# Filebeat custom log files / how to disable default module field mappings

**URL:** <https://discuss.elastic.co/t/filebeat-custom-log-files-how-to-disable-default-module-field-mappings/196195>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 21, 2019, 9:24pm UTC](https://discuss.elastic.co/t/filebeat-custom-log-files-how-to-disable-default-module-field-mappings/196195 "2019-08-21T21:24:15Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tishma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tishma/32/10026_2.png) [@tishma](https://discuss.elastic.co/u/tishma)\
**Post date:** [August 21, 2019, 9:24pm UTC](https://discuss.elastic.co/t/filebeat-custom-log-files-how-to-disable-default-module-field-mappings/196195/1 "2019-08-21T21:24:15Z")

</div>

I'm using filebeat to read log files that are not supported out of the box, for elasticsearch indexing.

The thing is that I get 1000+ field mappings that appear to be coming from default filebeat modules (apache, nginx, system, docker, etc.), and they only get in the way.

I've tried to reference a custom `fields.yml` file in `filebeat.yml` config, but it doesn't seem to make a difference. I'm still getting all those mappings. All the filebeat modules are disabled by default, so their state is also irrelevant.  
Any hint is much appreciated.

---

<div class="post-metadata">

**Author:** ![faec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faec/32/46988_2.png) [@faec](https://discuss.elastic.co/u/faec)\
**Post date:** [August 22, 2019, 7:45pm UTC](https://discuss.elastic.co/t/filebeat-custom-log-files-how-to-disable-default-module-field-mappings/196195/2 "2019-08-22T19:45:36Z")

</div>

There are various settings that will let you use a custom index template, overwrite an existing template, or turn off template management so you can set them up manually -- see [the docs here](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html) for details

---

<div class="post-metadata">

**Author:** ![tishma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tishma/32/10026_2.png) [@tishma](https://discuss.elastic.co/u/tishma)\
**Post date:** [August 23, 2019, 3:57pm UTC](https://discuss.elastic.co/t/filebeat-custom-log-files-how-to-disable-default-module-field-mappings/196195/3 "2019-08-23T15:57:49Z")

</div>

Thanks. My specific problem was with `setup.template.fields: "path/to/fields.yml"` that seemed to make no difference at all.  
I've added custom file, and I still got all fields from the default `fields.yml` in my index.

But I already figured out to turn it off completely, and I choose to do that instead.

---

<div class="post-metadata">

**Author:** ![0x00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/0x00/32/52748_2.png) [@0x00](https://discuss.elastic.co/u/0x00)\
**Post date:** [August 23, 2019, 4:15pm UTC](https://discuss.elastic.co/t/filebeat-custom-log-files-how-to-disable-default-module-field-mappings/196195/4 "2019-08-23T16:15:28Z")

</div>

If you don't mind sharing, what was the solution to turn it off completely? I was having a similar problem a few days ago.

Thanks!

---

<div class="post-metadata">

**Author:** ![tishma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tishma/32/10026_2.png) [@tishma](https://discuss.elastic.co/u/tishma)\
**Post date:** [August 23, 2019, 4:18pm UTC](https://discuss.elastic.co/t/filebeat-custom-log-files-how-to-disable-default-module-field-mappings/196195/5 "2019-08-23T16:18:55Z")

</div>

`setup.template.enabled: false` (it's also in the doc...)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 20, 2019, 4:21pm UTC](https://discuss.elastic.co/t/filebeat-custom-log-files-how-to-disable-default-module-field-mappings/196195/6 "2019-09-20T16:21:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
