# Indexing on customized fields

**URL:** <https://discuss.elastic.co/t/indexing-on-customized-fields/16002>\
**Category:** Elasticsearch\
**Created:** [February 25, 2014, 7:14am UTC](https://discuss.elastic.co/t/indexing-on-customized-fields/16002 "2014-02-25T07:14:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![san](https://avatars.discourse-cdn.com/v4/letter/s/ba9def/32.png) [@san](https://discuss.elastic.co/u/san)\
**Post date:** [February 25, 2014, 7:14am UTC](https://discuss.elastic.co/t/indexing-on-customized-fields/16002/1 "2014-02-25T07:14:41Z")

</div>

Snippet  
from [http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/mapping.html](http://www.elasticsearch.org/guide/en/elasticsearch/reference/current/mapping.html)

"Explicit mapping is defined on an index/type level. By default, there  
isn’t a need to define an explicit mapping, since one is automatically  
created and registered when a new type or new field is introduced (with no  
performance overhead) and have sensible defaults."

Following is the json format of the log Logstash is generating:

{  
"message" =\> "\<6\> Jan 9 07:19:26 w2k8r233110  
0|TEST|TESTPRODUCT|8.0.1310|TestSignature|This is test  
message|Medium|src=10.31.252.102",  
"@version" =\> "1",  
"@timestamp" =\> "2014-02-25T06:52:52.930Z",  
"type" =\> "syslog",  
"host" =\> [  
[0] "127.0.0.1:38989",  
[1] "w2k8r233110"  
],  
"syslog\_pri" =\> "6",  
"timestamp" =\> "Jan 9 07:19:26",  
"cef\_version" =\> "0",  
"device\_vendor" =\> "TEST",  
"device\_product" =\> "TESTPRODUCT",  
"device\_version" =\> "8.0.1310",  
"signature\_id" =\> "TestSignature",  
"message\_content" =\> "This is test message",  
"severity" =\> "Medium",  
"src\_ip" =\> "10.31.252.102"  
}

But i can't see the fields in Elasticsearch Kibana interface. Could anyone  
please help me out?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/6438c2fa-aacb-45cf-a19b-196c6aea6c3a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/6438c2fa-aacb-45cf-a19b-196c6aea6c3a%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Binh\_Ly](https://avatars.discourse-cdn.com/v4/letter/b/ce7236/32.png) [@Binh\_Ly](https://discuss.elastic.co/u/Binh_Ly)\
**Post date:** [February 25, 2014, 2:42pm UTC](https://discuss.elastic.co/t/indexing-on-customized-fields/16002/2 "2014-02-25T14:42:19Z")

</div>

By any chance, are you able to query this document directly from ES, like  
for example:

\_search  
{  
"query": {  
"match": {  
"device\_vendor": "TEST"  
}  
}  
}

I'd be interested to see the actual JSON document from ES.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e9ff523e-59aa-44ed-80a1-44c81766f5e2%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e9ff523e-59aa-44ed-80a1-44c81766f5e2%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:47am UTC](https://discuss.elastic.co/t/indexing-on-customized-fields/16002/3 "2017-07-06T01:47:23Z")

</div>


