# Logstash keep creating field despite the dynamic\_mapping being deactivated

**URL:** <https://discuss.elastic.co/t/logstash-keep-creating-field-despite-the-dynamic-mapping-being-deactivated/99391>\
**Category:** Logstash\
**Created:** [September 5, 2017, 9:08am UTC](https://discuss.elastic.co/t/logstash-keep-creating-field-despite-the-dynamic-mapping-being-deactivated/99391 "2017-09-05T09:08:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Melvyn\_Peignon](https://avatars.discourse-cdn.com/v4/letter/m/a88e57/32.png) [@Melvyn\_Peignon](https://discuss.elastic.co/u/Melvyn_Peignon)\
**Post date:** [September 5, 2017, 9:08am UTC](https://discuss.elastic.co/t/logstash-keep-creating-field-despite-the-dynamic-mapping-being-deactivated/99391/1 "2017-09-05T09:08:44Z")

</div>

I have defined my own template to be used by logstash where I have deactivate the dynamic mapping:

```
{
	"my_index": {
		"order": 0,
		"template": "my_index",
		"settings": {
			"index": {
				"mapper": {
					"dynamic": "false"
				},
				"analysis": {
					"analyzer": {
						"nlp_analyzer": {
							"filter": [
								"lowercase"
							],
							"type": "custom",
							"tokenizer": "nlp_tokenizer"
						}
					},
					"tokenizer": {
						"nlp_tokenizer": {
							"pattern": ""
							"(\w+)|(\s*[\s+])"
							"",
							"type": "pattern"
						}
					}
				},
				"number_of_shards": "1",
				"number_of_replicas": "0"
			}
		},
		"mappings": {
			"author": {
				"properties": {
					"author_name": {
						"type": "keyword"
					},
					"author_pseudo": {
						"type": "keyword"
					},
					"author_location": {
						"type": "text",
						"fields": {
							"standard": {
								"analyzer": "standard",
								"term_vector": "yes",
								"type": "text"
							},
							"nlp": {
								"analyzer": "nlp_analyzer",
								"term_vector": "yes",
								"type": "text"
							}
						}
					}
				}
			}
		}
	}
}

```

To test if elasticsearch won't generate new field I try to let a field in my events that is not present in my mapping, let's say that I have this event:

{  
"type" =\> "author",  
"author\_pseudo" =\> "chloemdelorenzo",  
"author\_name" =\> "Chloe DeLorenzo",  
"author\_location" =\> "US",  
}

Elasticsearch will generate a new fielding the mapping when indexing this event:

```
"type": {
     "type": "text",
      "fields": {
           "keyword": {
                "type": "keyword",
                "ignore_above": 256
           }
      }
 }

```

I know that Logstash is using my template because in my mapping I use a custom analyser and I can find it back into the mapping generated. But apparently it doesn't take into consideration that the dynamic field is disabled.

I want elastic search to ignore fields that are not present in my mapping but to index the field that have a defined mapping. How can I avoid logstash to create new field?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 7, 2017, 5:30am UTC](https://discuss.elastic.co/t/logstash-keep-creating-field-despite-the-dynamic-mapping-being-deactivated/99391/2 "2017-09-07T05:30:52Z")

</div>

Have you checked the actual mappings of the index, thereby verifying that your template has been correctly applied?

---

<div class="post-metadata">

**Author:** ![Melvyn\_Peignon](https://avatars.discourse-cdn.com/v4/letter/m/a88e57/32.png) [@Melvyn\_Peignon](https://discuss.elastic.co/u/Melvyn_Peignon)\
**Post date:** [September 7, 2017, 5:46am UTC](https://discuss.elastic.co/t/logstash-keep-creating-field-despite-the-dynamic-mapping-being-deactivated/99391/3 "2017-09-07T05:46:03Z")

</div>

Thanks! I have found my error:

I had to enforce the mapping at the document type level in the documentation they state this:

> **[Dynamic mapping | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-mapping.html)**

> Regardless of the value of this setting, types can still be added explicitly when creating an index or with the PUT mapping API.

So my question now is what is the purpose of :

```
 "mapper": {
	   "dynamic": "false"
 }

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 7, 2017, 5:55am UTC](https://discuss.elastic.co/t/logstash-keep-creating-field-despite-the-dynamic-mapping-being-deactivated/99391/4 "2017-09-07T05:55:50Z")

</div>

Sorry, I don't understand the question.

---

<div class="post-metadata">

**Author:** ![Melvyn\_Peignon](https://avatars.discourse-cdn.com/v4/letter/m/a88e57/32.png) [@Melvyn\_Peignon](https://discuss.elastic.co/u/Melvyn_Peignon)\
**Post date:** [September 7, 2017, 6:16am UTC](https://discuss.elastic.co/t/logstash-keep-creating-field-despite-the-dynamic-mapping-being-deactivated/99391/5 "2017-09-07T06:16:55Z")

</div>

Sorry, let me reformulate:

Apparently this settings doesn't deactivate the dynamic mapping:

```
"settings": {
			"index": {
				"mapper": {
					"dynamic": "false"
				},
                ....

```

But this does:

```
"mappings": {
    "author": {
        "dynamic": false,
        "properties": {
        ...

```

My question is why the first setting have no impact on the dynamic mapping? And what is it used for?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 7, 2017, 6:27am UTC](https://discuss.elastic.co/t/logstash-keep-creating-field-despite-the-dynamic-mapping-being-deactivated/99391/6 "2017-09-07T06:27:48Z")

</div>

That setting is used to [disable dynamic type creation](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-mapping.html#_disabling_automatic_type_creation).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 5, 2017, 6:28am UTC](https://discuss.elastic.co/t/logstash-keep-creating-field-despite-the-dynamic-mapping-being-deactivated/99391/7 "2017-10-05T06:28:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
