# Mapping explosion vs. the filebeat template

**URL:** https://discuss.elastic.co/t/mapping-explosion-vs-the-filebeat-template/295886
**Category:** Elasticsearch
**Created:** [January 31, 2022, 10:49pm UTC](https://discuss.elastic.co/t/mapping-explosion-vs-the-filebeat-template/295886 "2022-01-31T22:49:10Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)
#### Post date: [January 31, 2022, 10:49pm UTC](https://discuss.elastic.co/t/mapping-explosion-vs-the-filebeat-template/295886/1 "2022-01-31T22:49:10Z")

</div>

I'm struggling trying to figure out how to convert from the way we used legacy templates to the new index and component templates. I used to add our own templates with higher priority on top of the supplied filebeat template.

Then I read about mapping explosion and that the default limit for index fields is 1000. The filebeat template I just loaded for 7.16.2 for the Elasticsearch and logstash module results in an index with over 6500 fields.

If component templates are the wave of the future, could Elastic break the supplied filebeat template into components for mapping group, like activemq, agent, apache, auditd, aws-cloudwatch, aws-cloudtrail and so on. Then we could include the parts we want with our indices and reduce the excessive field count?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 28, 2022, 10:49pm UTC](https://discuss.elastic.co/t/mapping-explosion-vs-the-filebeat-template/295886/2 "2022-02-28T22:49:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
