# Elasticsearch Templates: How do I handle field properties?

**URL:** <https://discuss.elastic.co/t/elasticsearch-templates-how-do-i-handle-field-properties/14190>\
**Category:** Elasticsearch\
**Created:** [October 31, 2013, 2:04pm UTC](https://discuss.elastic.co/t/elasticsearch-templates-how-do-i-handle-field-properties/14190 "2013-10-31T14:04:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tom\_rkba](https://avatars.discourse-cdn.com/v4/letter/t/e79b87/32.png) [@tom\_rkba](https://discuss.elastic.co/u/tom_rkba)\
**Post date:** [October 31, 2013, 2:04pm UTC](https://discuss.elastic.co/t/elasticsearch-templates-how-do-i-handle-field-properties/14190/1 "2013-10-31T14:04:03Z")

</div>

I am running Logstash and one of my logs has various properties.

I have successfully applied this template:

curl -XPUT [http://localhost:9200/\_template/logstash\_per\_index](http://localhost:9200/_template/logstash_per_index) -d '{  
"template": "logstash\*",  
"settings": {  
"index.query.default\_field": "@message",  
"index.cache.field.type": "soft",  
"index.store.compress.stored": true  
},  
"mappings": {  
"_default_": {  
"\_all": { "enabled": false },  
"properties": {  
"@message": { "type": "string", "index": "analyzed" },  
"@source": { "type": "string", "index": "not\_analyzed" },  
"@source\_host": { "type": "string", "index": "not\_analyzed" },  
"@source\_path": { "type": "string", "index": "not\_analyzed" },  
"@tags": { "type": "string", "index": "not\_analyzed" },  
"@timestamp": { "type": "string", "index": "not\_analyzed" },  
"@type": { "type": "string", "index": "not\_analyzed" }  
}  
}  
}  
}  
'

However, one of the logs being sent to ES via Logstash includes field  
properties. This is the grok filter from the Logstash conf:

pattern =\> "%{IP:vipIP} %{IP:queryingServerIP} - -  
[%{HTTPDATE:timestamp}] "%{WORD:httpmethod} %{URIPATHPARAM:request}  
%{WORD:httpprotocol}/%{NUMBER:httpversion:float}"  
%{NUMBER:httpresponsecode:int} %{NUMBER:bytes:int}  
%{NUMBER:responsetime:float}"  
add\_field =\> ["teamname", "Team1"]  
add\_field =\> ["sourcetype", "access\_log"]

This translates into these mappings on the ES server:

"metadata" : {  
"templates" : { },  
"indices" : {  
"logstash-2013.10.18" : {  
"state" : "open",  
"settings" : {  
"index.number\_of\_shards" : "3",  
"index.number\_of\_replicas" : "2",  
"index.version.created" : "900599"  
},  
"mappings" : {  
"access\_log" : {  
"properties" : {  
"@fields" : {  
"properties" : {  
"vipIP" : {  
"type" : "string"  
},  
"timestamp" : {  
"type" : "string"  
},  
"httpversion" : {  
"type" : "double"  
},  
"responsetime" : {  
"type" : "double"  
},  
"bytes" : {  
"type" : "long"  
},  
"teamname" : {  
"type" : "string"  
},  
"request" : {  
"type" : "string"  
},  
"queryingServerIP" : {  
"type" : "string"  
},  
"httpmethod" : {  
"type" : "string"  
},  
"httpprotocol" : {  
"type" : "string"  
},  
"httpresponsecode" : {  
"type" : "long"  
},  
"sourcetype" : {  
"type" : "string"  
}  
}  
},  
"@timestamp" : {  
"format" : "dateOptionalTime",  
"type" : "date"  
},  
"@message" : {  
"type" : "string"  
},  
"@source" : {  
"type" : "string"  
},  
"@type" : {  
"type" : "string"  
},  
"@tags" : {  
"type" : "string"  
},  
"@source\_host" : {  
"type" : "string"  
},  
"@source\_path" : {  
"type" : "string"  
}  
}  
},  
[snip]

Do I need to handle the field properties in the template? Or will the  
generic one I showed at the beginning of the post be adequate? If I do  
need to do something with them, what do I need to add?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![javanna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javanna/32/4698_2.png) [@javanna](https://discuss.elastic.co/u/javanna)\
**Post date:** [November 4, 2013, 5:50pm UTC](https://discuss.elastic.co/t/elasticsearch-templates-how-do-i-handle-field-properties/14190/2 "2013-11-04T17:50:14Z")

</div>

Hi,  
you don't necessarily need to add all the fields (or objects, which are  
fields anyway) to your mappings, unless you are not happy with the defaults.  
If you don't specify the @fields one in the mapping the type of its  
children will be auto-detected based on their json type. Also, the strings  
fields will be "analyzed".

