I am using filebeat to send logs to logstash for processing, and finally, sending them to elasticsearch for graphing in kibana.
My question is:
Does filebeat affect how elasticsearch makes a dynamic mapping?
I ask this because when I used the "file" input to send logs to elasticsearch, I got very simple dynamic mappings(a dozen lines). However when I changed the logstash input to be filebeat, The mapping became huge (hundreds of lines). In addition, some fields now make Kibana unhappy, as I get an error I did not get before.
Does anyone know if filebeat has an effect on elasticsearch dynamic mappings, and if so, how do I control it?
Any help would be greatly appreciated.