# Index ignoring template

**URL:** <https://discuss.elastic.co/t/index-ignoring-template/112292>\
**Category:** Elasticsearch\
**Created:** [December 18, 2017, 6:23pm UTC](https://discuss.elastic.co/t/index-ignoring-template/112292 "2017-12-18T18:23:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![turnlikeawheel](https://avatars.discourse-cdn.com/v4/letter/t/e274bd/32.png) [@turnlikeawheel](https://discuss.elastic.co/u/turnlikeawheel)\
**Post date:** [December 18, 2017, 6:23pm UTC](https://discuss.elastic.co/t/index-ignoring-template/112292/1 "2017-12-18T18:23:53Z")

</div>

Disclaimer: I'm a bit new to ES/Filebeat so I may be misunderstanding something.

The problem is that ES is indexing the Filebeat field "beat.hostname" as text rather than keyword on seemingly random days when the daily index is created. The problem I'm having with this is that I have some visualizations that aggregate this field. When I load them now, I'm getting the "Courier Fetch: x of x shards failed" error because it can't aggregate the field from those indices.

The template for Filebeat 6.1.0 seems to be correct and 95% of my indices are fine.

The relevant template sections:

"filebeat-6.1.0": {  
"order": 1,  
"index\_patterns": [  
"filebeat-6.1.0-_"  
],  
"settings": {  
"index": {  
"mapping": {  
"total\_fields": {  
"limit": "10000"  
}  
},  
"refresh\_interval": "5s",  
"number\_of\_routing\_shards": "30",  
"number\_of\_shards": "2"  
}  
},  
"mappings": {  
"doc": {  
"\_meta": {  
"version": "6.1.0"  
},  
"date\_detection": false,  
"dynamic\_templates": [  
{  
"fields": {  
"mapping": {  
"type": "keyword"  
},  
"match\_mapping\_type": "string",  
"path\_match": "fields._"  
}  
},

.....

```
     "beat": {
        "properties": {
          "version": {
            "ignore_above": 1024,
            "type": "keyword"
          },
          "name": {
            "type": "keyword",
            "ignore_above": 1024
          },
          "hostname": {
            "type": "keyword",
            "ignore_above": 1024
          },
          "timezone": {
            "type": "keyword",
            "ignore_above": 1024
          }
        }
      },

```

But the mapping for that day shows:

"filebeat-6.1.0-2017.12.16": {  
"mappings": {  
"doc": {  
"properties": {  
"@timestamp": {  
"type": "date"  
},  
"beat": {  
"properties": {  
"hostname": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"name": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"version": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
}

I'm pretty sure I'm missing something, but if someone could point me in the right direction, that would be fantastic.

Thanks!

---

<div class="post-metadata">

**Author:** ![luiz.santos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luiz.santos/32/24664_2.png) [@luiz.santos](https://discuss.elastic.co/u/luiz.santos)\
**Post date:** [December 22, 2017, 3:44pm UTC](https://discuss.elastic.co/t/index-ignoring-template/112292/2 "2017-12-22T15:44:47Z")

</div>

Hi @turnlikeawheel,

It happens that elasticsearch creates by default the mapping for type text and keyword for the same field.

```
{
	"beat": {
		"properties": {
			"hostname": {
				"type": "text",
				"fields": {
					"keyword": {
						"type": "keyword",
						"ignore_above": 256
					}
				}
			}
		}
	}
}

```

To use the keyword field you should do "hostname.keyword".

Hope it helps.

Cheers,  
LG

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2018, 3:45pm UTC](https://discuss.elastic.co/t/index-ignoring-template/112292/3 "2018-01-19T15:45:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
