# Mappingがマージされてしまう件

**URL:** <https://discuss.elastic.co/t/mapping/93710>\
**Category:** 日本語による質問・議論はこちら\
**Created:** [July 19, 2017, 7:49am UTC](https://discuss.elastic.co/t/mapping/93710 "2017-07-19T07:49:01Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![atsuizo](https://avatars.discourse-cdn.com/v4/letter/a/d26b3c/32.png) [@atsuizo](https://discuss.elastic.co/u/atsuizo)\
**Post date:** [July 19, 2017, 7:49am UTC](https://discuss.elastic.co/t/mapping/93710/1 "2017-07-19T07:49:01Z")

</div>

最近触り始めた者ですが、インデックスとマッピングについて意図したとおりに作成できず、  
お力添えいただければと思います。

Linux上ですべてyumで構築した Logstash-Elasticsearch-Kibana の構成において、  
・任意のフォーマットのファイルA -\> /etc/logstash/conf.d/ファイルA用の定義 -\> elasticsearch index =\> A -\> A用のマッピングテンプレート  
・任意のフォーマットのファイルB -\> /etc/logstash/conf.d/ファイルB用の定義 -\> elasticsearch index =\> B -\> A用のマッピングテンプレート  
とし、initctlでサービスとしてLogstashを起動した時、  
ElasticSearch上にはA、BそれぞれのIndexが生成されるのですが、マッピングが  
・Aのマッピング：Logstashのデフォルト？＋A用に定義したテンプレートのマッピング  
・Bのマッピング：Logstashのデフォルト？＋A用に定義したテンプレートのマッピング＋B用に定義したテンプレートのマッピング  
のように認識されてしまいます。

これを厳密に分離して管理したいのですが、どこでどのような設定を入れるべきなのでしょうか。

なお、マッピングテンプレートで  
"dynamic": "strict"  
を追加したら、マッピングがマージされるのは防げたのですが、  
Indexの器だけが生成されて中身は空（Logstashからデータ登録できていない）となってしまいました。

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [July 19, 2017, 9:29am UTC](https://discuss.elastic.co/t/mapping/93710/2 "2017-07-19T09:29:33Z")

</div>

Logstashが利用しているテンプレートの機能は、実際にはElasticsearchの[Index Template](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html)という機能になります。  
このとき、Index Templateの`template`というパラメータの指定の仕方によって、複数のテンプレートがインデックスのマッピングなどの元に利用されます。  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html#multiple-templates](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html#multiple-templates)

おそらく、templateのパラメータがインデックス名に関連しているものになっているのかと思われます。  
A、Bとされているインデックス名は実際には`logstash-A-?`や`logstash-A-B-?`のようなものではないでしょうか？

---

<div class="post-metadata">

**Author:** ![atsuizo](https://avatars.discourse-cdn.com/v4/letter/a/d26b3c/32.png) [@atsuizo](https://discuss.elastic.co/u/atsuizo)\
**Post date:** [July 19, 2017, 12:35pm UTC](https://discuss.elastic.co/t/mapping/93710/3 "2017-07-19T12:35:09Z")

</div>

Indexは、logstashのelasticsearch output pluginでのconf指定に基づいて  
`xxx-yyy-A-%{+YYYY.MM.dd}`  
`xxx-yyy-B-%{+YYYY.MM.dd}`

にて作成されており、templateの指定は、

```
PUT _template/yyy-A
{
  "template": "xxx-yyy-A-*",
   "yyy-A": {
   "date_detection": false,
   "properties": {
    ・・・
}

PUT _template/yyy-B
{
  "template": "xxx-yyy-B-*",
   "yyy-B": {
   "date_detection": false,
   "properties": {
    ・・・
}

```

のような指定で作成しています。

いずれも、logstashのデフォルトと重複しないよう、  
`xxx-`の部分は`logstash-`の形式を避けて指定し、  
index、templateともにそのように作成されています。

KibanaのManagement画面からも  
それぞれの形式でIndex Patternsが検出されますが、  
作成されたIndex PetternはMappingがマージされたものとなります。

（冒頭でバージョンを書き忘れましたが、5.5です。他のバージョンは試したことがありません。）

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [July 20, 2017, 3:01am UTC](https://discuss.elastic.co/t/mapping/93710/4 "2017-07-20T03:01:22Z")

</div>

何度か試されながらKibanaのIndex Patternの画面を見ているようであれば、一度、Index Patternの画面でリロードをしてみるのがいいかと思います。

[https://www.elastic.co/guide/en/kibana/current/index-patterns.html#reload-fields](https://www.elastic.co/guide/en/kibana/current/index-patterns.html#reload-fields)

「Mappingがマージされている」とおっしゃっているのは、Kibanaの画面で確認されている時点でのことでしょうか？  
それとも、`GET xxx-yyy-B-2017.05.05/_mappings`で取得したもののフィールドがマージされているものになっていますでしょうか？

