# JSON string Mapping in elasticsearch

**URL:** <https://discuss.elastic.co/t/json-string-mapping-in-elasticsearch/18043>\
**Category:** Elasticsearch\
**Created:** [June 11, 2014, 12:33pm UTC](https://discuss.elastic.co/t/json-string-mapping-in-elasticsearch/18043 "2014-06-11T12:33:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rahul\_Nehra](https://avatars.discourse-cdn.com/v4/letter/r/b5a626/32.png) [@Rahul\_Nehra](https://discuss.elastic.co/u/Rahul_Nehra)\
**Post date:** [June 11, 2014, 12:33pm UTC](https://discuss.elastic.co/t/json-string-mapping-in-elasticsearch/18043/1 "2014-06-11T12:33:41Z")

</div>

Hi

We are in development phase and using one master and two data node  
setup.

I am using elasticserch to save application log in JSON format.

So that we could easily create mapping on all josn filed .

_Our Log format is very simple JSON string ._

_{_  
_"timestamp" :"",_  
_"application" :"",_  
_"severity" :"",_  
_"clientip" :"",_  
_"server" :"",_  
_"exception" :""_

_}_

Now When I am sending log logstash to Elasticserch then log is being  
saved and displaying under @message column on Kibana and \_plugin Head as a  
JSON string

Now I want to create mapping on three fields (_timestamp_,_application_  
and _severity_ ) form JSON string to create schema and make these filed  
searchable.

To create mapping i run the below curl command

curl -XPUT [http://localhost:9200/\_template/logstash\_per\_index](http://localhost:9200/_template/logstash_per_index) -d '{  
"template" :"logstash\*",  
"settings" : {

```
   "index.cache.field.type" :"soft",
   "index.store.compress.stored" : true,
   "index.query.default_field" :"@message"
 
},

```

"mappings" : {  
"_default_" : {  
"\_all" : {"enabled" : false},  
"properties" : {  
"@message" : {

```
              "properties" : {
           * "timestamp" : {"type":"date"},*

```

- 

```
                  "application" : {"type":"string"},*

```

- 

```
                  "severity" : {"type":"string"}*
              

             }
        },
       "@source": {"type":"string","index":"not_analyzed" },
       "@source_host": {"type":"string","index":"not_analyzed" },
       "@source_path": {"type":"string","index":"not_analyzed" },
       "@tags": {"type":"string","index":"not_analyzed" },
       "@timestamp": {"type":"date","index":"not_analyzed" },
        "@type": {"type":"string","index":"not_analyzed" }    
     }   
  }

```

}  
}  
'

But after run these command these filed are not searchable yet (i.e Not  
comming as separate column ).

[image: Inline image 1]

We are not not able figure out what is the wrong with this mapping.

Kindly suggest .

Regards  
Rahul

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/ea36a487-7bd5-4b4e-9973-bf048c95713e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ea36a487-7bd5-4b4e-9973-bf048c95713e%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:23am UTC](https://discuss.elastic.co/t/json-string-mapping-in-elasticsearch/18043/2 "2017-07-06T01:23:17Z")

</div>


