# Exclude fields from being indexed via dynamic templates mapping

**URL:** https://discuss.elastic.co/t/exclude-fields-from-being-indexed-via-dynamic-templates-mapping/142998
**Category:** Elasticsearch
**Created:** [August 4, 2018, 1:34am UTC](https://discuss.elastic.co/t/exclude-fields-from-being-indexed-via-dynamic-templates-mapping/142998 "2018-08-04T01:34:35Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![mrubin](https://avatars.discourse-cdn.com/v4/letter/m/e19adc/32.png) [@mrubin](https://discuss.elastic.co/u/mrubin)
#### Post date: [August 4, 2018, 1:34am UTC](https://discuss.elastic.co/t/exclude-fields-from-being-indexed-via-dynamic-templates-mapping/142998/1 "2018-08-04T01:34:35Z")

</div>

I have the following kind of json being indexed into ElasticSearch via Logstash:

```
"gameUpdate" : {
  "someField" : "something interesting",
  "otherStuff" : "...",
  "gameScores" : {
    "playerID1" : { ... },
    "playerID2" : { ... },
    "playerID3" : { ... },
    ...
  }
}

```

There could be a a large number of unique player IDs. I routinely run into "Could not index event to Elasticsearch. ... Limit of total fields [1000] in index [...] has been exceeded"

I have tried setting a custom template for this index as follows:

```
PUT _template/game-updates
{
  "index_patterns": ["game-updates-*"],
  "mappings": {
    "doc": {
      "dynamic_templates": [
        {
          "dont_index_scores": {
            "path_match": "gameUpdate.gameScores",
            "mapping": {
              "index": false
            }
          }
        }
      ]
    }
  }
}

```

For the path to match, I've tried "gameUpdate.gameScores" and "gameUpdate.gameScores.\*" and various other variants. If I retrieve the mapping for an index created from this template, it echoes that gameScores should not be indexed. However, I still see the logstash errors.

What is the correct way to exclude these fields from the index?

---

<div class="post-metadata">

### Author: ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)
#### Post date: [August 6, 2018, 4:03pm UTC](https://discuss.elastic.co/t/exclude-fields-from-being-indexed-via-dynamic-templates-mapping/142998/2 "2018-08-06T16:03:08Z")

</div>

try

```auto
"gameUpdate" : {
 "properties: {
        "gameScores": {
          "type": "object",
          "enabled": false
        },
  }
..

```

hope this helps

---

<div class="post-metadata">

### Author: ![mrubin](https://avatars.discourse-cdn.com/v4/letter/m/e19adc/32.png) [@mrubin](https://discuss.elastic.co/u/mrubin)
#### Post date: [August 6, 2018, 11:35pm UTC](https://discuss.elastic.co/t/exclude-fields-from-being-indexed-via-dynamic-templates-mapping/142998/3 "2018-08-06T23:35:01Z")

</div>

Is your suggestion meant for manually mapping the index, or for a dynamic mapping template? Can you please provide a more complete example which includes the

```
"mappings": {
  "doc": {
    "dynamic_templates": [
        ...
```

---

<div class="post-metadata">

### Author: ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)
#### Post date: [August 7, 2018, 6:26am UTC](https://discuss.elastic.co/t/exclude-fields-from-being-indexed-via-dynamic-templates-mapping/142998/4 "2018-08-07T06:26:23Z")

</div>

you can put that directly into the mapping, as you do not need to match anything, you are referring directly to the fields.

---

<div class="post-metadata">

### Author: ![mrubin](https://avatars.discourse-cdn.com/v4/letter/m/e19adc/32.png) [@mrubin](https://discuss.elastic.co/u/mrubin)
#### Post date: [August 7, 2018, 11:04am UTC](https://discuss.elastic.co/t/exclude-fields-from-being-indexed-via-dynamic-templates-mapping/142998/5 "2018-08-07T11:04:06Z")

</div>

Can I mix both a dynamic mapping template and this one property specified in the mapping?

Edit: my index is auto-created every day when logstash rolls over to a new date. It's not feasible to create an explicit mapping for it. I need to use a dynamic mapping template that I can set once and have it apply to any index created which matches a certain pattern.

---

<div class="post-metadata">

### Author: ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)
#### Post date: [August 7, 2018, 11:25am UTC](https://discuss.elastic.co/t/exclude-fields-from-being-indexed-via-dynamic-templates-mapping/142998/6 "2018-08-07T11:25:49Z")

</div>

yes, you can.

---

<div class="post-metadata">

### Author: ![mrubin](https://avatars.discourse-cdn.com/v4/letter/m/e19adc/32.png) [@mrubin](https://discuss.elastic.co/u/mrubin)
#### Post date: [August 7, 2018, 12:16pm UTC](https://discuss.elastic.co/t/exclude-fields-from-being-indexed-via-dynamic-templates-mapping/142998/7 "2018-08-07T12:16:12Z")

</div>

How do I specify a mapping when my index is auto-created every day by logstash?

---

<div class="post-metadata">

### Author: ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)
#### Post date: [August 7, 2018, 12:27pm UTC](https://discuss.elastic.co/t/exclude-fields-from-being-indexed-via-dynamic-templates-mapping/142998/8 "2018-08-07T12:27:03Z")

</div>

via an [index template](https://www.elastic.co/guide/en/elasticsearch/reference/6.3/indices-templates.html) (logstash is using the exact same mechanism)

---

<div class="post-metadata">

### Author: ![mrubin](https://avatars.discourse-cdn.com/v4/letter/m/e19adc/32.png) [@mrubin](https://discuss.elastic.co/u/mrubin)
#### Post date: [August 10, 2018, 3:44am UTC](https://discuss.elastic.co/t/exclude-fields-from-being-indexed-via-dynamic-templates-mapping/142998/9 "2018-08-10T03:44:02Z")

</div>

Thanks - this worked. I didn't know I could explicitly specify a field in the mapping (to be disabled, for example) while letting dynamic mapping still take care of the rest of the fields it encounters.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 7, 2018, 3:55am UTC](https://discuss.elastic.co/t/exclude-fields-from-being-indexed-via-dynamic-templates-mapping/142998/10 "2018-09-07T03:55:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
