# Elasticsearch Mapping to ECS

**URL:** <https://discuss.elastic.co/t/elasticsearch-mapping-to-ecs/250913>\
**Category:** Elasticsearch\
**Created:** [October 5, 2020, 1:37am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-to-ecs/250913 "2020-10-05T01:37:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bn1980](https://avatars.discourse-cdn.com/v4/letter/b/b5ac83/32.png) [@bn1980](https://discuss.elastic.co/u/bn1980)\
**Post date:** [October 5, 2020, 1:37am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-to-ecs/250913/1 "2020-10-05T01:37:40Z")

</div>

I have logstash creating a daily index  
` index => "logstash-suricata-%{+YYYY.MM.dd}"`

In order to create a mapping i am using a template which is assigned in logstash config  
` template => "/usr/local/etc/logstash/suricata_template.json"`

Is this the correct way to do mapping?

How do I map fields to the Elastic Common Schema (ECS) ?

Please

> **logstash.conf**
>
> ```
> input {
> redis {
> host => "192.168.188.154"
> data_type => "list"
> key => "suricata"
> codec => "json"
> threads => 12
> type => "SuricataIDPS"
> }
> }
> filter {
> if [type] == "SuricataIDPS" {
> date {
> match => ["timestamp", "ISO8601"]
> }
> }
> if [src_ip] {
> geoip {
> source => "src_ip"
> target => "src_geoip"
> }
> }
> if [dest_ip] {
> geoip {
> source => "dest_ip"
> target => "dest_geoip"
> }
> }
> }
> output {
> stdout { codec => rubydebug }
> elasticsearch {
> hosts => ["localhost:9200"]
> index => "logstash-suricata-%{+YYYY.MM.dd}"
> template => "/usr/local/etc/logstash/suricata_template.json"
> template_overwrite => true
> }
> }
> 
> ```

> **suricata\_template.json**
>
> ```
> {
> "template" : "logstash-suricata-*",
> "settings" : {
> "index.refresh_interval" : "5s",
> "number_of_replicas": 0,
> "number_of_shards": 1
> },
> "mappings" : {
> "_default_" : {
> "_all" : {"enabled" : false, "norms" : false},
> "dynamic_templates" : [ {
> "double_fields" : {
> "match" : "*",
> "match_mapping_type" : "double",
> "mapping" : { "type" : "double"}
> }
> }, {
> "long_fields" : {
> "match" : "*",
> "match_mapping_type" : "long",
> "mapping" : { "type" : "long", "doc_values" : true }
> }
> }, {
> "date_fields" : {
> "match" : "*",
> "match_mapping_type" : "date",
> "mapping" : { "type" : "date", "doc_values" : true }
> }
> } ],
> "properties" : {
> "@timestamp": { "type": "date", "doc_values" : true },
> "@version": { "type": "text", "index": false },
> "dest_geoip" : {
> "type" : "object",
> "dynamic": true,
> "properties" : {
> "ip": { "type": "ip", "doc_values" : true },
> "location" : { "type" : "geo_point", "doc_values" : true },
> "latitude" : { "type" : "double", "doc_values" : true },
> "longitude" : { "type" : "double", "doc_values" : true }
> }
> },
> "src_geoip" : {
> "type" : "object",
> "dynamic": true,
> "properties" : {
> "ip": { "type": "ip", "doc_values" : true },
> "location" : { "type" : "geo_point", "doc_values" : true },
> "latitude" : { "type" : "double", "doc_values" : true },
> "longitude" : { "type" : "double", "doc_values" : true }
> }
> }
> }
> }
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2020, 1:37am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-to-ecs/250913/2 "2020-11-02T01:37:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
