# Import data from folder

**URL:** <https://discuss.elastic.co/t/import-data-from-folder/80453>\
**Category:** Elasticsearch\
**Created:** [March 29, 2017, 9:39am UTC](https://discuss.elastic.co/t/import-data-from-folder/80453 "2017-03-29T09:39:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eiriks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eiriks/32/16848_2.png) [@Eiriks](https://discuss.elastic.co/u/Eiriks)\
**Post date:** [March 29, 2017, 9:39am UTC](https://discuss.elastic.co/t/import-data-from-folder/80453/1 "2017-03-29T09:39:46Z")

</div>

Hello.  
This is my first post, and first time using elasticsearch.

I've been given an elasticsearch dump, a large tar.gz tar expands to a folder with ~50 subfolders that mostly come in pairs (e.g. one named _video_ alongside on named _video-reference_).  
Inside these again a find many more folders, importantly among them always one `_mapping` that holds a file named `null` (no suffix) that holds what I'm pretty sure is the schema (I recognise it from the [tutorial - load dataset](https://www.elastic.co/guide/en/kibana/current/tutorial-load-dataset.html)). Siblings to these \_mapping folders are many many more folder that only contain one file each, always named `_source` (no suffix again) that contain a JSON document.

I've set up elasticsearch and kibana on my local machine, and would like to explore this data I've been given.

Do you recognise the folder-structure and files mentioned above? I assume it's from some standard export tool/dump procedure/etc. I would like to import this data, any hints on where I should start?

---

<div class="post-metadata">

**Author:** ![dakrone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dakrone/32/23351_2.png) [@dakrone](https://discuss.elastic.co/u/dakrone)\
**Post date:** [March 29, 2017, 4:22pm UTC](https://discuss.elastic.co/t/import-data-from-folder/80453/2 "2017-03-29T16:22:24Z")

</div>

Could you perhaps post an example of the `_source` file and `_mapping` directories?

It sounds like you could use logstash's `file` input to read the file and send it to Elasticsearch, but I'm having difficulty following the structure and content of the files and directories.

---

<div class="post-metadata">

**Author:** ![Eiriks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eiriks/32/16848_2.png) [@Eiriks](https://discuss.elastic.co/u/Eiriks)\
**Post date:** [March 31, 2017, 7:10am UTC](https://discuss.elastic.co/t/import-data-from-folder/80453/3 "2017-03-31T07:10:00Z")

</div>

Ok.  
Here's an example of a `_source` file.

```
{"remoteId":"367783173981106176","uRL":"https://twitter.com/ingunnsolheim/statuses/367783173981106176","metadata":{"versionId":"1.11182854.1376523439","state":"PUBLISHED","publicState":"PUBLISHED","versionPublished":"2013-08-15T01:37:20+02:00","modifier":"18.13156","publicVersionId":"1.11182854.1376523439","owner":"18.13156","_type":"Metadata"},"version":1376523439,"title":"https://twitter.com/ingunnsolheim/statuses/367783173981106176","modified":"2013-08-15T01:37:20+02:00","id":"1.11182854","published":"2013-08-15T01:37:20+02:00","_type":"Tweet"}

```

The file I assume is the corresponding schema file looks like this (file named `null`):

```
{"tweet":{"dynamic_templates":[{"long_text_strings":{"mapping":{"index":"analyzed","similarity":"default","analyzer":"norwegian","type":"string"},"match":"abstract|body|instructions|text|data","match_mapping_type":"string","match_pattern":"regex"}},{"short_text_strings":{"mapping":{"index":"analyzed","similarity":"BM25","analyzer":"norwegian","type":"string"},"match":".*title|.*Title|tittel|beskrivelse|caption|description|flip|footer|information|intro|lead|usage|searchWords","match_mapping_type":"string","match_pattern":"regex"}},{"other_strings":{"mapping":{"index":"not_analyzed","type":"string"},"match":"*","match_mapping_type":"string"}}],"_timestamp":{"enabled":true,"store":true},"properties":{"_type":{"type":"string","index":"not_analyzed"},"id":{"type":"string","index":"not_analyzed"},"indexedAt":{"type":"date","format":"dateOptionalTime"},"metadata":{"properties":{"_type":{"type":"string","index":"not_analyzed"},"firstVersionId":{"type":"string","index":"not_analyzed"},"id":{"type":"string","index":"not_analyzed"},"modelType":{"type":"string","index":"not_analyzed"},"modifier":{"type":"string","index":"not_analyzed"},"owner":{"type":"string","index":"not_analyzed"},"previousVersionId":{"type":"string","index":"not_analyzed"},"publicState":{"type":"string","index":"not_analyzed"},"publicVersionId":{"type":"string","index":"not_analyzed"},"state":{"type":"string","index":"not_analyzed"},"version":{"properties":{"_type":{"type":"string","index":"not_analyzed"},"created":{"type":"date","format":"dateOptionalTime"},"id":{"type":"string","index":"not_analyzed"},"modelType":{"type":"string","index":"not_analyzed"},"published":{"type":"date","format":"dateOptionalTime"},"version":{"type":"long"}}},"versionId":{"type":"string","index":"not_analyzed"},"versionPublished":{"type":"date","format":"dateOptionalTime"},"versions":{"properties":{"_type":{"type":"string","index":"not_analyzed"},"created":{"type":"date","format":"dateOptionalTime"},"id":{"type":"string","index":"not_analyzed"},"updated":{"type":"date","format":"dateOptionalTime"},"version":{"type":"long"}}}}},"modelType":{"type":"string","index":"not_analyzed"},"modified":{"type":"date","format":"dateOptionalTime"},"plug":{"properties":{"_type":{"type":"string","index":"not_analyzed"},"modelType":{"type":"string","index":"not_analyzed"}}},"published":{"type":"date","format":"dateOptionalTime"},"remoteId":{"type":"string","index":"not_analyzed"},"title":{"type":"string","analyzer":"norwegian","similarity":"BM25"},"uRL":{"type":"string","index":"not_analyzed"},"updated":{"type":"date","format":"dateOptionalTime"},"version":{"type":"long"}}}}

```

The folder structure then looks like this:

![](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6f498eda54a2c7712bb291970568c1733489546b.png)

Does this still sound like a job for "logstash's file input"? Can you point me towards some material on this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2017, 7:10am UTC](https://discuss.elastic.co/t/import-data-from-folder/80453/4 "2017-04-28T07:10:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
