Index mappings for elastic security

Long story short im working on a custom project that uses a graylog front end, and im trying to figure out how to either have elastic security read the existing indexes graylog has written, or to have graylog write them in a different format.

I do not currently have an operations ES server handy so if nothing else could someone post the mapping for the indexes that it does read from?

Ive been told this is possible but there isnt anything readily available on the how.
any help appreciated.

