# 7.9: "....creating index, cause \[auto(bulk api)\],..." ignores null\_values set in legacy index template

**URL:** <https://discuss.elastic.co/t/7-9-creating-index-cause-auto-bulk-api-ignores-null-values-set-in-legacy-index-template/251463>\
**Category:** Elasticsearch\
**Created:** [October 8, 2020, 2:22pm UTC](https://discuss.elastic.co/t/7-9-creating-index-cause-auto-bulk-api-ignores-null-values-set-in-legacy-index-template/251463 "2020-10-08T14:22:28Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jze](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jze/32/47285_2.png) [@jze](https://discuss.elastic.co/u/jze)\
**Post date:** [October 8, 2020, 2:22pm UTC](https://discuss.elastic.co/t/7-9-creating-index-cause-auto-bulk-api-ignores-null-values-set-in-legacy-index-template/251463/1 "2020-10-08T14:22:29Z")

</div>

Excerpt from template:  
(Ruby hash)

```auto
index_patterns: [
  "ldb-dvm-*",
],
order: 200,
...
...
aliases: {
  'ldb-dvm' => {},
},
mappings: {
  _source: {
    enabled: true,
  },
  dynamic_templates: [{
    strings: {
      match: '*',
      match_mapping_type: 'string',
      mapping: {
        type: 'text', fields: { raw: { type: 'keyword', ignore_above: 256 } },
      },
    },
  },],
  properties: {
    '@timestamp' => { type: 'date', doc_values: true },
    '@version' => { type: 'keyword' },
    :environment => { type: 'text', fielddata: true },
    :application => { type: 'text', fields: { keyword: { type: 'keyword', ignore_above: 256 } } },
    :host => { type: 'text', fields: { keyword: { type: 'keyword', ignore_above: 256 } } },
    :host_ip => { type: 'ip', doc_values: true, null_value: '127.0.0.1' },
    :type => { type: 'text', fields: { keyword: { type: 'keyword', ignore_above: 256 } } },
    :type_group => { type: 'text', fields: { keyword: { type: 'keyword', ignore_above: 256 } } },
    ...
    ...

```

This template is created via REST API **BEFORE** any such index is created.  
And after that this appears in the elasticsearch log (excerpt):

```auto
[ldb-dvm-system-2020.10.08] creating index, cause [auto(bulk api)], templates [ldb-dvm-environment], shards [1]/[0]
Cluster health status changed from [YELLOW] to [GREEN] (reason: [shards started [[ldb-dvm-system-2020.10.08][0]]]).
[ldb-dvm-system-2020.10.08/HndQQ8J9TrGfTNyy_USBNA] update_mapping [_doc]
[ldb-dvm-system-2020.10.08] [[ldb-dvm-system-2020.10.08/HndQQ8J9TrGfTNyy_USBNA]] failed to apply mappings
java.lang.IllegalArgumentException: Mapper for [host_ip] conflicts with existing mapping:
[mapper [host_ip] has different [null_value] values]
        at org.elasticsearch.index.mapper.FieldMapper.merge(FieldMapper.java:308) ~[elasticsearch-7.9.0.jar:7.9.0]
...
...

```

So it says the index was autocreated based on the ldb-dvm-environment template which is the one above, right?  
When I checked the mapping of the index template, the null\_value was set in its mapping.

If I remove the null\_value from the template, the error does not appear.

Now how do I force ELK to use the mappings from the template during index creation?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2020, 2:22pm UTC](https://discuss.elastic.co/t/7-9-creating-index-cause-auto-bulk-api-ignores-null-values-set-in-legacy-index-template/251463/2 "2020-11-05T14:22:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
