# Template for elastic indexing

**URL:** <https://discuss.elastic.co/t/template-for-elastic-indexing/81433>\
**Category:** Elasticsearch\
**Created:** [April 6, 2017, 8:39am UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433 "2017-04-06T08:39:52Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [April 6, 2017, 8:39am UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433/1 "2017-04-06T08:39:52Z")

</div>

Hello

I being created template to increase performance of indexing (and gain of space).

Where i can put not analyze string type ? (text & keyword from ES 5.x). The best will be not analyze all text field i think.

So, maybe I don't need metafield as source, score, beats info ? ... where i can delete few of them ?

```
 {
    "order": 0,
    "version": 50001,
    "template": "ta-test-edr",
    "settings": {
      "index": {
        "number_of_replicas": 0,
        "number_of_shards" : 1,
        "refresh_interval": "-1"
      }
    },
    "mappings": {
      "_default_": {
        "dynamic_templates": [
          {
            "string_fields": {
              "mapping": {
                "norms": false,
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword"
                  }
                }
              },
              "match_mapping_type": "string",
              "match": "*"
            }
          }
        ],
        "_all": {
          "norms": false,
          "enabled": true
        },
        "properties": {
          "@timestamp": {
            "include_in_all": false,
            "type": "date"
          },
          "geoip": {
            "dynamic": true,
            "properties": {
              "ip": {
                "type": "ip"
              },
              "latitude": {
                "type": "half_float"
              },
              "location": {
                "type": "geo_point"
              },
              "longitude": {
                "type": "half_float"
              }
            }
          },
          "@version": {
            "include_in_all": false,
            "type": "keyword"
          }
        }
      }
    },
    "aliases": {}
  }
```

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [April 6, 2017, 8:44am UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433/2 "2017-04-06T08:44:17Z")

</div>

I believe it's like to delete field not use :

```
"properties": {
            "source" : { "enabled" : false },
            "beat": { "enabled" : false },
            "@version": { "enabled" : false },
            "name": { "enabled" : false },
            "version": { "enabled" : false },
            "host": { "enabled" : false },
            "input_type": { "enabled" : false },
            "tags": { "enabled" : false },
            "type": { "enabled" : false } }
```

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [April 6, 2017, 2:55pm UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433/3 "2017-04-06T14:55:11Z")

</div>

Ok i belive it's work fine with this template :

```
PUT _template/template_edr
{
    "order": 0,
    "version": 50001,
    "template": "edr-*",
    "settings": {
      "index": {
        "number_of_replicas": 0,
        "number_of_shards" : 1,
        "refresh_interval": "-1"
      }
    },
    "mappings": {
      "_default_": {
        "dynamic_templates": [
          {
            "string_fields": {
              "mapping": {
                "norms": false,
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "index": "not_analyzed"
                  }
                }
              },
              "match_mapping_type": "string",
              "match": "*"
            }
          }
        ],
        "_all": {
          "norms": false,
          "enabled": true
        },
        "properties": {
          "edr_Granctets": {
            "type": "long"
          },
          "edr_EI": {
            "type": "long"
            },
          "edr_Janomer": {
            "type": "byte"
          },
          "edr_MC": {
            "type": "integer"
            },
          "edr_DN": {
            "type": "long"
            },
          "edr_MasDN": {
            "type": "long"
            },
          
          "edr_ModonFlag": {
            "type": "byte"
            },
          "edr_ParlFlag": {
            "type": "byte"
            },
          "edr_SurId": {
            "type": "long"
          },
          "edr_Usimit": {
            "type": "long"
          },
          "edr_Usetets": {
            "type": "long"
          },
          
          "@timestamp": {
            "include_in_all": false,
            "type": "date"
          },
          "geoip": {
            "enabled": false
            },
            "source" : { 
              "enabled" : false 
            },
            "beat": { 
              "enabled" : false 
            },
            "@version": {
              "include_in_all": false,
              "type": "keyword"
             },
            "name": { 
              "enabled" : false 
            },
            "host": { 
              "enabled" : false 
            },
            "input_type": { 
              "enabled" : false 
            },
            "tags": { 
              "enabled" : false 
            },
            "type": { 
              "enabled" : false 
              
            }
        }
      }
    },
    "aliases": {}
  }

```

How to know if my settings are correctly understand ? thank you

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [April 7, 2017, 3:39pm UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433/4 "2017-04-07T15:39:58Z")

