Brian,

Thank you for the reply, even if it does not answer my question. 

By the way, how am I supposed to change a mapping setting? Do I have to push 
back the entire mapping with one line modified, or can I just push something 
like: 

{
  "logstash": {
     "mappings": {
        "_default_": {
           "_all": {
              "enabled": false
           }
        }
     }
  }
}



On 20 juin 2014, at 23:04, Brian wrote:

> Patrick,
> 
> Here's my template, along with where the _all field is disabled. You may wish 
> to add this setting to your own template, and then also add the index setting 
> to ignore malformed data (if someone's log entry occasionally slips in "null" 
> or "no-data" instead of the usual numeric value):
> 
> {
>   "automap" : {
>     "template" : "logstash-*",
>     "settings" : {
>       "index.mapping.ignore_malformed" : true
>     },
>     "mappings" : {
>       "_default_" : {
>         "numeric_detection" : true,
>         "_all" : { "enabled" : false },
>         "properties" : {
>           "message" : { "type" : "string" },
>           "host" : { "type" : "string" },
>           "UUID" : {  "type" : "string", "index" : "not_analyzed" },
>           "logdate" : {  "type" : "string", "index" : "no" }
>         }
>       }
>     }
>   }
> }
> 
> Brian

-- 
You received this message because you are subscribed to the Google Groups 
"elasticsearch" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to elasticsearch+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/elasticsearch/8D497ED9-54DF-48EA-AA91-44A621B72287%40patpro.net.
For more options, visit https://groups.google.com/d/optout.

Reply via email to