# Fields and Space

**URL:** <https://discuss.elastic.co/t/fields-and-space/36756>\
**Category:** Logstash\
**Created:** [December 9, 2015, 3:28pm UTC](https://discuss.elastic.co/t/fields-and-space/36756 "2015-12-09T15:28:04Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [December 9, 2015, 3:28pm UTC](https://discuss.elastic.co/t/fields-and-space/36756/1 "2015-12-09T15:28:04Z")

</div>

I understand how to create fields in Logstash however once they go into Elasticsearch and into Kibana I get .raw versions and the space difference between my indexes before the new ELK 2+ stack were significantly smaller. Is there a way through my logstash config i can save on disk space?

Thanks  
Jack

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 9, 2015, 6:34pm UTC](https://discuss.elastic.co/t/fields-and-space/36756/2 "2015-12-09T18:34:00Z")

</div>

Go through your string fields and make sure they're analyzed in the best way. By default you'll get the field itself analyzed and a .raw subfield with the non-analyzed string, but this doesn't always make sense. Some fields are better left unanalyzed from the start (then you don't need a separate .raw subfield) and for others it doesn't make sense to have the .raw field. Adjust the index template as needed.

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [December 10, 2015, 1:01pm UTC](https://discuss.elastic.co/t/fields-and-space/36756/3 "2015-12-10T13:01:27Z")

</div>

how do i adjust the index template?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 10, 2015, 1:26pm UTC](https://discuss.elastic.co/t/fields-and-space/36756/4 "2015-12-10T13:26:04Z")

</div>

Copy the index template file that ships with Logstash (/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-1.0.5-java/lib/logstash/outputs/elasticsearch/elasticsearch-template.json or similar) to another location, edit it, and update the elasticsearch output's `template` option to point to your modified copy. The next time ES creates an index it should have your updated mappings. You can't change the existing mappings without reindexing.

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [December 10, 2015, 2:58pm UTC](https://discuss.elastic.co/t/fields-and-space/36756/5 "2015-12-10T14:58:48Z")

</div>

This is awesome and exactly what i'm looking for! Thanks for the quick response. I found it but i'm not sure what i'm looking at can you point me to any documentation that i could teach myself what i'm looking at?

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 10, 2015, 3:06pm UTC](https://discuss.elastic.co/t/fields-and-space/36756/6 "2015-12-10T15:06:21Z")

</div>

[https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html)  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html)  
[https://www.elastic.co/guide/en/elasticsearch/guide/current/mapping.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/mapping.html)

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [December 10, 2015, 3:57pm UTC](https://discuss.elastic.co/t/fields-and-space/36756/7 "2015-12-10T15:57:19Z")

</div>

I've read all of these now and my question is there a place to set "doc\_values" false to all fields? or do i have to wait for the fields to be created and then change them after the fact? If I have a bunch of fields do i define each filed in this template?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 10, 2015, 5:47pm UTC](https://discuss.elastic.co/t/fields-and-space/36756/8 "2015-12-10T17:47:34Z")

</div>

You can set default mappings per type which is how the default template does to enable doc values and add the .raw subfield. Which version of the elasticsearch output are you using? There have been some recent changes there.

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [December 15, 2015, 3:41pm UTC](https://discuss.elastic.co/t/fields-and-space/36756/9 "2015-12-15T15:41:09Z")

</div>

Sorry for the delayed response. I'm using Elastic 2.1 my output from logstash is

output {  
elasticsearch  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:18am UTC](https://discuss.elastic.co/t/fields-and-space/36756/10 "2017-07-06T05:18:20Z")

</div>


