# Trouble with template and field mapping

**URL:** <https://discuss.elastic.co/t/trouble-with-template-and-field-mapping/44585>\
**Category:** Elasticsearch\
**Created:** [March 16, 2016, 3:59pm UTC](https://discuss.elastic.co/t/trouble-with-template-and-field-mapping/44585 "2016-03-16T15:59:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dloyd](https://avatars.discourse-cdn.com/v4/letter/d/4491bb/32.png) [@dloyd](https://discuss.elastic.co/u/dloyd)\
**Post date:** [March 16, 2016, 3:59pm UTC](https://discuss.elastic.co/t/trouble-with-template-and-field-mapping/44585/1 "2016-03-16T15:59:36Z")

</div>

Hello Guy and Gals. I am rather new and think I am missing something simplistic. I am running BRO IDS, grabbing the connection log file with logstash and sending it to my ES cluster to **index =\> "logstash-bro-conn-%{+YYYY.MM.dd}"**  
. I tried to created a template called logstash-bro-conn to specify the field types that are coming from the bro log to set the field mapping. I am trying to have this template apply to the new daily index that is created " **logstash-bro-conn-YYYYMMDD**"

**I created the template with the following**

**\_PUT _template/logstash-bro-conn_**  
{  
"order": 1,  
"template" : "logstash-bro-conn-\*",  
"settings": {  
"index": {  
"mappings": {  
"ts": { "type": "date" },  
"uid": { "type": "string" },  
"id\_resp\_h": { "type": "ip" },  
"id\_resp\_p": { "type": "int" },  
"id\_orig\_h": { "type": "ip" },  
"id\_orig\_p": { "type": "int" },  
"proto": { "type": "string" },  
"duration": { "type": "long" },  
"local\_orig": { "type": "bool" },  
"conn\_state": { "type": "string" },  
"history": { "type": "string" },  
"local\_resp": { "type": "bool" },  
"missed\_bytes": { "type": "byte" },  
"orig\_bytes": { "type": "byte" },  
"orig\_cc": { "type": "string" },  
"orig\_ip\_bytes": { "type": "byte" },  
"orig\_pkts": { "type": "long" },  
"resp\_bytes": { "type": "byte" },  
"resp\_cc": { "type": "string" },  
"resp\_ip\_bytes": { "type": "byte" },  
"resp\_pkts": { "type": "long" },  
"sensorname": { "type": "string" },  
"service": { "type": "string" },  
"tunnel\_parents": { "type": "string" }  
},  
"refresh\_interval": "30s",  
"number\_of\_shards": "2",  
"number\_of\_replicas": "2"  
},

---

<div class="post-metadata">

**Author:** ![dloyd](https://avatars.discourse-cdn.com/v4/letter/d/4491bb/32.png) [@dloyd](https://discuss.elastic.co/u/dloyd)\
**Post date:** [March 16, 2016, 4:00pm UTC](https://discuss.elastic.co/t/trouble-with-template-and-field-mapping/44585/2 "2016-03-16T16:00:23Z")

</div>

**When I look at the index settings all of the field types seem to be set**

**\_GET logstash-bro-conn-2016.03.16/_settings_**

{  
"logstash-bro-conn-2016.03.16": {  
"settings": {  
"index": {  
"mappings": {  
"resp\_pkts": {  
"type": "long"  
},  
"resp\_cc": {  
"type": "string"  
},  
"orig\_cc": {  
"type": "string"  
},  
"sensorname": {  
"type": "string"  
},  
"id\_orig\_p": {  
"type": "int"  
},  
"duration": {  
"type": "long"  
},  
"local\_resp": {  
"type": "bool"  
},  
"_default_": {  
"dynamic\_templates": [  
{  
"message\_field": {  
"match": "message",  
"match\_mapping\_type": "string",  
"mapping": {  
"index": "analyzed",  
"omit\_norms": "true",  
"fielddata": {  
"format": "disabled"  
},  
"type": "string"  
}  
}  
},  
{

```
              }
            }
          }
        ],
        "_all": {
          "omit_norms": "true",
          "enabled": "true"
        },
        "properties": {
          "@version": {
            "type": "string",
            "index": "not_analyzed",
            "doc_values": "true"
          },
          "@timestamp": {
            "type": "date",
            "doc_values": "true"
          },
          "geoip": {
            "type": "object",
            "dynamic": "true",
            "properties": {
              "location": {
                "type": "geo_point",
                "doc_values": "true"
              },
              "ip": {
                "type": "ip",
                "doc_values": "true"
              },
              "latitude": {
                "type": "float",
                "doc_values": "true"
              },
              "longitude": {
                "type": "float",
                "doc_values": "true"
              }
            }
          }
        }
      },
      "uid": {
        "type": "string"
      },
      "conn_state": {
        "type": "string"
      },
      "id_orig_h": {
        "type": "ip"
      },
      "id_resp_h": {
        "type": "ip"
      },
      "id_resp_p": {
        "type": "int"
      },
      "resp_ip_bytes": {
        "type": "byte"
      },
      "orig_bytes": {
        "type": "byte"
      },
      "local_orig": {
        "type": "bool"
      },
      "orig_ip_bytes": {
        "type": "byte"
      },
      "orig_pkts": {
        "type": "long"
      },
      "history": {
        "type": "string"
      },
      "missed_bytes": {
        "type": "byte"
      },
      "tunnel_parents": {
        "type": "string"
      },
      "resp_bytes": {
        "type": "byte"
      },
      "service": {
        "type": "string"
      },
      "proto": {
        "type": "string"
      },
      "ts": {
        "type": "date"
      }
    },
    "refresh_interval": "30s",
    "number_of_shards": "2",
    "creation_date": "1458141964034",
    "number_of_replicas": "2",
    "uuid": "K8tWMImQSSeEDjp8-8_d5w",
    "version": {
      "created": "2020099"
    }
  }
}

```

}

---

<div class="post-metadata">

**Author:** ![dloyd](https://avatars.discourse-cdn.com/v4/letter/d/4491bb/32.png) [@dloyd](https://discuss.elastic.co/u/dloyd)\
**Post date:** [March 16, 2016, 4:04pm UTC](https://discuss.elastic.co/t/trouble-with-template-and-field-mapping/44585/3 "2016-03-16T16:04:24Z")

</div>

**When I look at the mappings for the index none of the mapping that were set in the template are correct**

**\_GET logstash-bro-conn-2016.03.16/_mapping_**

{  
"logstash-bro-conn-2016.03.16": {  
"mappings": {  
"_default_": {  
"\_all": {  
"enabled": true,  
"omit\_norms": true  
},

```
      "id_resp_h": {
        **"type": "string"** ,
        "norms": {
          "enabled": false

      "id_resp_p": {
        **"type": "string"** ,
        "norms": {
          "enabled": false
       
        }
      },
      "local_orig": {
        **"type": "string",**
        "norms": {
          "enabled": false
        },

```

/////////

Thanks in advance!

David

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:07pm UTC](https://discuss.elastic.co/t/trouble-with-template-and-field-mapping/44585/4 "2017-07-05T23:07:52Z")

</div>


