# Fields not saved with template mapping

**URL:** <https://discuss.elastic.co/t/fields-not-saved-with-template-mapping/206785>\
**Category:** Elasticsearch\
**Created:** [November 6, 2019, 11:54am UTC](https://discuss.elastic.co/t/fields-not-saved-with-template-mapping/206785 "2019-11-06T11:54:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mortueta](https://avatars.discourse-cdn.com/v4/letter/m/3ec8ea/32.png) [@mortueta](https://discuss.elastic.co/u/mortueta)\
**Post date:** [November 6, 2019, 11:54am UTC](https://discuss.elastic.co/t/fields-not-saved-with-template-mapping/206785/1 "2019-11-06T11:54:50Z")

</div>

Hi,

Before now I was using dynamic templates as it is quite easy to structure the data automatically and in case of needing new fields this is done automatically.

Now that I have every field that I need, I want to define the field types to improve everything (searcheability, storage, performance...)

I have taken the dynamic template as example and redefine the field types to the needs. The template is stored in the right way but now I am not getting the field only basic data.

Logstash is not trowing any error of mapping.

> **Logstash output**
>
> {  
> "fac" =\> "f\_dns\_proxy",  
> "area" =\> "a\_aclquery",  
> "cmd" =\> "dnsp",  
> "dstport" =\> 53,  
> "rule\_name" =\> "my rule",  
> "dstip" =\> "1.1.1.1",  
> "host" =\> "0.0.0.0",  
> "@version" =\> "1",  
> "reason" =\> "Traffic allowed by policy.",  
> "logid" =\> 0,  
> "srcport" =\> 55890,  
> "hostname" =\> "[example.example.org](http://example.example.org)",  
> "srczone" =\> "internal",  
> "pri" =\> "p\_major",  
> "syslog5424\_pri" =\> "46",  
> "@timestamp" =\> 2019-11-06T11:27:13.698Z,  
> "event" =\> "ACL allow",  
> "dstzone" =\> "internal",  
> "pid" =\> "32445",  
> "type" =\> "t\_aclallow",  
> "application" =\> "DNS\n",  
> "program" =\> "auditd",  
> "srcip" =\> "1.1.1.1",  
> "cache\_hit" =\> 1,  
> "protocol" =\> "17",  
> "logsource" =\> "example"  
> }

WIth dynamic everything fine

 ![Dynamic](https://us1.discourse-cdn.com/elastic/original/3X/c/8/c8134bb8f3d750b493a1e8b1ba389efe9a3c951a.png)

Using template I am not seeing any field any longer

 ![template](https://us1.discourse-cdn.com/elastic/original/3X/2/0/208b7fe841d72836a671a00650deeba4a83dc46e.png)

---

<div class="post-metadata">

**Author:** ![mortueta](https://avatars.discourse-cdn.com/v4/letter/m/3ec8ea/32.png) [@mortueta](https://discuss.elastic.co/u/mortueta)\
**Post date:** [November 6, 2019, 11:55am UTC](https://discuss.elastic.co/t/fields-not-saved-with-template-mapping/206785/2 "2019-11-06T11:55:47Z")

</div>

I was not able to to attach the template because the character limitations.

