template\_logstash  
{  
"logstash" : {  
"order" : 0,  
"template" : "logstash-_",  
"settings" : {  
"index.analysis.analyzer.default.stopwords" : "none",  
"index.refresh\_interval" : "5s",  
"index.analysis.analyzer.default.type" : "standard"  
},  
"mappings" : {  
"default" : {  
"dynamic\_templates" : [ {  
"string\_fields" : {  
"mapping" : {  
"type" : "multi\_field",  
"fields" : {  
"raw" : {  
"index" : "not\_analyzed",  
"ignore\_above" : 256,  
"type" : "string"  
},  
"{name}" : {  
"index" : "analyzed",  
"omit\_norms" : true,  
"type" : "string"  
}  
}  
},  
"match\_mapping\_type" : "string",  
"match" : "_"  
}  
} ],  
"properties" : {  
"geoip" : {  
"dynamic" : true,  
"path" : "full",  
"properties" : {  
"location" : {  
"type" : "geo\_point"  
}  
},  
"type" : "object"  
},  
"@version" : {  
"index" : "not\_analyzed",  
"type" : "string"  
}  
},  
"\_all" : {  
"enabled" : true  
}  
}  
}  
}  
}

_Then you need to remove the 1st parrent in the "json tree":_  
{  
"logstash" :  
}

_So you end up with:_

{  
"order" : 0,  
"template" : "logstash-_",  
"settings" : {  
"index.analysis.analyzer.default.stopwords" : "none",  
"index.refresh\_interval" : "5s",  
"index.analysis.analyzer.default.type" : "standard"  
},  
"mappings" : {  
"default" : {  
"dynamic\_templates" : [ {  
"string\_fields" : {  
"mapping" : {  
"type" : "multi\_field",  
"fields" : {  
"raw" : {  
"index" : "not\_analyzed",  
"ignore\_above" : 256,  
"type" : "string"  
},  
"{name}" : {  
"index" : "analyzed",  
"omit\_norms" : true,  
"type" : "string"  
}  
}  
},  
"match\_mapping\_type" : "string",  
"match" : "_"  
}  
} ],  
"properties" : {  
"geoip" : {  
"dynamic" : true,  
"path" : "full",  
"properties" : {  
"location" : {  
"type" : "geo\_point"  
}  
},  
"type" : "object"  
},  
"@version" : {  
"index" : "not\_analyzed",  
"type" : "string"  
}  
},  
"\_all" : {  
"enabled" : true  
}  
}  
}  
}

_That can be put back to logstash template like:_  
_curl -XPUT localhost:9200/\_template/_ -d @template\_logstash\*

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/86cf401d-931d-4a63-bf6b-65b6b35122e3%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/86cf401d-931d-4a63-bf6b-65b6b35122e3%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:10am UTC](https://discuss.elastic.co/t/elasticsearch-field-mapping-dynamic-templates/17996/7 "2017-07-06T01:10:59Z")

</div>


