# Mapping question

**URL:** <https://discuss.elastic.co/t/mapping-question/314528>\
**Category:** Elasticsearch\
**Created:** [September 15, 2022, 4:11pm UTC](https://discuss.elastic.co/t/mapping-question/314528 "2022-09-15T16:11:17Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 15, 2022, 4:11pm UTC](https://discuss.elastic.co/t/mapping-question/314528/1 "2022-09-15T16:11:17Z")

</div>

I have old index hundreds of them which has following in pattern.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/8/78b814f07d300654240f321e924e070e31663826.png)

I have another index created on different test cluster. which had this place dynamically.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55d4e37647691b091c3aea059bd4d8fd93187999.png)

What I want is to add this host.name.keyword in previous index pattern.  
I understand that I must have messed up something when I did create first set of index and patterns.

how do I add host.name.keyword now to previous pattern?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 15, 2022, 6:56pm UTC](https://discuss.elastic.co/t/mapping-question/314528/2 "2022-09-15T18:56:09Z")

</div>

Actually your original / top example is more correct.

The second example is a default mapping meaning you did not define it ...

I would suggest to fix the test cluster.

You can't change the mapping on the 100s of existing indices

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 15, 2022, 7:02pm UTC](https://discuss.elastic.co/t/mapping-question/314528/3 "2022-09-15T19:02:53Z")

</div>

but it says it would be wise to use .keyword for aggregation as it is more optimized.

and I have only four of such field that needs to be changed.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 15, 2022, 7:45pm UTC](https://discuss.elastic.co/t/mapping-question/314528/4 "2022-09-15T19:45:38Z")

</div>

Yes your top one IS a keyword

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/4/b4745cad9a04b8808b8ea5abfff262d84459477b.png)

Exactly

A `keyword` does not need to be named `.keyword`

It just needs to be a `keyword` type

Look at the mapping on the top index you will see [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/keyword.html#keyword-field-type)

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 15, 2022, 8:11pm UTC](https://discuss.elastic.co/t/mapping-question/314528/5 "2022-09-15T20:11:01Z")

</div>

ok. that make sense. but I don't know how it came up as host.name = keyword, this is using metricbeat template (7.12.0) I must have done something to be like that.

because second example is 7.17.1 metricbeat template.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 15, 2022, 8:18pm UTC](https://discuss.elastic.co/t/mapping-question/314528/6 "2022-09-15T20:18:56Z")

</div>

one more question then  
on second pic it shows  
host.name = text,keyword. but I am not able to use that on viz it gives me this error

Reason  
Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [host.name] in order to load field data by uninverting the inverted index. Note that this can use significant memory.

but when I use host.name.keyword it works fine.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 16, 2022, 12:15am UTC](https://discuss.elastic.co/t/mapping-question/314528/7 "2022-09-16T00:15:59Z")

</div>

> [@elasticforme](#):
>
> ok. that make sense. but I don't know how it came up as host.name = keyword, this is using metricbeat template (7.12.0) I must have done something to be like that.

Most Likely you missed running setup... that is what happens when there is no mapping template

Whenever you see this

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55d4e37647691b091c3aea059bd4d8fd93187999.png)

That means the template is not applied... you did not run setup or you renamed the index to something the template does not match therefore the perdefined mapping is not applied and thus the default mapping IS applied (I show that at the bottom)

> [@elasticforme](#):
>
> Reason  
> Text fields are not optimized for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [host.name] in order to load field data by uninverting the inverted index. Note that this can use significant memory.
> 
> but when I use host.name.keyword it works fine.

Yes this makes perfect sense...

`host.name`

Actually a multifield (2 fields in 1)

One is `host.name` is a `text` field which you can not aggregate on hence the error message above

the Second `host.name.keyword` is a `keyword` which you can use to aggregate on.

Do this... this is what is happening and you are seeing...

```auto
POST discuss-test/_doc
{
   "host.name" : "myhost"
}

GET discuss-test

{
  "discuss-test": {
    "aliases": {},
    "mappings": {
      "properties": {
        "host": {
          "properties": {
            "name": {
              "type": "text", <!----- host.name of type text
              "fields": {
                "keyword": {
                  "type": "keyword", <!--- host.name.keyword of type keyword 
                  "ignore_above": 256
                }
              }
            }
          }
        }
      }
    }
...

```

What it should look like, and will look like with the proper templates / mapping applied

```auto
DELETE discuss-test

PUT discuss-test/
{
  "mappings": {
    "properties": {
      "host": {
        "properties": {
          "name": {
            "type": "keyword"
          }
        }
      }
    }
  }
}

POST discuss-test/_doc
{
   "host.name" : "myhost"
}

GET discuss-test

{
  "discuss-test": {
    "aliases": {},
    "mappings": {
      "properties": {
        "host": {
          "properties": {
            "name": {
              "type": "keyword"
            }
          }
        }
      }
    },
...

```

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 16, 2022, 12:55pm UTC](https://discuss.elastic.co/t/mapping-question/314528/8 "2022-09-16T12:55:51Z")

</div>

This is great @stephenb I understand now what happened and how to fix/investigate further.

I will have to investigate and get this properly align.

basically my existing cluster have proper mapping. and I discover this while testing upgrade process on my test cluster.

I will have to find a way to duplicate that on test for proper testing.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 16, 2022, 2:43pm UTC](https://discuss.elastic.co/t/mapping-question/314528/9 "2022-09-16T14:43:17Z")

</div>

Thanks again @stephenb  
I was able to duplicate exactly what I had in production to test cluster.

what I had to do is host.name is not something that comes with metricbeat (fields.yml) hence once I put the default template which is composable index template. I added this

```auto
 "host": {
      "type": "object",
      "properties": {
        "name": {
          "type": "keyword"
        }
      }
    }

```

Actually I had define 10 such field for our use case. and they where all under object "host, system, processes"

I tested out with one object like host.name and it works now.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 16, 2022, 4:00pm UTC](https://discuss.elastic.co/t/mapping-question/314528/10 "2022-09-16T16:00:51Z")

</div>

> [@elasticforme](#):
>
> what I had to do is host.name

Hmmm... it should be

> **[ECS fields | Metricbeat Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/beats/metricbeat/current/exported-fields-ecs.html#_host)**

> **`host.hostname`**
> 
> Hostname of the host. It normally contains what the `hostname` command returns on the host machine.
> 
> type: keyword
> 
> **`host.name`**
> 
> Name of the host. It can contain what `hostname` returns on Unix systems, the fully qualified domain name, or a name specified by the user. The sender decides which value to use.
> 
> type: keyword

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [September 16, 2022, 9:35pm UTC](https://discuss.elastic.co/t/mapping-question/314528/11 "2022-09-16T21:35:30Z")

</div>

something wrong then because if I leave is as is, it creates exactly like my pic2.

but if I remove that multi level part from it. it does creates only one "host.name" as keyword

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2022, 9:36pm UTC](https://discuss.elastic.co/t/mapping-question/314528/12 "2022-10-14T21:36:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