> **Template**
>
> [PUT \_template/fwsw\_1  
> {  
> "index\_patterns": ["logstash-firewall-syslog-sidewinder-\*"],  
> "settings": {  
> "number\_of\_shards": 5  
> },  
> "mappings": {  
> "\_source": {  
> "enabled": false  
> },  
> "properties": {  
> "@timestamp": {  
> "type": "date"  
> },  
> "@version": {  
> "type": "keyword"  
> },  
> "app\_categories": {  
> "type": "keyword"  
> },  
> "app\_risk": {  
> "type": "keyword"  
> },  
> "application": {  
> "type": "keyword"  
> },  
> "area": {  
> "type": "keyword"  
> },  
> "attackip": {  
> "type": "ip"  
> },  
> "attackzone": {  
> "type": "keyword"  
> },  
> "bytes\_written\_to\_client": {  
> "type": "long"  
> },  
> "bytes\_written\_to\_server": {  
> "type": "long"  
> },  
> "cache\_hit": {  
> "type": "integer"  
> },  
> "category": {  
> "type": "keyword"  
> },  
> "cky\_i": {  
> "type": "keyword"  
> },  
> "cky\_r": {  
> "type": "keyword"  
> },  
> "cmd": {  
> "type": "keyword"  
> },  
> "config\_area": {  
> "type": "keyword"  
> },  
> "config\_item": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "cpu\_data": {  
> "type": "integer"  
> },  
> "dst\_geo": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "dstip": {  
> "type": "ip"  
> },  
> "dstport": {  
> "type": "integer"  
> },  
> "dstzone": {  
> "type": "keyword"  
> },  
> "event": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "fac": {  
> "type": "keyword"  
> },  
> "geoip": {  
> "dynamic": "true",  
> "properties": {  
> "city\_name": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "continent\_code": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "country\_code2": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "country\_code3": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "country\_name": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "ip": {  
> "type": "ip"  
> },  
> "latitude": {  
> "type": "half\_float"  
> },  
> "location": {  
> "type": "geo\_point"  
> },  
> "longitude": {  
> "type": "half\_float"  
> },  
> "postal\_code": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "region\_code": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "region\_name": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "timezone": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> }  
> }  
> },  
> "host": {  
> "type": "keyword"  
> },  
> "hostname": {  
> "type": "keyword"  
> },  
> "ibytes": {  
> "type": "long"  
> },  
> "information": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "interface": {  
> "type": "keyword"  
> },  
> "ipkt": {  
> "type": "integer"  
> },  
> "load\_data": {  
> "type": "integer"  
> },  
> "local\_gw": {  
> "type": "ip"  
> },  
> "local\_net": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "logid": {  
> "type": "integer"  
> },  
> "logsource": {  
> "type": "keyword"  
> },  
> "mbuf\_data": {  
> "type": "integer"  
> },  
> "msg\_id": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "netsessid": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "obytes": {  
> "type": "long"  
> },  
> "opkt": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "pid": {  
> "type": "keyword"  
> },  
> "pri": {  
> "type": "keyword"  
> },  
> "program": {  
> "type": "keyword"  
> },  
> "protocol": {  
> "type": "keyword"  
> },  
> "real\_data": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "reason": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "remote\_gw": {  
> "type": "ip"  
> },  
> "remote\_id": {  
> "type": "keyword"  
> },  
> "remote\_logname": {  
> "type": "keyword"  
> },  
> "remote\_net": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "request\_command": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "rule\_name": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "spi": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "src\_geo": {  
> "type": "keyword"  
> },  
> "srcip": {  
> "type": "ip"  
> },  
> "srcport": {  
> "type": "integer"  
> },  
> "srczone": {  
> "type": "keyword"  
> },  
> "ssl\_name": {  
> "type": "keyword"  
> },  
> "syslog5424\_pri": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "total\_events": {  
> "type": "integer"  
> },  
> "type": {  
> "type": "keyword"  
> },  
> "udb\_action": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "udb\_class": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "udb\_user": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "user\_name": {  
> "type": "keyword"  
> },  
> "virt\_data": {  
> "type": "integer"  
> },  
> "vpn\_name": {  
> "type": "keyword"  
> }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![mortueta](https://avatars.discourse-cdn.com/v4/letter/m/3ec8ea/32.png) [@mortueta](https://discuss.elastic.co/u/mortueta)\
**Post date:** [November 11, 2019, 2:16pm UTC](https://discuss.elastic.co/t/fields-not-saved-with-template-mapping/206785/3 "2019-11-11T14:16:08Z")

</div>

FEEDBACK

I created the template from the GUI following the "Create template" wizard and now it is working. Probably something wasn't defined properly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 9, 2019, 2:16pm UTC](https://discuss.elastic.co/t/fields-not-saved-with-template-mapping/206785/4 "2019-12-09T14:16:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
