# How to properly use Mappings?

**URL:** <https://discuss.elastic.co/t/how-to-properly-use-mappings/55422>\
**Category:** Elasticsearch\
**Created:** [July 13, 2016, 3:35pm UTC](https://discuss.elastic.co/t/how-to-properly-use-mappings/55422 "2016-07-13T15:35:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![stash](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@stash](https://discuss.elastic.co/u/stash)\
**Post date:** [July 13, 2016, 3:35pm UTC](https://discuss.elastic.co/t/how-to-properly-use-mappings/55422/1 "2016-07-13T15:35:48Z")

</div>

Hi,

I use logstash to feed data into elasticsearch. I am processing error logs and I have a field called SEVERITY that can take up just a few values (all strings). So I'd like this field not to be analyzed. I gathered that if I create an index first it [ie. the SEVERITY field] will be analyzed by default. If I add an index template first, however, and feed data in afterwards I get the following exception from elasticsearch:

`MapperParsingException[Failed to parse mapping [SEVERITY]: Root mapping definition has unsupported parameters: [index : not_analyzed] [type : string]];`

My index template is the following:

```
[INSTBASE=devl]$ curl -XGET 'localhost:9200/_template/app_errors_default?pretty'
{
  "app_errors_default" : {
    "order" : 0,
    "template" : "app_errors_*",
    "settings" : { },
    "mappings" : {
      "SEVERITY" : {
        "index" : "not_analyzed",
        "type" : "string"
      }
    },
    "aliases" : { }
  }
}

```

(Please note, that I have not attempted to create the index manually.)

What I am missing here?

---

<div class="post-metadata">

**Author:** ![javanna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/javanna/32/4698_2.png) [@javanna](https://discuss.elastic.co/u/javanna)\
**Post date:** [July 14, 2016, 7:43am UTC](https://discuss.elastic.co/t/how-to-properly-use-mappings/55422/2 "2016-07-14T07:43:16Z")

</div>

Hi,  
under `mappings` you need to have the name of the type, then `properties` and then the actual top-level fields (e.g. `SEVERITY`).

The error mentions root mapping, meaning that it considers `SEVERITY` the name of your type, and it says that `index` and `type` are not supported properties at that level.

Have a look at an example [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html).

Cheers  
Luca

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:35pm UTC](https://discuss.elastic.co/t/how-to-properly-use-mappings/55422/3 "2017-07-05T22:35:49Z")

</div>


