# Kafka input - Type missing

**URL:** <https://discuss.elastic.co/t/kafka-input-type-missing/194064>\
**Category:** Logstash\
**Created:** [August 6, 2019, 4:54pm UTC](https://discuss.elastic.co/t/kafka-input-type-missing/194064 "2019-08-06T16:54:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![asacr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asacr/32/51777_2.png) [@asacr](https://discuss.elastic.co/u/asacr)\
**Post date:** [August 6, 2019, 4:54pm UTC](https://discuss.elastic.co/t/kafka-input-type-missing/194064/1 "2019-08-06T16:54:28Z")

</div>

Hello,

We've got an existing ELK environment using filebeat primarily. Everything is working fine there, but I'm trying to add some data using the Kafka input plugin and running into an issue.

Logstash Version: 5.4.0  
logstash-input-kafka Version: 5.1.11

Logstash input config is as follows:

```
input {
    kafka {
        type => "foo-type"
        bootstrap_servers => "<snip>"
        topics => ["<snip>"]
        auto_offset_reset => "latest"
        codec => "json"
        group_id => "<snip>"
        decorate_events => true
    }
}

```

Relevant output config:

```
output {
  elasticsearch {
    hosts => ["{{es_hosts}}"]
    manage_template => false
    index => "%{[@metadata][type]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

Problem: The index name and associated mapping (`foo-type`) is not being applied correctly, instead it is being named simply `%{[@metadata][type]}-2019.08.06`

Expected behavior: The index _should_ be named `foo-type-2019.08.06` and have the correct mapping applied.

Any idea what's going on here?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 6, 2019, 5:15pm UTC](https://discuss.elastic.co/t/kafka-input-type-missing/194064/2 "2019-08-06T17:15:05Z")

</div>

foo-type will be in [type], not [@metadata][type]

---

<div class="post-metadata">

**Author:** ![asacr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asacr/32/51777_2.png) [@asacr](https://discuss.elastic.co/u/asacr)\
**Post date:** [August 6, 2019, 5:26pm UTC](https://discuss.elastic.co/t/kafka-input-type-missing/194064/3 "2019-08-06T17:26:25Z")

</div>

Is that specific to the Kafka input plugin? The output config specified above (`[@metadata][type]`) is what we currently use in production for ~5 other types and it works fine.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 6, 2019, 5:37pm UTC](https://discuss.elastic.co/t/kafka-input-type-missing/194064/4 "2019-08-06T17:37:00Z")

</div>

> [@asacr](#):
>
> Is that specific to the Kafka input plugin?

No, type is one of the options common across inputs and it sets the [type] field. I think you are relying on something configured in filebeat to add a metadata field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 3, 2019, 5:37pm UTC](https://discuss.elastic.co/t/kafka-input-type-missing/194064/5 "2019-09-03T17:37:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
