# List all fields in Data stream

**URL:** <https://discuss.elastic.co/t/list-all-fields-in-data-stream/357914>\
**Category:** Elastic Search\
**Tags:** datastreams\
**Created:** [April 22, 2024, 1:48pm UTC](https://discuss.elastic.co/t/list-all-fields-in-data-stream/357914 "2024-04-22T13:48:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![FaisalParkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faisalparkar/32/131022_2.png) [@FaisalParkar](https://discuss.elastic.co/u/FaisalParkar)\
**Post date:** [April 22, 2024, 1:48pm UTC](https://discuss.elastic.co/t/list-all-fields-in-data-stream/357914/1 "2024-04-22T13:48:19Z")

</div>

Hello Everyone,

I need some help, I am using a datastream for storing data from a firewall. I wanted to see which fields were created as part of the data ingested from my Logstash input. So I can then create a component template which defines the correct field types.

Is someone able to guide me on how I can view the fields in the datastream called logs-vendor-firewall, which has a hidden index of .ds-logs-vendor-firewall-2024.03.24-000001.

Many thanks in advance.

---

<div class="post-metadata">

**Author:** ![mvg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mvg/32/98890_2.png) [@mvg](https://discuss.elastic.co/u/mvg)\
**Post date:** [April 22, 2024, 2:20pm UTC](https://discuss.elastic.co/t/list-all-fields-in-data-stream/357914/2 "2024-04-22T14:20:17Z")

</div>

Either the field caps api (`GET logs-vendor-firewall/_field_caps?field=*`) or field mapping api (`GET logs-vendor-firewall/_mapping/field/*`)should be able to help you here.

---

<div class="post-metadata">

**Author:** ![FaisalParkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faisalparkar/32/131022_2.png) [@FaisalParkar](https://discuss.elastic.co/u/FaisalParkar)\
**Post date:** [April 22, 2024, 3:38pm UTC](https://discuss.elastic.co/t/list-all-fields-in-data-stream/357914/3 "2024-04-22T15:38:08Z")

</div>

Hey Martijn,

Many thanks for this. The second API call has worked for me.

GET logs-vendor-firewall/\_mapping/field/\*

Now I can use this to create a component template for this particular firewall device.

Thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2024, 3:38pm UTC](https://discuss.elastic.co/t/list-all-fields-in-data-stream/357914/4 "2024-05-20T15:38:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
