# Ingest Pipeline

**URL:** <https://discuss.elastic.co/t/ingest-pipeline/271089>\
**Category:** Elasticsearch\
**Created:** [April 23, 2021, 12:34pm UTC](https://discuss.elastic.co/t/ingest-pipeline/271089 "2021-04-23T12:34:52Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![spike83](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spike83/32/47036_2.png) [@spike83](https://discuss.elastic.co/u/spike83)\
**Post date:** [April 23, 2021, 12:34pm UTC](https://discuss.elastic.co/t/ingest-pipeline/271089/1 "2021-04-23T12:34:52Z")

</div>

Hi,

I have am ingest pipeline that set within Elasticsearch ingest node, that takes the message field from a log file and splits it out.

During this I pull out the date which looks fine when it hits the document, but the index pattern is setting it as a string and not a date. is the a way I can get it to set as a date?

```auto
[
  {
    "grok": {
      "field": "message",
      "patterns": [
        "%{YUMTIMESTAMP:yum.date} %{NOTSPACE:yum.state} %{NOTSPACE:yum.package}"
      ],
      "pattern_definitions": {
        "YUMTIMESTAMP": "%{MONTH} +%{MONTHDAY} %{TIME}"
      },
      "description": "Yum entry"
    }
  },
  {
    "date": {
      "field": "yum.date",
      "formats": [
        "MMM dd HH:mm:ss"
      ],
      "target_field": "yum.datetime"
    }
  }
]

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 23, 2021, 12:51pm UTC](https://discuss.elastic.co/t/ingest-pipeline/271089/2 "2021-04-23T12:51:43Z")

</div>

You need to define the mapping for your index and set the field as a date field.

---

<div class="post-metadata">

**Author:** ![spike83](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spike83/32/47036_2.png) [@spike83](https://discuss.elastic.co/u/spike83)\
**Post date:** [April 23, 2021, 1:06pm UTC](https://discuss.elastic.co/t/ingest-pipeline/271089/3 "2021-04-23T13:06:12Z")

</div>

Thank you for coming back to me.

I haven't carried out a mapping before, where is this setup?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 23, 2021, 1:37pm UTC](https://discuss.elastic.co/t/ingest-pipeline/271089/4 "2021-04-23T13:37:36Z")

</div>

> **[Explicit mapping | Elasticsearch Guide \[7.12\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/explicit-mapping.html)**

And

> **[Date field type | Elasticsearch Guide \[7.12\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/date.html)**

You can GET your current mapping using

`GET /yourindexname`

And the adjust from there.

---

<div class="post-metadata">

**Author:** ![spike83](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spike83/32/47036_2.png) [@spike83](https://discuss.elastic.co/u/spike83)\
**Post date:** [April 23, 2021, 1:39pm UTC](https://discuss.elastic.co/t/ingest-pipeline/271089/5 "2021-04-23T13:39:27Z")

</div>

Thanks @stephenb - As im pulling the data in through filebeat, wil i need to update the mapping on every new index created for each release e.g. filebeat-7.11 then filebeat-7.12?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 23, 2021, 1:42pm UTC](https://discuss.elastic.co/t/ingest-pipeline/271089/6 "2021-04-23T13:42:42Z")

</div>

No you will use an [index template](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-templates.html) 🙂 that matches the pattern of indices like

`my-filebeat-*`

Think of a template as a mapping (and settings) that get applied to any index name that matches a pattern

---

<div class="post-metadata">

**Author:** ![spike83](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spike83/32/47036_2.png) [@spike83](https://discuss.elastic.co/u/spike83)\
**Post date:** [April 23, 2021, 2:25pm UTC](https://discuss.elastic.co/t/ingest-pipeline/271089/7 "2021-04-23T14:25:37Z")

</div>

Thanks. Had to wing it a little but got it working with your help 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2021, 2:26pm UTC](https://discuss.elastic.co/t/ingest-pipeline/271089/8 "2021-05-21T14:26:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
