# How does elasticsearch index json

**URL:** <https://discuss.elastic.co/t/how-does-elasticsearch-index-json/285335>\
**Category:** Elasticsearch\
**Tags:** ecs-elastic-common-schema\
**Created:** [September 28, 2021, 10:02am UTC](https://discuss.elastic.co/t/how-does-elasticsearch-index-json/285335 "2021-09-28T10:02:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zeeshan\_Alam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zeeshan_alam/32/94298_2.png) [@Zeeshan\_Alam](https://discuss.elastic.co/u/Zeeshan_Alam)\
**Post date:** [September 28, 2021, 10:02am UTC](https://discuss.elastic.co/t/how-does-elasticsearch-index-json/285335/1 "2021-09-28T10:02:14Z")

</div>

We are trying to push log into elastic which adhere to Elastic Common Schema (ECS) .

Does elastic index data differently for the logs shown below. Both are having same data just the JSON format is different.

**Format 1**

```auto
{
  "log.level": "INFO",
  "log.logger": "org.elasticsearch.bootstrap.Bootstrap",
  "log.file.path": "/var/log/fun-times.log"
}

```

**Format 2**

```auto
{
  "log": {
    "level": "INFO",
    "logger": "org.elasticsearch.bootstrap.Bootstrap",
    "file": {
      "path": "/var/log/fun-times.log"
    }
  }
}

```

Ref: [Log Fields | Elastic Common Schema (ECS) Reference [1.11] | Elastic](https://www.elastic.co/guide/en/ecs/1.11/ecs-log.html)

---

<div class="post-metadata">

**Author:** ![kgeller](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kgeller/32/85639_2.png) [@kgeller](https://discuss.elastic.co/u/kgeller)\
**Post date:** [September 29, 2021, 1:50pm UTC](https://discuss.elastic.co/t/how-does-elasticsearch-index-json/285335/2 "2021-09-29T13:50:17Z")

</div>

There is no difference to Elasticsearch between those two formats.

See [Questions and Answers | Elastic Common Schema (ECS) Reference [1.12] | Elastic](https://www.elastic.co/guide/en/ecs/current/ecs-faq.html#notation-diff)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 29, 2021, 3:24pm UTC](https://discuss.elastic.co/t/how-does-elasticsearch-index-json/285335/3 "2021-09-29T15:24:25Z")

</div>

@kgeller Welcome to the Community!

@Zeeshan_Alam Just to add on a bit to what @kgeller said.

As was said, The 2 Formats are **Indexed** exactly the same, meaning how the **fields** are stored and then queried are exactly this same but there are some subtle difference

1. And it may be obvious but the `_source` documents will remain different.... with the "`.`" notation the source will not be automatically converted from Format 1 to Format 2 (see below)

2. IF you wanted to ingest those documents and use an ingest pipeline to operate on them (change, set, mutate etc) ingest pipelines will not work on Format 1 See [Here](https://www.elastic.co/guide/en/elasticsearch/reference/current/dot-expand-processor.html) unless you use the `dot_expander` processor. I bring this up because it can cause confusion sometime when people try to use ingest pipeline with documents with the "`.`" notations, ingest pipeline are executed pre-index time so they work on the source document... or in the case with format 1... will not work 🙂

```auto
GET discuss/_search
{
  "fields": [
    "*"
  ]
}

```

Result: Note the \_source is unchanged for each but the indexed fields are equivalent.

```auto
{
  "took" : 1,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 2,
      "relation" : "eq"
    },
    "max_score" : 1.0,
    "hits" : [
      {
        "_index" : "discuss",
        "_type" : "_doc",
        "_id" : "eIAcMnwBSSVLweAdY8S_",
        "_score" : 1.0,
        "_source" : {
          "log.level" : "INFO",
          "log.logger" : "org.elasticsearch.bootstrap.Bootstrap",
          "log.file.path" : "/var/log/fun-times.log"
        },
        "fields" : {
          "log.level.keyword" : [
            "INFO"
          ],
          "log.file.path" : [
            "/var/log/fun-times.log"
          ],
          "log.level" : [
            "INFO"
          ],
          "log.logger.keyword" : [
            "org.elasticsearch.bootstrap.Bootstrap"
          ],
          "log.logger" : [
            "org.elasticsearch.bootstrap.Bootstrap"
          ],
          "log.file.path.keyword" : [
            "/var/log/fun-times.log"
          ]
        }
      },
      {
        "_index" : "discuss",
        "_type" : "_doc",
        "_id" : "eYAcMnwBSSVLweAd2cTe",
        "_score" : 1.0,
        "_source" : {
          "log" : {
            "level" : "INFO",
            "logger" : "org.elasticsearch.bootstrap.Bootstrap",
            "file" : {
              "path" : "/var/log/fun-times.log"
            }
          }
        },
        "fields" : {
          "log.level.keyword" : [
            "INFO"
          ],
          "log.file.path" : [
            "/var/log/fun-times.log"
          ],
          "log.level" : [
            "INFO"
          ],
          "log.logger.keyword" : [
            "org.elasticsearch.bootstrap.Bootstrap"
          ],
          "log.logger" : [
            "org.elasticsearch.bootstrap.Bootstrap"
          ],
          "log.file.path.keyword" : [
            "/var/log/fun-times.log"
          ]
        }
      }
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 27, 2021, 3:24pm UTC](https://discuss.elastic.co/t/how-does-elasticsearch-index-json/285335/4 "2021-10-27T15:24:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
