# Understanding the role of fields.yml

**URL:** <https://discuss.elastic.co/t/understanding-the-role-of-fields-yml/157854>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 22, 2018, 10:23am UTC](https://discuss.elastic.co/t/understanding-the-role-of-fields-yml/157854 "2018-11-22T10:23:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Martin\_H\_Andersen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martin_h_andersen/32/37348_2.png) [@Martin\_H\_Andersen](https://discuss.elastic.co/u/Martin_H_Andersen)\
**Post date:** [November 22, 2018, 10:23am UTC](https://discuss.elastic.co/t/understanding-the-role-of-fields-yml/157854/1 "2018-11-22T10:23:50Z")

</div>

My setup is this: filebeat -\> logstash -\> elasticsearch

I don't understand why filebeat is responsible for defining the fields mapping in elasticsearch.  
Fields can be altered in logstash? Giving new names.

We have a very fixed set of structured data we are logging should I load the mapping directly into ES? and how would I do that?

Thanks

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [November 22, 2018, 1:30pm UTC](https://discuss.elastic.co/t/understanding-the-role-of-fields-yml/157854/2 "2018-11-22T13:30:24Z")

</div>

Hello @Martin_H_Andersen,

In beats we try to provide an out of the box experience as much as possible in the scenario beats sending directly to Elasticsearch. Beats take care of any version upgrade, it make sure the index pattern is correct. The fields.yml is used to generate the elasticsearch JSON template.

Doing so allow us to create custom dashboard to visualize the information, because the fields will have the correct types.

When you are using Logstash, we consider this as a more advanced use case where user will either:

1. use the LS default dynamic template
2. create their own templates depending on the fields they have
3. will use a beat template as a starting point.

Concerning the point 3 and since you have custom fields you could use the command:

```auto
{beatname} export template > mytemplate.json

```

This will give you the template that the beat is using, you can modify it with your custom fields and push it to elasticsearch.

Do this answer your question?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2018, 1:30pm UTC](https://discuss.elastic.co/t/understanding-the-role-of-fields-yml/157854/3 "2018-12-20T13:30:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
