# Filebeat to elasticsearch configuration(mapping)

**URL:** <https://discuss.elastic.co/t/filebeat-to-elasticsearch-configuration-mapping/271031>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 23, 2021, 3:26am UTC](https://discuss.elastic.co/t/filebeat-to-elasticsearch-configuration-mapping/271031 "2021-04-23T03:26:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tkkchan](https://avatars.discourse-cdn.com/v4/letter/t/8491ac/32.png) [@tkkchan](https://discuss.elastic.co/u/tkkchan)\
**Post date:** [April 23, 2021, 3:26am UTC](https://discuss.elastic.co/t/filebeat-to-elasticsearch-configuration-mapping/271031/1 "2021-04-23T03:26:41Z")

</div>

Dear All,  
I am currently trying to put some files into ES using Filebeat, and meanwhile I want to see if I can set the mapping(with Filebeat, without calling API for ES). As I see from some logstash config, there's a way to do it, like below:

```auto
output {
    stdout { codec => rubydebug }
    elasticsearch {
        hosts => ["localhost:9200"]
        index => "your_index"
        template => "mapping.json"
        template_overwrite => true

}

```

Is there a way to do this in filebeat.yml? if so, could you please show me the correct syntax?

Right now my filebeat.yml output section looks like this

```auto
output.elasticsearch:
  hosts: ["localhost:9200"]
  index: "your_index"

```

Cheers,  
TK

---

<div class="post-metadata">

**Author:** ![ndtreviv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ndtreviv/32/22494_2.png) [@ndtreviv](https://discuss.elastic.co/u/ndtreviv)\
**Post date:** [April 23, 2021, 10:05am UTC](https://discuss.elastic.co/t/filebeat-to-elasticsearch-configuration-mapping/271031/2 "2021-04-23T10:05:43Z")

</div>

Yes, this is possible. Take a look at this:

> **[Configure Elasticsearch index template loading | Filebeat Reference \[7.12\] |...](https://www.elastic.co/guide/en/beats/filebeat/current/configuration-template.html)**

So you'll need something like:

```auto
setup.template.name: your-index
setup.template.pattern: your-index-*
setup.template.fields: "your-index-fields.yml"
setup.template.overwrite: true

```

and then under the `output.elasticsearch` section something like:

```auto
  index: "your-index-%{+yyyy.MM.dd}"

```

For a reference of what should be in your-index-fields.yml, take a look at the fields.yml that comes installed in `/etc/filebeat/fields.yml`

---

<div class="post-metadata">

**Author:** ![tkkchan](https://avatars.discourse-cdn.com/v4/letter/t/8491ac/32.png) [@tkkchan](https://discuss.elastic.co/u/tkkchan)\
**Post date:** [April 29, 2021, 2:18am UTC](https://discuss.elastic.co/t/filebeat-to-elasticsearch-configuration-mapping/271031/3 "2021-04-29T02:18:01Z")

</div>

Dear Nathan,  
thank you very much indeed!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2021, 4:18am UTC](https://discuss.elastic.co/t/filebeat-to-elasticsearch-configuration-mapping/271031/4 "2021-05-27T04:18:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
