# Mapping use dynamic strict

**URL:** <https://discuss.elastic.co/t/mapping-use-dynamic-strict/264957>\
**Category:** Elasticsearch\
**Created:** [February 20, 2021, 6:31pm UTC](https://discuss.elastic.co/t/mapping-use-dynamic-strict/264957 "2021-02-20T18:31:34Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 20, 2021, 6:31pm UTC](https://discuss.elastic.co/t/mapping-use-dynamic-strict/264957/1 "2021-02-20T18:31:35Z")

</div>

I am trying to test out this feature but not getting what I want

for example

```
PUT _index_template/sachin_quick_test
{
  "index_patterns": ["sachin_quick_test-*"],
  "template": {
    "settings": {
      "number_of_shards": 1
    },
    
  "mappings" : {
      "dynamic": "strict",
      "properties" : {
        "@timestamp" : {
          "type" : "date"
        },
        "@version" : {
          "type" : "text",
          "fields" : {
            "keyword" : {
              "type" : "keyword",
              "ignore_above" : 256
            }
          }
        },
        "day" : {
          "type" : "text",
          "fields" : {
            "keyword" : {
              "type" : "keyword",
              "ignore_above" : 256
            }
          }
        }
}
}
}

```

Template gets created. and I can see it then when I put the data and day="string" it works

but it still does work when I put data=123 and explicitly convert to integer or not convert. it gets saved in elk as integer

Reason I know it works because if I change number\_of\_shards setting to 2 it does creates two shard that means it is using this template.

is my syntax is wrong for dynamic?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 21, 2021, 8:39pm UTC](https://discuss.elastic.co/t/mapping-use-dynamic-strict/264957/2 "2021-02-21T20:39:35Z")

</div>

I did all sort of different combination but day field still allows text and integer both

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 21, 2021, 9:12pm UTC](https://discuss.elastic.co/t/mapping-use-dynamic-strict/264957/3 "2021-02-21T21:12:38Z")

</div>

> [@elasticforme](#):
>
> but it still does work when I put data=123 and explicitly convert to integer or not convert. it gets saved in elk as integer

Can you show the actual mapping after you have posted this?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 21, 2021, 9:17pm UTC](https://discuss.elastic.co/t/mapping-use-dynamic-strict/264957/4 "2021-02-21T21:17:36Z")

</div>

I suspect you are seeing something similar to [this](https://discuss.elastic.co/t/elastic-stores-string-in-numeric-long-field/264102/6)

How the field is stored is different than how the field is represented in the source document I suspect you are looking at the source document and expecting it to change the type please read the response above and it may help clarify.

Elastic does not cast / correct the source document but it will convert if it can into the actual stored field /doc\_value

So in your case if you set day=123 in the \_source it looks like the integer you entered, but if you looked at the actual doc\_value it would be a string.

And pretty much anything can be a string so it will almost always index a value as a string

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 22, 2021, 3:20pm UTC](https://discuss.elastic.co/t/mapping-use-dynamic-strict/264957/5 "2021-02-22T15:20:32Z")

</div>

@stephenb this is exactly what I have been seeing. But you are saying when I see value 123 without " around it, it is still a string correct?  
if that is the case then what I have seen so far is wrong that string should be inside double quote and integer is without it. 🙂

@warkolm here are detail. exactly what is happening

```
PUT _index_template/sachin_quick_test
{
  "index_patterns": ["sachin_quick_test-*"],
  "template": {
    "settings": {
      "number_of_shards": 1
    },
  "mappings" : {
    "dynamic": "strict",
      "properties" : {
        "@timestamp" : {
          "type" : "date"
        },
        "job" : {
          "type" : "long"
        },
        "day" : {
          "type" : "text",
          "fields" : {
            "keyword" : {
              "type" : "keyword",
              "ignore_above" : 256
            }
          }
        }
      }
    }
  }
}

```

Then I send two document

```
message => '{"job": 100, "day":123}'
message => '{"job": 101, "day":"Monday"}'

GET sachin_quick_test-2021/_search
"hits" : [
      {
        "_index" : "sachin_quick_test-2021",
        "_type" : "_doc",
        "_id" : "101",
        "_score" : 1.0,
        "_source" : {
          "job" : 101,
          "day" : "Monday",
          "@timestamp" : "2021-02-22T15:12:20.125Z"
        }
      },
      {
        "_index" : "sachin_quick_test-2021",
        "_type" : "_doc",
        "_id" : "100",
        "_score" : 1.0,
        "_source" : {
          "job" : 100,
          "day" : 123,
          "@timestamp" : "2021-02-22T15:12:51.359Z"
        }
      }
    ]
```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 22, 2021, 3:28pm UTC](https://discuss.elastic.co/t/mapping-use-dynamic-strict/264957/6 "2021-02-22T15:28:22Z")

</div>

Yes... that is _exactly_ what I am saying 🙂

what you see in your query is the `_source` document, the Source what you put into elasticsearch, elasticsearch does not "correct" that. This is the subtlety that most people do not "grok" the source document is just that ... the source document, you can actually chose to _not_ store it (not suggesting that unless you have a specific reason) ..... that data that is actually indexed and searched is stored in other data structures withing elasticsearch most notable doc\_values.

To see the fields that are actually indexed and stored as fields that are actually searched try this date field will show up as text

```auto
GET sachin_quick_test-2021/_search
{
  "docvalue_fields": ["day"]
}

```

if you try this opposite and try to define a long and then try it is easier to see

```
DELETE my-index

PUT my-index

PUT my-index
{
  "mappings": {
    "properties": {
      "testId": {
        "type": "long"
      }
    }
  }
}

PUT my-index/_doc/1
{
  "testId": 1
}

PUT my-index/_doc/2
{
  "testId": "2"
}

# This will fail on indexing with a mapping exception
PUT my-index/_doc/3
{
  "testId": "three"
}

GET my-index/_search
{
  "docvalue_fields": ["testId"]
}

```

Not in the result the testId in the doc\_value is actually a long

```
{
  "took" : 1,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 2,
      "relation" : "eq"
    },
    "max_score" : 1.0,
    "hits" : [
      {
        "_index" : "my-index",
        "_type" : "_doc",
        "_id" : "1",
        "_score" : 1.0,
        "_source" : {
          "testId" : 1
        },
        "fields" : {
          "testId" : [
            1
          ]
        }
      },
      {
        "_index" : "my-index",
        "_type" : "_doc",
        "_id" : "2",
        "_score" : 1.0,
        "_source" : {
          "testId" : "2"
        },
        "fields" : {
          "testId" : [
            2 <--------- long even though the _source was "2"
          ]
        }
      }
    ]
  }
}
```

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 22, 2021, 4:01pm UTC](https://discuss.elastic.co/t/mapping-use-dynamic-strict/264957/7 "2021-02-22T16:01:36Z")

</div>

Ok I change day=long and I was not able to save Monday in to it.

But if I set day=string I am able to save Monday and 123 (even when I use mutate and convert that to integer inside logstash)  
this is weird. but now I understand it hence I can use it the way I wanted it.

Basically I want to define my mapping strict for all field that way no one can put unwanted type in to defined and my pattern gets messed up where one field will have multiple type of data.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 22, 2021, 4:03pm UTC](https://discuss.elastic.co/t/mapping-use-dynamic-strict/264957/8 "2021-02-22T16:03:07Z")

</div>

Thank you @stephenb

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2021, 4:03pm UTC](https://discuss.elastic.co/t/mapping-use-dynamic-strict/264957/9 "2021-03-22T16:03:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
