Mappings
Add fields and sub-fields in place, and change existing fields safely with a generated reindex routine.
Open an index and go to its Mapping tab (or the Mapping tab of the Index view). Every field is listed with its type and details — sub-fields like title.raw sit under their parent. Use the filter to find a field, or Raw JSON to see the mapping as Elasticsearch returns it.
Elasticsearch can add fields to an existing index at any time, but it can’t change the type or analysis of a field that already holds data. kabanos follows that rule: additions apply immediately, anything else goes through a reindex.
Add a field
Click + Add field:
- Field name — dotted paths are fine:
seller.phonecreates thesellerobject if it doesn’t exist. - Add as sub-field of — pick an existing field to add a multi-field, e.g. a
keywordsub-field under atextfield. - Type — 24 types:
keyword,text,long,integer,short,double,float,scaled_float,boolean,date,date_nanos,ip,geo_point,geo_shape,object,nested,flattened,dense_vector,wildcard,constant_keyword,search_as_you_type,match_only_text,version,binary. - Type-specific options appear as needed: Analyzer for text types (including the index’s own analyzers), ignore_above for keyword, Format for dates, scaling_factor for scaled floats and dims for vectors.
- Also add a .keyword sub-field — on by default for
textfields, so you can sort and aggregate on them. - Extra parameters (JSON) — anything else, e.g.
{"index": false}. - Index existing documents into it now — runs
_update_by_queryin the background so documents already in the index get the new field. Without it, only new and updated documents are indexed into it. Follow the task in Stack management → Tasks.
The field is added with PUT <index>/_mapping.
Change or remove a field
Click Edit on a field (or Edit JSON for the whole mapping) and click Review change. If you only added fields, it applies in place. If you changed or removed an existing field, kabanos explains that it needs a reindex and lists what is Changed, Removed and Added. You then choose:
- Try in place — a few parameters (like
ignore_above) can be updated on an existing field. If Elasticsearch rejects the change, you’ll see why. Not offered when you removed a field. - Create reindex routine — the safe way. Enter the New index name (it’s suggested for you:
listings-v7→listings-v8,logs→logs-v2).
The generated reindex routine
kabanos builds a routine that you review before running:
- Cluster is healthy — asserts the status isn’t red.
- Count source documents — captures the count.
- Create the new index with the new mapping — copying the shard and replica counts, refresh interval, analysis,
max_result_window, field limit, codec, index sorting, lifecycle policy and similarity settings. - Start reindex — in the background, capturing the task id.
- Wait for the reindex task — polls every 5 seconds until it completes, and fails if it reports an error.
- Verify document count — asserts the new index has as many documents as the source.
- Move aliases to the new index — only if the index has aliases, and it asks before running.
Every step stops the routine on failure. The source index is never deleted — remove it yourself once you’re happy. Use Dry run first to see exactly what would be sent.
Template mappings
Template mappings work differently because templates only affect indices created later — see Aliases & templates.