# Mapping of index containing date in index(Ex. filebeat-2016.05.24)

**URL:** <https://discuss.elastic.co/t/mapping-of-index-containing-date-in-index-ex-filebeat-2016-05-24/50792>\
**Category:** Elasticsearch\
**Created:** [May 24, 2016, 6:16am UTC](https://discuss.elastic.co/t/mapping-of-index-containing-date-in-index-ex-filebeat-2016-05-24/50792 "2016-05-24T06:16:17Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sukhada369](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@sukhada369](https://discuss.elastic.co/u/sukhada369)\
**Post date:** [May 24, 2016, 6:16am UTC](https://discuss.elastic.co/t/mapping-of-index-containing-date-in-index-ex-filebeat-2016-05-24/50792/1 "2016-05-24T06:16:17Z")

</div>

I am using the index pattern as "filebeat-[yyyy.mm.dd]". Some of the fields need to be analysed and hence I am uploading mapping.json template for the same with changes in it for required fields. The problem I am facing here is that, I am not able to do the mapping changes for the pattern "filebeat-\*" and hence need to upload a new mapping file everyday. What can be done in such scenarios?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 24, 2016, 7:58am UTC](https://discuss.elastic.co/t/mapping-of-index-containing-date-in-index-ex-filebeat-2016-05-24/50792/2 "2016-05-24T07:58:28Z")

</div>

So you're saying that you have an index template that matches filebeat-\*, yet a newly created filebeat-2016.05.24 index doesn't get the mappings from the template?

---

<div class="post-metadata">

**Author:** ![sukhada369](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@sukhada369](https://discuss.elastic.co/u/sukhada369)\
**Post date:** [May 24, 2016, 9:18am UTC](https://discuss.elastic.co/t/mapping-of-index-containing-date-in-index-ex-filebeat-2016-05-24/50792/3 "2016-05-24T09:18:09Z")

</div>

No,  
Giving you an example. I have an index as filebeat-2016.05.24. It is having a field as "message" which needs to be analysed. To do the required changes I downloaded mapping.json file for the given index, made required changes and uploaded the template. Now when I receive new logs for the same index, my field "message" is analysed.

So, can we have a generalized template as "filebeat-\*" instead of "filebeat-2016.05.24"? So that I don't need to upload the new mapping template for each date.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 24, 2016, 12:16pm UTC](https://discuss.elastic.co/t/mapping-of-index-containing-date-in-index-ex-filebeat-2016-05-24/50792/4 "2016-05-24T12:16:18Z")

</div>

> Giving you an example. I have an index as filebeat-2016.05.24. It is having a field as "message" which needs to be analysed. To do the required changes I downloaded mapping.json file for the given index, made required changes and uploaded the template.

But did you actually upload a template? It sounds like you just used the update mapping API. Which exact HTTP request did you make?

> Now when I receive new logs for the same index, my field "message" is analysed.

You can't change the mappings of existing indexes. You have to reindex.

> So, can we have a generalized template as "filebeat-\*" instead of "filebeat-2016.05.24"? So that I don't need to upload the new mapping template for each date.

Yes, that's exactly the idea with index templates.

---

<div class="post-metadata">

**Author:** ![sukhada369](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@sukhada369](https://discuss.elastic.co/u/sukhada369)\
**Post date:** [May 24, 2016, 12:58pm UTC](https://discuss.elastic.co/t/mapping-of-index-containing-date-in-index-ex-filebeat-2016-05-24/50792/5 "2016-05-24T12:58:36Z")

</div>

To get the field mapping I used following command:  
curl -XGET '[http://localhost:9200/filebeat-2016.05.24/\_mapping?pretty](http://localhost:9200/filebeat-2016.05.24/_mapping?pretty)' \> map.json

Now I made changes to map.json and uploaded it using following command:  
curl [http://localhost:9200/filebeat-2016.05.24](http://localhost:9200/filebeat-2016.05.24) -X POST -d @map.json

I want to apply a generalized mapping which would be used by all the indices filebeat-\*

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 24, 2016, 1:24pm UTC](https://discuss.elastic.co/t/mapping-of-index-containing-date-in-index-ex-filebeat-2016-05-24/50792/6 "2016-05-24T13:24:55Z")

</div>

Okay, then look into index templates. What you've been doing so far is unrelated to index templates.

---

<div class="post-metadata">

**Author:** ![sukhada369](https://avatars.discourse-cdn.com/v4/letter/s/ce7236/32.png) [@sukhada369](https://discuss.elastic.co/u/sukhada369)\
**Post date:** [May 24, 2016, 1:37pm UTC](https://discuss.elastic.co/t/mapping-of-index-containing-date-in-index-ex-filebeat-2016-05-24/50792/7 "2016-05-24T13:37:24Z")

</div>

Ok!! Thank you 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:49pm UTC](https://discuss.elastic.co/t/mapping-of-index-containing-date-in-index-ex-filebeat-2016-05-24/50792/8 "2017-07-05T22:49:29Z")

</div>