On Thursday, October 31, 2013 3:04:03 PM UTC+1, tom rkba wrote:

> I am running Logstash and one of my logs has various properties.
> 
> I have successfully applied this template:
> 
> curl -XPUT [http://localhost:9200/\_template/logstash\_per\_index](http://localhost:9200/_template/logstash_per_index) -d '{  
> "template": "logstash\*",  
> "settings": {  
> "index.query.default\_field": "@message",  
> "index.cache.field.type": "soft",  
> "index.store.compress.stored": true  
> },  
> "mappings": {  
> "_default_": {  
> "\_all": { "enabled": false },  
> "properties": {  
> "@message": { "type": "string", "index": "analyzed" },  
> "@source": { "type": "string", "index": "not\_analyzed" },  
> "@source\_host": { "type": "string", "index": "not\_analyzed" },  
> "@source\_path": { "type": "string", "index": "not\_analyzed" },  
> "@tags": { "type": "string", "index": "not\_analyzed" },  
> "@timestamp": { "type": "string", "index": "not\_analyzed" },  
> "@type": { "type": "string", "index": "not\_analyzed" }  
> }  
> }  
> }  
> }  
> '
> 
> However, one of the logs being sent to ES via Logstash includes field  
> properties. This is the grok filter from the Logstash conf:
> 
> pattern =\> "%{IP:vipIP} %{IP:queryingServerIP} - -  
> [%{HTTPDATE:timestamp}] "%{WORD:httpmethod} %{URIPATHPARAM:request}  
> %{WORD:httpprotocol}/%{NUMBER:httpversion:float}"  
> %{NUMBER:httpresponsecode:int} %{NUMBER:bytes:int}  
> %{NUMBER:responsetime:float}"  
> add\_field =\> ["teamname", "Team1"]  
> add\_field =\> ["sourcetype", "access\_log"]
> 
> This translates into these mappings on the ES server:
> 
> "metadata" : {  
> "templates" : { },  
> "indices" : {  
> "logstash-2013.10.18" : {  
> "state" : "open",  
> "settings" : {  
> "index.number\_of\_shards" : "3",  
> "index.number\_of\_replicas" : "2",  
> "index.version.created" : "900599"  
> },  
> "mappings" : {  
> "access\_log" : {  
> "properties" : {  
> "@fields" : {  
> "properties" : {  
> "vipIP" : {  
> "type" : "string"  
> },  
> "timestamp" : {  
> "type" : "string"  
> },  
> "httpversion" : {  
> "type" : "double"  
> },  
> "responsetime" : {  
> "type" : "double"  
> },  
> "bytes" : {  
> "type" : "long"  
> },  
> "teamname" : {  
> "type" : "string"  
> },  
> "request" : {  
> "type" : "string"  
> },  
> "queryingServerIP" : {  
> "type" : "string"  
> },  
> "httpmethod" : {  
> "type" : "string"  
> },  
> "httpprotocol" : {  
> "type" : "string"  
> },  
> "httpresponsecode" : {  
> "type" : "long"  
> },  
> "sourcetype" : {  
> "type" : "string"  
> }  
> }  
> },  
> "@timestamp" : {  
> "format" : "dateOptionalTime",  
> "type" : "date"  
> },  
> "@message" : {  
> "type" : "string"  
> },  
> "@source" : {  
> "type" : "string"  
> },  
> "@type" : {  
> "type" : "string"  
> },  
> "@tags" : {  
> "type" : "string"  
> },  
> "@source\_host" : {  
> "type" : "string"  
> },  
> "@source\_path" : {  
> "type" : "string"  
> }  
> }  
> },  
> [snip]
> 
> Do I need to handle the field properties in the template? Or will the  
> generic one I showed at the beginning of the post be adequate? If I do  
> need to do something with them, what do I need to add?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:08am UTC](https://discuss.elastic.co/t/elasticsearch-templates-how-do-i-handle-field-properties/14190/3 "2017-07-06T02:08:59Z")

</div>


