# Index template mapping type

**URL:** <https://discuss.elastic.co/t/index-template-mapping-type/59955>\
**Category:** Elasticsearch\
**Created:** [September 7, 2016, 9:22am UTC](https://discuss.elastic.co/t/index-template-mapping-type/59955 "2016-09-07T09:22:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![eirc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eirc/32/11769_2.png) [@eirc](https://discuss.elastic.co/u/eirc)\
**Post date:** [September 7, 2016, 9:22am UTC](https://discuss.elastic.co/t/index-template-mapping-type/59955/1 "2016-09-07T09:22:58Z")

</div>

So I've made an index template to set up mappings for some nginx access logs I've put in Elasticsearch with Filebeat & Logstash. Because I have various nginx access log formats I set for each format a different `document_type` with Filebeat & according to that I use different grok patterns to extract fields from the logs. So on Elasticsearch logs arrive with type `nginx_access_main` or `nginx_access_api`. In the index template mapping though I've used an arbitrary `nginx_access` type.

I'm trying to understand why that works. Is it because it's a substring of the actual types or is it because [fields are shared across mapping types](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html#field-conflicts)? If it's the latter what's the point of using the type in the mapping since no matter what it'll work for all types?

I'm also trying to actually change the document type with Logstash but by mutate replacing `type` I only update the `type` field whereas the `_type` field remains the same. Is there any way to change that? In this [year old discussion](https://discuss.elastic.co/t/how-to-conditionally-set-the-type/32862) it seems mutating `type` had worked for them.

Thanks

---

<div class="post-metadata">

**Author:** ![eirc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eirc/32/11769_2.png) [@eirc](https://discuss.elastic.co/u/eirc)\
**Post date:** [September 7, 2016, 9:51am UTC](https://discuss.elastic.co/t/index-template-mapping-type/59955/2 "2016-09-07T09:51:01Z")

</div>

Ok so about the second part I got my answer, I have to mutate both the `type` and the `[@metadata][type]` fields.

```
mutate {
  replace => { "[@metadata][type]" => "nginx_access" }
  replace => { "type" => "nginx_access" }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:22pm UTC](https://discuss.elastic.co/t/index-template-mapping-type/59955/3 "2017-07-05T22:22:05Z")

</div>


