# How to map already fields in a index to ECS fields in elasticsearch

**URL:** <https://discuss.elastic.co/t/how-to-map-already-fields-in-a-index-to-ecs-fields-in-elasticsearch/208868>\
**Category:** Elasticsearch\
**Created:** [November 21, 2019, 11:21am UTC](https://discuss.elastic.co/t/how-to-map-already-fields-in-a-index-to-ecs-fields-in-elasticsearch/208868 "2019-11-21T11:21:38Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vishnu\_mk](https://avatars.discourse-cdn.com/v4/letter/v/71c47a/32.png) [@Vishnu\_mk](https://discuss.elastic.co/u/Vishnu_mk)\
**Post date:** [November 21, 2019, 11:21am UTC](https://discuss.elastic.co/t/how-to-map-already-fields-in-a-index-to-ecs-fields-in-elasticsearch/208868/1 "2019-11-21T11:21:39Z")

</div>

Suppose I want to map my ClientIP field to ECS fIeld what is the approach.  
The ClientIP filed is already created in the index . Can I map it to ECS field,if the ClientIP field is already created

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 21, 2019, 11:38am UTC](https://discuss.elastic.co/t/how-to-map-already-fields-in-a-index-to-ecs-fields-in-elasticsearch/208868/2 "2019-11-21T11:38:17Z")

</div>

take a look at the [alias datatype](https://www.elastic.co/guide/en/elasticsearch/reference/7.4/alias.html)

---

<div class="post-metadata">

**Author:** ![Vishnu\_mk](https://avatars.discourse-cdn.com/v4/letter/v/71c47a/32.png) [@Vishnu\_mk](https://discuss.elastic.co/u/Vishnu_mk)\
**Post date:** [November 21, 2019, 12:00pm UTC](https://discuss.elastic.co/t/how-to-map-already-fields-in-a-index-to-ecs-fields-in-elasticsearch/208868/3 "2019-11-21T12:00:39Z")

</div>

```
PUT siem-test
{
  "mappings": {
    "properties": {
      "ClientIP": {
        "type": "text"
      },
      "client.ip": {
        "type": "alias"
      },
      "transit_mode": {
        "type": "keyword"
      }
    }
  }
}

```

I am getting following error:

```
{
  "error": {
    "root_cause": [
      {
        "type": "resource_already_exists_exception",
        "reason": "index [siem-test/GQN9k-6YSpuaCrU0DrdACg] already exists",
        "index_uuid": "GQN9k-6YSpuaCrU0DrdACg",
        "index": "siem-test"
      }
    ],
    "type": "resource_already_exists_exception",
    "reason": "index [siem-test/GQN9k-6YSpuaCrU0DrdACg] already exists",
    "index_uuid": "GQN9k-6YSpuaCrU0DrdACg",
    "index": "siem-test"
  },
  "status": 400
}
```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 21, 2019, 2:50pm UTC](https://discuss.elastic.co/t/how-to-map-already-fields-in-a-index-to-ecs-fields-in-elasticsearch/208868/4 "2019-11-21T14:50:19Z")

</div>

you have to update the mappings, you cannot recreate the index unless you want to delete it

```auto
PUT siem-test/_mappings
{
  "properties": {
    "client.ip": {
      "type": "alias",
      "path": "ClientIP"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Vishnu\_mk](https://avatars.discourse-cdn.com/v4/letter/v/71c47a/32.png) [@Vishnu\_mk](https://discuss.elastic.co/u/Vishnu_mk)\
**Post date:** [November 22, 2019, 6:00am UTC](https://discuss.elastic.co/t/how-to-map-already-fields-in-a-index-to-ecs-fields-in-elasticsearch/208868/5 "2019-11-22T06:00:10Z")

</div>

> [@spinscale](#):
>
> PUT siem-test/\_mappings { "properties": { "client.ip": { "type": "alias", "path": "ClientIP" } } }

Thank you @spinscale for your help.  
But i am getting bellow error now

```
{
  "error": {
    "root_cause": [
      {
        "type": "illegal_argument_exception",
        "reason": "mapper [client] of different type, current_type [text], merged_type [ObjectMapper]"
      }
    ],
    "type": "illegal_argument_exception",
    "reason": "mapper [client] of different type, current_type [text], merged_type [ObjectMapper]"
  },
  "status": 400
}

```

---

<div class="post-metadata">

**Author:** ![Vishnu\_mk](https://avatars.discourse-cdn.com/v4/letter/v/71c47a/32.png) [@Vishnu\_mk](https://discuss.elastic.co/u/Vishnu_mk)\
**Post date:** [November 22, 2019, 11:08am UTC](https://discuss.elastic.co/t/how-to-map-already-fields-in-a-index-to-ecs-fields-in-elasticsearch/208868/6 "2019-11-22T11:08:46Z")

</div>

Thank you @spinscale it worked now

```
PUT siem-test/_mappings
{
  "properties": {
    "client.ip": {
      "type": "alias",
      "path": "ClientIP.keyword"
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Vishnu\_mk](https://avatars.discourse-cdn.com/v4/letter/v/71c47a/32.png) [@Vishnu\_mk](https://discuss.elastic.co/u/Vishnu_mk)\
**Post date:** [November 22, 2019, 12:25pm UTC](https://discuss.elastic.co/t/how-to-map-already-fields-in-a-index-to-ecs-fields-in-elasticsearch/208868/7 "2019-11-22T12:25:32Z")

</div>

Hii @spinscale the filed name got renamed but then to it is not getting popped up in SIEM APP of elastic

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [November 28, 2019, 8:33am UTC](https://discuss.elastic.co/t/how-to-map-already-fields-in-a-index-to-ecs-fields-in-elasticsearch/208868/8 "2019-11-28T08:33:32Z")

</div>

Sorry, I am not a heavy SIEM user (yet), you may want to ask this specific question in the [SIEM category](https://discuss.elastic.co/c/siem)

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2019, 8:33am UTC](https://discuss.elastic.co/t/how-to-map-already-fields-in-a-index-to-ecs-fields-in-elasticsearch/208868/9 "2019-12-26T08:33:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
