# Mapping for Elasticsearch \[easy\]

**URL:** <https://discuss.elastic.co/t/mapping-for-elasticsearch-easy/212036>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 16, 2019, 4:41pm UTC](https://discuss.elastic.co/t/mapping-for-elasticsearch-easy/212036 "2019-12-16T16:41:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kevin\_Csuka](https://avatars.discourse-cdn.com/v4/letter/k/7feea3/32.png) [@Kevin\_Csuka](https://discuss.elastic.co/u/Kevin_Csuka)\
**Post date:** [December 16, 2019, 4:41pm UTC](https://discuss.elastic.co/t/mapping-for-elasticsearch-easy/212036/1 "2019-12-16T16:41:04Z")

</div>

I've got an easy question.

I've got this file:

```
# epoch, metric1, metric2, metric3
1576425930,0.0718,0.0127,1

```

How can I tell Filebeat to send it to Elasticsearch and use the correct mapping.  
My config file currently looks like this:

```
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /tmp/file.csv
filebeat.config.modules:
  path: ${path.config}/modules.d/*.yml
  reload.enabled: false
  reload.period: 10s
setup.template.name: "test"
setup.template.fields: "/etc/filebeat/map.yml"
setup.template.settings:
  index.number_of_shards: 1
cloud.id: <snip>
cloud.auth: <snip>
processors:
 - drop_fields:
     fields: ["type", "beat.name", "beat.version", "_type", "_score", "_id", "@version", "offset", "host", "container", "input", "host", "agent", "log", "_score"]

```

Data is send to Elasticsearch, and a index is created with name; filebeat-, this is undesired.

Anyone can help me out?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [December 20, 2019, 12:25pm UTC](https://discuss.elastic.co/t/mapping-for-elasticsearch-easy/212036/2 "2019-12-20T12:25:03Z")

</div>

Hey @Kevin_Csuka,

Sorry, I think I don't fully understand the question, let me add some comments to see if they help 🙂

> [@Kevin\_Csuka](#):
>
> Data is send to Elasticsearch, and a index is created with name; filebeat-, this is undesired.

Do you mean that an index is created with the exact name "`filebeat-`", or with a name that starts with `filebeat-`? If it is a name that starts with `filebeat-` this is the expected and recommended behaviour. What name were you expecting?

> [@Kevin\_Csuka](#):
>
> How can I tell Filebeat to send it to Elasticsearch and use the correct mapping.

To what mapping do you refer? If you refer to the mapping of the fields in the CSV file, you may use the [`decode_csv_fields` processor](https://www.elastic.co/guide/en/beats/filebeat/7.5/decode-csv-fields.html), this can parse each csv line and put them in a field as an array. Once in an array you can use the [`extract_array` processor](https://www.elastic.co/guide/en/beats/filebeat/7.5/extract-array.html) to define your mapping from the position of the value to some specific field.

You can find a good example of the use of `decode_csv_fields` with `extract_array` in the panw module: [https://github.com/elastic/beats/blob/v7.5.0/x-pack/filebeat/module/panw/panos/config/input.yml#L23](https://github.com/elastic/beats/blob/v7.5.0/x-pack/filebeat/module/panw/panos/config/input.yml#L23)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2020, 12:25pm UTC](https://discuss.elastic.co/t/mapping-for-elasticsearch-easy/212036/3 "2020-01-17T12:25:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
