# Override \_default\_ mapping properties

**URL:** <https://discuss.elastic.co/t/override--default--mapping-properties/51660>\
**Category:** Elasticsearch\
**Created:** [June 2, 2016, 8:49am UTC](https://discuss.elastic.co/t/override--default--mapping-properties/51660 "2016-06-02T08:49:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nicolas\_Guyomar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolas_guyomar/32/10124_2.png) [@Nicolas\_Guyomar](https://discuss.elastic.co/u/Nicolas_Guyomar)\
**Post date:** [June 2, 2016, 8:49am UTC](https://discuss.elastic.co/t/override--default--mapping-properties/51660/1 "2016-06-02T08:49:05Z")

</div>

Hi,

I started a while ago using the logstash default elasticsearch template "[https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template.json](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template.json)" on an existing cluster (1.7.3), so that I could use doc\_value on every field.

Thing is, some "already existing fields" haven't changed. They are still using fielddata and putting some memory pressure on my cluster.

I use the logstash (1.5.2) elasticsearch output plugin with 'template\_overwrite =\> true' , but still, the _default_ mapping **properties** are not updated, the dynamic template part is OK.

Can I override this default mapping ? Or maybe remove the properties which are not using doc\_value ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 3, 2016, 1:41am UTC](https://discuss.elastic.co/t/override--default--mapping-properties/51660/2 "2016-06-03T01:41:38Z")

</div>

What's your config look like, have you set `template_overwrite`?

---

<div class="post-metadata">

**Author:** ![Nicolas\_Guyomar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolas_guyomar/32/10124_2.png) [@Nicolas\_Guyomar](https://discuss.elastic.co/u/Nicolas_Guyomar)\
**Post date:** [June 3, 2016, 7:33am UTC](https://discuss.elastic.co/t/override--default--mapping-properties/51660/3 "2016-06-03T07:33:49Z")

</div>

Hi,

I'm using the elasticsearch output plugin

```
 elasticsearch {
                host => [<%= @elasticsearch_datanodes %>]
                cluster => "<%= @elasticsearchcluster %>"
                protocol => "http"
                port => 9200
                workers => 8
                flush_size => 500
                **template => "/opt/application/logstash/template/elasticsearch_mapping.json"**
 **template_overwrite => true**
            }

```

What I do not understand, is that when a new index gets created @ midnight, its mappings contains a default configuration for some fields, that I'd like to be different.

For instance those 2 fields are using fielddata (extract from the _default_ part of today's mapping) :

```
    "level": {
                            "type": "string",
                            "fields": {
                                "raw": {
                                    "type": "string",
                                    "index": "not_analyzed",
                                    "ignore_above": 256
                                }
                            }
                        },
                        "message": {
                            "type": "string",
                            "fields": {
                                "raw": {
                                    "type": "string",
                                    "index": "not_analyzed",
                                    "ignore_above": 256
                                }
                            }
                        }

```

Meanwhile, some other fields are Ok :

```
"operation": {
                        "type": "string",
                        "norms": {
                            "enabled": false
                        },
                        **"fielddata": {**
 **"format": "disabled"**
 **},**
                        "fields": {
                            "raw": {
                                "type": "string",
                                "index": "not_analyzed",
                                "doc_values": true,
                                "ignore_above": 256
                            }
                        }
                    },

```

Why do some field gets a "default" configuration?. I do not understand where those properties come from. It is like I have, somewhere in elasticsearch, a _default_ which is applied to every newly created index.

I tried to remove the _default_ from every mapping yesterday, (curl -XDELETE elastic:9200/\_template/_default_) and I was not seeing this _default_ in my old index mapping. But this morning logstash-2016.06.03 got this _default_ with some field missing the fielddata part

My biggest problem is that those concerned fields are the most requested from Kibana (message, level, host..), resulting in some memory pressure on my cluster.

---

<div class="post-metadata">

**Author:** ![Nicolas\_Guyomar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicolas_guyomar/32/10124_2.png) [@Nicolas\_Guyomar](https://discuss.elastic.co/u/Nicolas_Guyomar)\
**Post date:** [June 3, 2016, 6:04pm UTC](https://discuss.elastic.co/t/override--default--mapping-properties/51660/4 "2016-06-03T18:04:41Z")

</div>

Hi,

Anyone got an idea on this ?

I will try to hard code fielddata missing properties to disable it on fields that are getting an incorrect mapping, but I do not feel this is the right way to deal with my problem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:46pm UTC](https://discuss.elastic.co/t/override--default--mapping-properties/51660/5 "2017-07-05T22:46:20Z")

</div>