---

<div class="post-metadata">

**Author:** ![atsuizo](https://avatars.discourse-cdn.com/v4/letter/a/d26b3c/32.png) [@atsuizo](https://discuss.elastic.co/u/atsuizo)\
**Post date:** [July 24, 2017, 12:14am UTC](https://discuss.elastic.co/t/mapping/93710/5 "2017-07-24T00:14:16Z")

</div>

`GET _mappings`で取得した結果がマージされています。

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [July 24, 2017, 1:10am UTC](https://discuss.elastic.co/t/mapping/93710/6 "2017-07-24T01:10:43Z")

</div>

具体的にlogstashの設定を張り付けていただけますでしょうか？あと、ディレクトリにあるファイルの一覧も張り付けていただけますでしょうか？

---

<div class="post-metadata">

**Author:** ![atsuizo](https://avatars.discourse-cdn.com/v4/letter/a/d26b3c/32.png) [@atsuizo](https://discuss.elastic.co/u/atsuizo)\
**Post date:** [July 24, 2017, 1:50am UTC](https://discuss.elastic.co/t/mapping/93710/7 "2017-07-24T01:50:44Z")

</div>

以下、具体的なLogstashの設定です。

/etc/logstash/conf.d/配下には、(A-1)(A-2)のファイル以外には存在していません。

(A)MySQLに対してSHOW GLOBAL STATUSを実行した結果をログファイルに出力、Logstash経由でelasticsearchへ

```
mysql -h ホスト名 -u ユーザー名 -pパスワード -e "SHOW GLOBAL STATUS;" | sed -e 's/\t/\" \"/g' | sed -e 's/^/\"/g' | sed -e 's/$/\"/g' | sed -e "s/^/$(date '+%Y\/%m\/%d %H:%M:%S') /g" >> 出力先ファイル

```

(B)MySQLに対してSHOW FULL PROCESSLISTを実行した結果をログファイルに出力、Logstash経由でelasticsearchへ

```
mysql -h ホスト名 -u ユーザー名 -pパスワード -e "SHOW FULL PROCESSLIST;" | sed -e 's/\t/\" \"/g' | sed -e 's/^/\"/g' | sed -e 's/$/\"/g' | sed -e "s/^/$(date '+%Y\/%m\/%d %H:%M:%S') /g" >> 出力先ファイル

```

＊ 文字数がこちらの入力上限に達したようなので、(B)の分は別レスにて張り付けます。

(A-1)Logstashの設定  
/usr/share/logstash/conf.d/mysql\_global\_status.conf

```
input {
    file {
        path => "/var/log/mysql_monitor/show_global_status.log"
        start_position => "beginning"
        type => "mysql-status"
    }
}
filter {
    grok {
        match => { "message" => '%{DATESTAMP:date} "%{DATA:Variable_name}" "%{INT:Variable_value}"' }
    }
}
output {
    if [type] == "mysql-status" {
      elasticsearch {
        hosts => ["localhost:9200"]
        index => "lgs-mysql-status-%{+YYYY.MM.dd}"
        manage_template => false
        template_name => "lgs-mysql-status"
      }
    }
# stdout { codec => rubydebug }
}

```

(A-2)Mapping設定に使用したコマンド

```
PUT _template/mysql-status
{
  "template": "lgs-mysql-status-*", 
   "mappings": {
     "mysql-status": {
       "date_detection": false,
       "properties": {
         "@timestamp": {
           "type": "date"
         },
         "Variable_name": {
           "type": "text"
         },
         "Variable_value": {
           "type": "long"
         }
       }
      }
   }
}

```

(A-3)Mappingの確認結果・・・Variable\_name、Variable\_value以外の項目はLogstashのデフォルト？

```
GET lgs-mysql-status-2017.07.24/_mappings
{
  "lgs-mysql-status-2017.07.24": {
    "mappings": {
      "mysql-status": {
        "date_detection": false,
        "properties": {
          "@timestamp": {
            "type": "date"
          },
          "@version": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "Variable_name": {
            "type": "text"
          },
          "Variable_value": {
            "type": "long"
          },
          "date": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "host": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "message": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "path": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "tags": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "type": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![atsuizo](https://avatars.discourse-cdn.com/v4/letter/a/d26b3c/32.png) [@atsuizo](https://discuss.elastic.co/u/atsuizo)\
**Post date:** [July 24, 2017, 1:51am UTC](https://discuss.elastic.co/t/mapping/93710/8 "2017-07-24T01:51:09Z")

</div>

(B-1)Logstashの設定  
/usr/share/logstash/conf.d/mysql\_show\_full\_processlist.conf

