# How to write mapping for extra fields of Logstash

**URL:** <https://discuss.elastic.co/t/how-to-write-mapping-for-extra-fields-of-logstash/13479>\
**Category:** Elasticsearch\
**Created:** [September 5, 2013, 4:16pm UTC](https://discuss.elastic.co/t/how-to-write-mapping-for-extra-fields-of-logstash/13479 "2013-09-05T16:16:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![subin](https://avatars.discourse-cdn.com/v4/letter/s/58956e/32.png) [@subin](https://discuss.elastic.co/u/subin)\
**Post date:** [September 5, 2013, 4:16pm UTC](https://discuss.elastic.co/t/how-to-write-mapping-for-extra-fields-of-logstash/13479/1 "2013-09-05T16:16:26Z")

</div>

hello,

sorry, I did ask this before (in Logstash's group) but I lost it from my  
emails and can't seem to find out from public archives. It's more  
ES-centered though.

When we add custom fields to parse our logs, logstash appends the string  
'@fields' to those new fields and will have an output as below:

{"@source":"file://loghost/logs/remote/mail/mail.log","@tags":["mx-mail","mx-mail3"],"@fields":{"date":["Aug  
5  
00:24:10"],"host":["mx-mail3"],"service":["postfix/smtpd[11985]"],"program":["postfix/smtpd"],"pid":["11985"],"message":["connect  
from  
unknown[113.160.101.48]"]},"@timestamp":"2013-08-05T00:24:10-04:00","@source\_path":"/logs/remote/mail/mail.log","@source\_host":"loghost","@message":"connect  
from unknown[10.0.4.27]","@type":"postfix"}

In order to map the @fields.date, @fields.host etc, I've created a mapping  
as in the below link:

> <https://gist.github.com/osssubb/6183360>

Could you please verify if it's correct?

Thanks,

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:17am UTC](https://discuss.elastic.co/t/how-to-write-mapping-for-extra-fields-of-logstash/13479/2 "2017-07-06T02:17:59Z")

</div>


