# Nginx module and keyword fields

**URL:** <https://discuss.elastic.co/t/nginx-module-and-keyword-fields/103277>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 10, 2017, 12:42am UTC](https://discuss.elastic.co/t/nginx-module-and-keyword-fields/103277 "2017-10-10T00:42:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![aarongorka](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aarongorka/32/22947_2.png) [@aarongorka](https://discuss.elastic.co/u/aarongorka)\
**Post date:** [October 10, 2017, 12:42am UTC](https://discuss.elastic.co/t/nginx-module-and-keyword-fields/103277/1 "2017-10-10T00:42:14Z")

</div>

The Nginx module for Filebeat seems to ship most fields as keywords, as indicated here: [https://www.elastic.co/guide/en/beats/filebeat/master/exported-fields-nginx.html](https://www.elastic.co/guide/en/beats/filebeat/master/exported-fields-nginx.html)

It makes it really difficult to do some more useful searches, e.g. searching for a prefix on nginx.access.url so I can find out what traffic is going to a legacy app, or to group nginx.access.referrers by a common domain.

Is there any way to configure Filebeat to ship fields as text, or is this potentially a feature that could be added?

---

<div class="post-metadata">

**Author:** ![aarongorka](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aarongorka/32/22947_2.png) [@aarongorka](https://discuss.elastic.co/u/aarongorka)\
**Post date:** [November 2, 2017, 10:16pm UTC](https://discuss.elastic.co/t/nginx-module-and-keyword-fields/103277/2 "2017-11-02T22:16:57Z")

</div>

I went through the Filebeat source code and couldn't find anything explicitly setting the field type, I think it's just a index template issue. Using this configuration in Filebeat makes the fields indexed as the default Logstash template has some bonus configuration:

```
output.elasticsearch:
  indices:
    - index: "logstash-%{+yyyy.MM.dd}"
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 2, 2017, 11:24pm UTC](https://discuss.elastic.co/t/nginx-module-and-keyword-fields/103277/3 "2017-11-02T23:24:11Z")

</div>

> [@aarongorka](#):
>
> I think it's just a index template issue.

Yep

If you customize the index template you can change how the data is mapped. You could setup the fields as `text`, but if you also want to aggregate on the fields then using a [multi field](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-fields.html) will be best so you can do both.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2017, 11:24pm UTC](https://discuss.elastic.co/t/nginx-module-and-keyword-fields/103277/4 "2017-11-30T23:24:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