```
input {
    file {
        path => "/var/log/mysql_monitor/show_full_processlist.log"
        start_position => "beginning"
        type => "mysql-processlist"
    }
}
filter {
    grok {
        match => { "message" => '%{DATESTAMP:date} "%{DATA:Proc_id}" "%{DATA:Mysql_user_name}" "%{DATA:Client_host}" "%{DATA:Db_schema}" "%{DATA:Command}" "%{INT:Timer}" "%{DATA:State}" "%{DATA:Info}"' }
    }
}
output {
    if [type] == "mysql-processlist" {
      elasticsearch {    
        hosts => ["localhost:9200"]
        index => "lgs-mysql-processlist-%{+YYYY.MM.dd}"
        manage_template => false
        template_name => "lgs-mysql-processlist"
      }
    }
# stdout { codec => rubydebug }
}

```

(B-2)Mapping設定に使用したコマンド

```
PUT _template/mysql-processlist
{
  "template": "lgs-mysql-processlist-*", 
  "mappings": {
    "mysql-processlist": {
      "properties": {
        "@timestamp": {
        "type": "date"
      },
        "Proc_id": {
        "type": "text"
      },
        "Mysql_user_name": {
        "type": "text"
      },
        "Client_host": {
        "type": "text"
      },        
        "Db_schema": {
        "type": "text"
      },        
        "Command": {
        "type": "text"
      },
        "Timer": {
        "type": "long"
      },
        "State": {
        "type": "text"
      },
        "Info": {
        "type": "text"
      }
      }
    }
  }
}

```

(B-3)Mappingの確認結果・・・(A)で定義したVariable\_name、Variable\_value等が混じっている。  
GET lgs-mysql-processlist-2017.07.24/\_mappings

```
{
  "lgs-mysql-processlist-2017.07.24": {
    "mappings": {
      "mysql-processlist": {
        "properties": {
          "@timestamp": {
            "type": "date"
          },
          "@version": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "Client_host": {
            "type": "text"
          },
          "Command": {
            "type": "text"
          },
          "Db_schema": {
            "type": "text"
          },
          "Info": {
            "type": "text"
          },
          "Mysql_user_name": {
            "type": "text"
          },
          "Proc_id": {
            "type": "text"
          },
          "State": {
            "type": "text"
          },
          "Timer": {
            "type": "long"
          },
          "Variable_name": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "Variable_value": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "date": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "host": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "message": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "path": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "tags": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          },
          "type": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![johtani](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johtani/32/44956_2.png) [@johtani](https://discuss.elastic.co/u/johtani)\
**Post date:** [July 24, 2017, 2:28am UTC](https://discuss.elastic.co/t/mapping/93710/9 "2017-07-24T02:28:13Z")

</div>

あー、なるほど。  
(A-3)にかんしては、Elasticsearchのデフォルトになります。

> **[Mapping changes | Elasticsearch Reference \[5.5\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/5.5/breaking_50_mapping_changes.html#_default_string_mappings)**

あと、A-1のtemplate\_nameはA-2のmysql-statusにしないときちんと動かないと思いますが。。。

混ざる点に関してはおそらく、grokにもifを書くべきかと。  
Logstash内部としては1つの設定(1つのPipeline)になりますので、それぞれのログを読み込んだ後に、2つのgrokが動いているはずです。

参考：

> [@Running multiple independent logstash config files with input,filter and output](https://discuss.elastic.co/t/running-multiple-independent-logstash-config-files-with-input-filter-and-output/29757):
>
> Hi, We have multiple applications running on a single server and we are collecting the logs from these application and sending it to a intermediate queues using logstash forwarders. As, the log formats, processing and the output queues were different for different applications logs, I prepared multiple config files which are complete in themselves i.e. each config file has the input, filter and output section. what is the best way to start all the configs, logstash -f /configDirPath is givi…

---

<div class="post-metadata">

**Author:** ![atsuizo](https://avatars.discourse-cdn.com/v4/letter/a/d26b3c/32.png) [@atsuizo](https://discuss.elastic.co/u/atsuizo)\
**Post date:** [July 24, 2017, 2:58am UTC](https://discuss.elastic.co/t/mapping/93710/10 "2017-07-24T02:58:21Z")

</div>

(1)`output`部における`template_name`の誤記修正のみ -\> 変化なし

(2)`filter` 部において、`grok`記述のブロックの外を`if[type]=="inputで定義したタイプ"{}`で囲む -\> 問題解消しました！

.confは１つのファイルで書いても複数のファイルで書いても良いけど、異なるフォーマットのファイルを監視、取込する際には`filter`と`output`には`if`をつけるべき、ということですね。  
outputが別れていて、templateも指定してあっても、その前のfilterを通ってきたデータの構造によって自動判断するmapping定義の方が強い、と。

Logstashは事前にmappingを定義しなくても自動判定でelasticsearchインデックス構造を決めて作ってくれる易しさがある一方、意図したとおりに取り込ませるには、そうした自動判定に入らないように厳密に定義してあげる必要がある、と理解しました。

ありがとうございました。

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2017, 2:58am UTC](https://discuss.elastic.co/t/mapping/93710/11 "2017-08-21T02:58:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