</div>

hummm i have some errors in elastic log :

```
[2017-04-07T17:28:45,155][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [uiStateJSON]
[2017-04-07T17:28:45,155][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [description]
[2017-04-07T17:28:45,156][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [savedSearchId]
[2017-04-07T17:28:45,156][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [searchSourceJSON]
[2017-04-07T17:28:45,156][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [title]
[2017-04-07T17:28:45,156][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [visState]
[2017-04-07T17:28:45,157][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [uiStateJSON]
[2017-04-07T17:28:45,157][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [description]
[2017-04-07T17:28:45,157][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [savedSearchId]
[2017-04-07T17:28:45,157][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [searchSourceJSON]

```

So I use text in my template no ? 😕

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 8, 2017, 11:07pm UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433/5 "2017-04-08T23:07:04Z")

</div>

> [@Beuhlet\_Reseau](#):
>
> Where i can put not analyze string type ? (text & keyword from ES 5.x). The best will be not analyze all text field i think.

That is what you have here;

```
 "string_fields": {
              "mapping": {
                "norms": false,
                "type": "text",
                "fields": {
                  "keyword": {
                    "type": "keyword"
                  }
                }
          }

```

> [@Beuhlet\_Reseau](#):
>
> So, maybe I don't need metafield as source, score, beats info ? ... where i can delete few of them ?

Don't send them is the easiest way 🙂 But you can disable source (as it is an ES native field) if you really want.

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [April 10, 2017, 8:09am UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433/6 "2017-04-10T08:09:26Z")

</div>

@warkolm

> [@warkolm](#):
>
> Don't send them is the easiest way 🙂 But you can disable source (as it is an ES native field) if you really want.

"source" : {  
"enabled" : false  
},

That is ? or you talk to remove source field directly in logstash with the remove\_field ?  
So, i want remove field like input\_type, beat.\*, \_score,\_id ??? (I have disable it in template but i continu to see them in discover)

About depracated error, why ? I use text and keyword no ? @Christian_Dahlqvist

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 10, 2017, 10:01am UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433/7 "2017-04-10T10:01:13Z")

</div>

> [@Beuhlet\_Reseau](#):
>
> "source" : { "enabled" : false },

That.

> [@Beuhlet\_Reseau](#):
>
> So, i want remove field like input\_type, beat.\*, score,id

You cannot remove `_id`, if that is what you mean.

> [@Beuhlet\_Reseau](#):
>
> About depracated error, why ? I use text and keyword no ? @Christian_Dahlqvist

Please don't ping people like that.

Have a look at [Mapping changes | Elasticsearch Guide [5.3] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/5.3/breaking_50_mapping_changes.html#_literal_string_literal_fields_replaced_by_literal_text_literal_literal_keyword_literal_fields)

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [April 10, 2017, 11:25am UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433/8 "2017-04-10T11:25:27Z")

</div>

I understand @warkolm

> [@warkolm](#):
>
> So, i want remove field like input\_type, beat.\*, score,id
> 
> You cannot remove \_id, if that is what you mean.

If i do that :

```
mutate {
                remove_field => ["message", "beat", "input_type", "type", "tags", "host"]
                   }

```

It's also good no ?

So, I have this error from few moment :

 ![](https://us1.discourse-cdn.com/elastic/original/3X/e/b/eb0146c1c204d69eca86bcaebfa3877a755c9f06.JPG)

it's because of template (see above) when i delete my template i haven't error 😕

---

<div class="post-metadata">

**Author:** ![billnbell](https://avatars.discourse-cdn.com/v4/letter/b/eb8c5e/32.png) [@billnbell](https://discuss.elastic.co/u/billnbell)\
**Post date:** [April 12, 2017, 3:08pm UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433/9 "2017-04-12T15:08:26Z")

</div>

Shouldn't the default be norms: false on all keyword fields?

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [April 12, 2017, 3:38pm UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433/10 "2017-04-12T15:38:42Z")

</div>

Yes i copy it from default logstash template (GET /template).

Why ??

So I see every fields (numeric and text) in index pattern page but i see always this error message on discover

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [April 14, 2017, 9:16am UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433/11 "2017-04-14T09:16:38Z")

</div>

IF i want not analyze few numeric data fields i have just put :

"numeric\_field" {  
type="long"  
index="not\_analyze"  
}

?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2017, 9:20am UTC](https://discuss.elastic.co/t/template-for-elastic-indexing/81433/12 "2017-05-12T09:20:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
