# Anomaly detection - Elastic Jobs failing to start

**URL:** <https://discuss.elastic.co/t/anomaly-detection-elastic-jobs-failing-to-start/220015>\
**Category:** SIEM\
**Tags:** elastic-stack-machine-learning\
**Created:** [February 19, 2020, 4:03pm UTC](https://discuss.elastic.co/t/anomaly-detection-elastic-jobs-failing-to-start/220015 "2020-02-19T16:03:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![KevSex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevsex/32/29031_2.png) [@KevSex](https://discuss.elastic.co/u/KevSex)\
**Post date:** [February 19, 2020, 4:03pm UTC](https://discuss.elastic.co/t/anomaly-detection-elastic-jobs-failing-to-start/220015/1 "2020-02-19T16:03:20Z")

</div>

When I attempt to create an ML job using one of the pre-defined jobs for instance "windows\_rare\_user\_type10\_remote\_login", I receive the below error:

```auto
[status_exception] [datafeed-windows_rare_user_type10_remote_login] cannot retrieve field [@timestamp] because it has no mappings

```

I am using the default winlogbeat index template which shows the mapping for `@timestamp` is set correctly.

```auto
      "@timestamp": {
        "type": "date"
      },

```

Any ideas?

---

<div class="post-metadata">

**Author:** ![richcollier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/richcollier/32/115035_2.png) [@richcollier](https://discuss.elastic.co/u/richcollier)\
**Post date:** [February 20, 2020, 11:53am UTC](https://discuss.elastic.co/t/anomaly-detection-elastic-jobs-failing-to-start/220015/2 "2020-02-20T11:53:26Z")

</div>

There's a mapping clash in there somewhere...check the following:

Get the name of the index pattern the datafeed is configured to use:

```auto
GET _ml/datafeeds/datafeed-windows_rare_user_type10_remote_login

```

You're looking for what is defined in the `indices` section, for example:

```auto
      "indices" : [
        "myindexname-*"
      ],

```

Then, determine the mappings for that _exact name_ index pattern (including the wildcards, if any):

```auto
GET myindexname-*/_mapping

```

Post the results here so we can see

---

<div class="post-metadata">

**Author:** ![KevSex](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevsex/32/29031_2.png) [@KevSex](https://discuss.elastic.co/u/KevSex)\
**Post date:** [February 21, 2020, 8:55pm UTC](https://discuss.elastic.co/t/anomaly-detection-elastic-jobs-failing-to-start/220015/3 "2020-02-21T20:55:04Z")

</div>

Hey Rich,

Thanks for pointing me in the right direction. The mapping I use was different from the default specified in the datafeed.

After updating using the below API call, I was successfully able to start the job.

```auto
POST _ml/datafeeds/datafeed-windows_rare_user_type10_remote_login/_update
{
"indices": ["<new-index-name>"]
}

```

Cheers,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2020, 8:55pm UTC](https://discuss.elastic.co/t/anomaly-detection-elastic-jobs-failing-to-start/220015/4 "2020-03-20T20:55:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
