# Integration field map error, how to fix temporarily

**URL:** <https://discuss.elastic.co/t/integration-field-map-error-how-to-fix-temporarily/368807>\
**Category:** Kibana\
**Created:** [October 14, 2024, 9:51pm UTC](https://discuss.elastic.co/t/integration-field-map-error-how-to-fix-temporarily/368807 "2024-10-14T21:51:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [October 14, 2024, 9:51pm UTC](https://discuss.elastic.co/t/integration-field-map-error-how-to-fix-temporarily/368807/1 "2024-10-14T21:51:48Z")

</div>

In the Microsoft Exchange integration, message tracking, field relatedrecipeinetaddress is mapped as an IP, but it is really an email address. I've reported a bug, but until it's fixed, what is the best way to fix this?

I can just change the field in the component template logs-microsoft\_exchange\_server.messagetracking@package, but that I wonder if there is a method to add custom mappings? If I change this template, will it get over written at update? If I change the mapping, will it cause a mapping conflict in Kibana? Another option would be to add a .text and maybe also a .keyword field.

Just trying to avoid the typical elastic learning by painful choices path 🙂  
Thanks.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 15, 2024, 1:37am UTC](https://discuss.elastic.co/t/integration-field-map-error-how-to-fix-temporarily/368807/2 "2024-10-15T01:37:26Z")

</div>

@rugenl

You can use the `@custom` component template

> **[Data streams | Fleet and Elastic Agent Guide \[8.15\] | Elastic](https://www.elastic.co/guide/en/fleet/current/data-streams.html#_edit_the_elasticsearch_index_template)**

Should be

`logs-microsoft_exchange_server.messagetracking@custom`

Although as the note says it is really recommended to change mappings but in this case I would try

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [October 16, 2024, 2:31pm UTC](https://discuss.elastic.co/t/integration-field-map-error-how-to-fix-temporarily/368807/3 "2024-10-16T14:31:47Z")

</div>

It doesn't look like the exchange\_server integration created any @custom component templates.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 16, 2024, 3:53pm UTC](https://discuss.elastic.co/t/integration-field-map-error-how-to-fix-temporarily/368807/4 "2024-10-16T15:53:21Z")

</div>

Hi @rugenl

You have to create it...

If you look in the top template you should see it included but you have to create it... then it will be included

`logs-microsoft_exchange_server.messagetracking@custom`

 ![Screenshot 2024-10-16 at 8.52.26 AM](https://us1.discourse-cdn.com/elastic/original/3X/2/b/2be6102862aa325472839e24f902290f984bc6ad.png)
