# Incorrect mapping not matching grok filers and fields .conf file

**URL:** <https://discuss.elastic.co/t/incorrect-mapping-not-matching-grok-filers-and-fields-conf-file/186288>\
**Category:** Logstash\
**Created:** [June 18, 2019, 2:48pm UTC](https://discuss.elastic.co/t/incorrect-mapping-not-matching-grok-filers-and-fields-conf-file/186288 "2019-06-18T14:48:10Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![asad\_ali](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asad_ali/32/47894_2.png) [@asad\_ali](https://discuss.elastic.co/u/asad_ali)\
**Post date:** [June 18, 2019, 6:28pm UTC](https://discuss.elastic.co/t/incorrect-mapping-not-matching-grok-filers-and-fields-conf-file/186288/5 "2019-06-18T18:28:30Z")

</div>

I tried to remove the host.metadata not extra fields are dropped down to 34 from 51. I opened new link here

> [@Incorrect mapping of fields by Kibanna send from logstash](https://discuss.elastic.co/t/incorrect-mapping-of-fields-by-kibanna-send-to-logstash/186336):
>
> Problem I have very simple log file for testing purposes. Below as:- 2008-09-15T11:30:00Z sarah 2008-09-15T12:18:00Z jessica 2008-09-15T13:20:00Z parker lee On testing stdout of logstash is { "type" =\> "log", "input" =\> { "type" =\> "log" }, "tags" =\> [[0] "beats\_input\_codec\_plain\_applied" ], "@timestamp" =\> 2008-09-15T11:30:00.000Z, "ecs" =\> { "version" =\> "1.0.0" }, "host" =\> { "name" =\> "elk" }, "agent" =\> { "ephemeral\_id" =\> "de724cef-e507-4b82-909d-700ab2f14f0c", "…

---

_[View the full topic](https://discuss.elastic.co/t/incorrect-mapping-not-matching-grok-filers-and-fields-conf-file/186288)._
