# Alerting is not working for unexisting \_doc type

**URL:** <https://discuss.elastic.co/t/alerting-is-not-working-for-unexisting-doc-type/193367>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [August 1, 2019, 3:46pm UTC](https://discuss.elastic.co/t/alerting-is-not-working-for-unexisting-doc-type/193367 "2019-08-01T15:46:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![evalufran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evalufran/32/53286_2.png) [@evalufran](https://discuss.elastic.co/u/evalufran)\
**Post date:** [August 1, 2019, 3:46pm UTC](https://discuss.elastic.co/t/alerting-is-not-working-for-unexisting-doc-type/193367/1 "2019-08-01T15:46:46Z")

</div>

Hi everyone, i noticed that alerting is not working if i use a costum dynamic template.

After having created a query on a watcher i'm not able to create a trigger, here's the message from extraction query:

`Failed to parse mapping [_doc]: Root mapping definition has unsupported parameters: [_doc : {dynamic_templates=[{message_text={path_match=message, mapping={type=text}}}, {cust_msg_text={path_match=cust_msg, mapping={type=text}}}, {payload_text={path_match=payload*, mapping={type=text}}}, {playload={path_match=playload*, mapping={type=text}}}, {timestamp_fix={path_match=timestamp, mapping={format=YYYY MMM dd HH:mm:ss:SSS||YYYY-MM-dd HH:mm:ss.SSZZ||YYYY-MM-dd'T'HH:mm:ss.SSSZZ||YYY-MM-dd'T'HH:mm:ss.SZZ||YYY-MM-dd'T'HH:mm:ss.SZ||YYYY-MM-dd'T'HH:mm:ss,SZZ||YYYY-MM-dd'T'HH:mm:ss.SSSz||YYYY-MM-dd'T'HH:mm:ss.Sz||YYYY-MM-dd'T'HH:mm:ss.SSz||YYYY-MM-dd'T'HH:mm:ss,SSSz||YYYY-MM-dd'T'HH:mm:ss,Sz||YYYY-MM-dd'T'HH:mm:ss,SSz||YYYY-MM-dd'T'HH:mm:ssz, type=date}}}]}]`

As for my custum template:

```
{
    "index_patterns": [
      "*"
    ],
    "order": 0,
    "mappings": {
      "dynamic_templates": [
        {
          "message_text": {
            "path_match": "message",
            "mapping": {
              "type": "text"
            }
          }
        },
        {
          "cust_msg_text": {
            "path_match": "cust_msg",
            "mapping": {
              "type": "text"
            }
          }
        },
        {
          "payload_text": {
            "path_match": "payload*",
            "mapping": {
              "type": "text"
            }
          }
        },
        {
          "playload": {
            "path_match": "playload*",
            "mapping": {
              "type": "text"
            }
          }
        },
        {
          "timestamp_fix": {
            "path_match": "timestamp",
            "mapping": {
              "type": "date",
              "format": "YYYY MMM dd HH:mm:ss:SSS||YYYY-MM-dd HH:mm:ss.SSZZ||YYYY-MM-dd'T'HH:mm:ss.SSSZZ||YYY-MM-dd'T'HH:mm:ss.SZZ||YYY-MM-dd'T'HH:mm:ss.SZ||YYYY-MM-dd'T'HH:mm:ss,SZZ||YYYY-MM-dd'T'HH:mm:ss.SSSz||YYYY-MM-dd'T'HH:mm:ss.Sz||YYYY-MM-dd'T'HH:mm:ss.SSz||YYYY-MM-dd'T'HH:mm:ss,SSSz||YYYY-MM-dd'T'HH:mm:ss,Sz||YYYY-MM-dd'T'HH:mm:ss,SSz||YYYY-MM-dd'T'HH:mm:ssz"
            }
          }
        }
      ]
    }
  }

```

As you can see in mapping there is not \_doc which is deprecated,  
I think this might be a bug

Best regards

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 1, 2019, 7:27pm UTC](https://discuss.elastic.co/t/alerting-is-not-working-for-unexisting-doc-type/193367/2 "2019-08-01T19:27:58Z")

</div>

you wrote alerting in the subject, but monitoring in the body. Can you be more clear?

Also, can you share the template? Especially the patterns you are applying it to?

Thanks!

--Alex

---

<div class="post-metadata">

**Author:** ![evalufran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evalufran/32/53286_2.png) [@evalufran](https://discuss.elastic.co/u/evalufran)\
**Post date:** [August 2, 2019, 7:59am UTC](https://discuss.elastic.co/t/alerting-is-not-working-for-unexisting-doc-type/193367/3 "2019-08-02T07:59:30Z")

</div>

Hi!  
Thank you for replying!!  
i updated my issue and i shared my template!

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 2, 2019, 8:04am UTC](https://discuss.elastic.co/t/alerting-is-not-working-for-unexisting-doc-type/193367/4 "2019-08-02T08:04:54Z")

</div>

do not use `index_patterns: [*]`, this means that you index pattern will also be applied to the internal elastic indices used by security, alerting and monitoring. Always specify a proper index pattern with a prefix.

---

<div class="post-metadata">

**Author:** ![evalufran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evalufran/32/53286_2.png) [@evalufran](https://discuss.elastic.co/u/evalufran)\
**Post date:** [August 2, 2019, 8:30am UTC](https://discuss.elastic.co/t/alerting-is-not-working-for-unexisting-doc-type/193367/5 "2019-08-02T08:30:47Z")

</div>

Thank you for your quick reply, im trying to use a regexp for negative look behind to exclude index names starting with point, i tried this one: `"^(?!\\.).*"` but it doesn't work, do you have any hint?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 2, 2019, 8:42am UTC](https://discuss.elastic.co/t/alerting-is-not-working-for-unexisting-doc-type/193367/6 "2019-08-02T08:42:51Z")

</div>

this does not support the full complexity of regexes, just simple patterns, as performance is important here - backtracking would reduce that performance very likely significantly

---

<div class="post-metadata">

**Author:** ![evalufran](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evalufran/32/53286_2.png) [@evalufran](https://discuss.elastic.co/u/evalufran)\
**Post date:** [August 2, 2019, 9:06am UTC](https://discuss.elastic.co/t/alerting-is-not-working-for-unexisting-doc-type/193367/7 "2019-08-02T09:06:13Z")

</div>

Thank you very very very much!  
Everything works now!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2019, 9:06am UTC](https://discuss.elastic.co/t/alerting-is-not-working-for-unexisting-doc-type/193367/8 "2019-08-30T09:06:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
