# Elasticsearch Mapping (date in index)

**URL:** <https://discuss.elastic.co/t/elasticsearch-mapping-date-in-index/44556>\
**Category:** Elasticsearch\
**Created:** [March 16, 2016, 1:58pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-date-in-index/44556 "2016-03-16T13:58:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![schilwan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/schilwan/32/14206_2.png) [@schilwan](https://discuss.elastic.co/u/schilwan)\
**Post date:** [March 16, 2016, 1:58pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-date-in-index/44556/1 "2016-03-16T13:58:09Z")

</div>

I am using Flume to put some data into ElasticSearch:

The interceptor is below:  
agent.sources.tail.interceptors.i7.serializers = s0  
agent.sources.tail.interceptors.i7.serializers.s0.type = org.apache.flume.interceptor.RegexExtractorInterceptorMillisSerializer  
[agent.sources.tail.interceptors.i7.serializers.s0.name](http://agent.sources.tail.interceptors.i7.serializers.s0.name) = date  
agent.sources.tail.interceptors.i7.serializers.s0.pattern = yyyy MMM dd HH:mm:ss

For some reason the date was coming in as a string even with the above interceptor so decided to do a mapping as shown below:

PUT myindex-2016-03-16{  
"mappings": {  
"mytype": {  
"properties": { "@fields" : {  
"properties": {  
"date": { "type": "date", "format": "yyyy-MMM-dd HH:mm:ss" } } } } } }}

Flume tries to be clever and creates a new index for each day so the mapping I made above will be invalid for tomorrow as its going to make date appear as a string again on the new index for 17th March, is there a way to tell elastic that any index with myindex\* should have the above mapping? As obviously doing a PUT with myindex\* and the above does not work.

Thanks

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 16, 2016, 2:13pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-date-in-index/44556/2 "2016-03-16T14:13:44Z")

</div>

You can add a mapping for all indices matching a pattern through the use of a [index template](https://www.elastic.co/guide/en/elasticsearch/reference/2.2/indices-templates.html).

---

<div class="post-metadata">

**Author:** ![schilwan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/schilwan/32/14206_2.png) [@schilwan](https://discuss.elastic.co/u/schilwan)\
**Post date:** [March 16, 2016, 2:21pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-date-in-index/44556/3 "2016-03-16T14:21:06Z")

</div>

Thanks, I knew elastic had a way but weren't sure what to look for.

thanks again

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [March 16, 2016, 6:10pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-date-in-index/44556/4 "2016-03-16T18:10:30Z")

</div>

You can create a mapping template for all indices start with myindex

```auto
PUT _template/myindex
{
  "template": "myindex*",
  "mappings": {
    "mytype": {
      "properties": {
        "@fields": {
          "properties": {
            "date": {
              "type": "date",
              "format": "yyyy-MMM-dd HH:mm:ss"
            }
          }
        }
      }
    }
  }
}

```

with `"template": "myindex*"`, your future indices will use the mappings you specify in the template. You can modify (by overwriting) the template at any time, but it affects only future indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:07pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-date-in-index/44556/5 "2017-07-05T23:07:49Z")

</div>


