# Mapping directly in Logstash Pipeline

**URL:** <https://discuss.elastic.co/t/mapping-directly-in-logstash-pipeline/327757>\
**Category:** Logstash\
**Created:** [March 15, 2023, 1:27pm UTC](https://discuss.elastic.co/t/mapping-directly-in-logstash-pipeline/327757 "2023-03-15T13:27:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_Thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_thomas/32/82551_2.png) [@\_Thomas](https://discuss.elastic.co/u/_Thomas)\
**Post date:** [March 15, 2023, 1:27pm UTC](https://discuss.elastic.co/t/mapping-directly-in-logstash-pipeline/327757/1 "2023-03-15T13:27:02Z")

</div>

Hi Guys,  
since I didn't find anything helpful on the net - I need to ask here:  
Is it possible to do the Mapping of fields directly in the Logstash Pipeline - either in the Input or in the Filter section?  
As I do have a couple fields to populate, I want to make sure they're correctly mapped.

I'm looking to achieve something like that:

```auto
input {
  syslog {
    port => 1514
  }
}
filter {
   mappings => {
        "MWG_ClientIP" => "ip"
        "MWG_RequestMethod" => "text"
        "MWG_BytesFromServer" => "long"
        "MWG_BytesFromClient" => "long"
        "MWG_URL" => "wildcard"
}
ouput {}

```

This is just a sample of what I'm trying to achieve, and I also removed a couple things, which aren't really that important for that question.

If I cannot do the Mapping directly in one step while processing the Data, I guess the only other two Options I have left are:  
-) Create the Mapping within the DevTools before creating the Index itself  
or  
-) create an Index Template and do the mapping there, right?

Any help/input is highly appreciated.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 15, 2023, 1:48pm UTC](https://discuss.elastic.co/t/mapping-directly-in-logstash-pipeline/327757/2 "2023-03-15T13:48:36Z")

</div>

> [@\_Thomas](#):
>
> Is it possible to do the Mapping of fields directly in the Logstash Pipeline - either in the Input or in the Filter section?

No, it is not possible.

> [@\_Thomas](#):
>
> If I cannot do the Mapping directly in one step while processing the Data, I guess the only other two Options I have left are:  
> -) Create the Mapping within the DevTools before creating the Index itself  
> or  
> -) create an Index Template and do the mapping there, right?

I would say that the best approach is to create an index template with your mappings.

---

<div class="post-metadata">

**Author:** ![\_Thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_thomas/32/82551_2.png) [@\_Thomas](https://discuss.elastic.co/u/_Thomas)\
**Post date:** [March 15, 2023, 1:49pm UTC](https://discuss.elastic.co/t/mapping-directly-in-logstash-pipeline/327757/3 "2023-03-15T13:49:24Z")

</div>

Alright - thank you very much. That's what I thought.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2023, 1:49pm UTC](https://discuss.elastic.co/t/mapping-directly-in-logstash-pipeline/327757/4 "2023-04-12T13:49:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
