# As the final mapping would have more than 1 type ERROR

**URL:** <https://discuss.elastic.co/t/as-the-final-mapping-would-have-more-than-1-type-error/115457>\
**Category:** Elasticsearch\
**Created:** [January 14, 2018, 9:11pm UTC](https://discuss.elastic.co/t/as-the-final-mapping-would-have-more-than-1-type-error/115457 "2018-01-14T21:11:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ramzey1981](https://avatars.discourse-cdn.com/v4/letter/r/d26b3c/32.png) [@ramzey1981](https://discuss.elastic.co/u/ramzey1981)\
**Post date:** [January 14, 2018, 9:11pm UTC](https://discuss.elastic.co/t/as-the-final-mapping-would-have-more-than-1-type-error/115457/1 "2018-01-14T21:11:47Z")

</div>

I had data going to ES from filebeats with no issues and then yesterday, I get tons of these errors for most of our rest-api services.

i looked at the filebeat debug output and see metadata type as doc. I looked at logstash in debug and I dont know were this other type is coming from. Has anybody else seent this with json documents?

[2018-01-14T20:59:36,323][DEBUG][o.e.a.b.TransportShardBulkAction] [application-2018.01.14][4] failed to execute bulk item (index) BulkShardRequest [[application-2018.01.14][4]] containing [index {[application-2018.01.14][doc][7P549mABJPWY86CHb3z9], source[{"request":{"agent":"java-sdk,0.1.0-dev.5709.uncommitted+sprint.d39eb72;Linux,3.10.0-514.16.1.el7.x86\_64,amd64;,,;SBM,0.1.0-dev.5709.uncommitted+sprint.d39eb72","route":"/organization/_/pipeline/_/account/_/state/_","method":"GET","size":"","resource":"/organization/xxxxxxxxxxx/pipeline/89xxxxx92-a4e8-/account/5-/state/featureExtractionState","addr":"xxxxxxx"},"offset":192733520,"log":"","level":"INFO","source":"/var/log/timeseries-service/rest-api/timeseries\_info","logsource":"timeseries-api@rest-api","version":"LATEST","tags":["leveled","leveled2"],"logtype":"application","@timestamp":"2018-01-14T20:59:34.618Z","response":{"size":165110,"status":200},"beat":{"name":"pre-prod-20171229-timeseries-api-02","hostname":"pre-prod-20171229-timeseries-api-02","version":"6.0.0"},"@version":"1","time":{"total":77},"index\_prefix":"application","levelcode":3}]}]  
java.lang.IllegalArgumentException: Rejecting mapping update to [application-2018.01.14] as the final mapping would have more than 1 type: [doc, bebf52d2-7d9d-4b4b-a31b-3779dc9d1c8a]

my filebeat file is as follows,

filebeat.prospectors:

- input\_type: log  
paths:
  - /var/log/java-gateway/java-gateway.log  
fields:  
logsource: java-gateway  
logtype: application  
fields\_under\_root: True  
json.keys\_under\_root: True  
json.message\_key: log  
json.overwrite\_keys: True

- input\_type: log  
paths:
  - /var/log/timeseries-service/rest-api/\*  
fields:  
logsource: timeseries-api@rest-api  
logtype: application  
version: LATEST  
fields\_under\_root: True  
json.keys\_under\_root: True  
json.message\_key: log  
json.overwrite\_keys: True  
output.redis:

# Array of hosts to connect to.
hosts: ["lxxxxx:6379"]  
ssl.enabled: false

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 14, 2018, 9:40pm UTC](https://discuss.elastic.co/t/as-the-final-mapping-would-have-more-than-1-type-error/115457/2 "2018-01-14T21:40:45Z")

</div>

Please format your code using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

It sounds like you are trying to send a weird doc type or that you already created it: `bebf52d2-7d9d-4b4b-a31b-3779dc9d1c8a`.

Run a `GET application-2018.01.14/_mapping` and see what you have yet.

May be a wrong index template.

---

<div class="post-metadata">

**Author:** ![ramzey1981](https://avatars.discourse-cdn.com/v4/letter/r/d26b3c/32.png) [@ramzey1981](https://discuss.elastic.co/u/ramzey1981)\
**Post date:** [January 15, 2018, 5:14pm UTC](https://discuss.elastic.co/t/as-the-final-mapping-would-have-more-than-1-type-error/115457/3 "2018-01-15T17:14:00Z")

</div>

thanks David,

sorry about the code formatting...

i did a Get on \_mapping on that index and you are correct i am getting an incorrect mapping but i'm trying to find out how. I dont set that in my template, Bascially I took the filebeat template and cloned it a few times one for services in our infrastructure and one for all the applications logging into our infrastructure. Looks like this particular application is sending json logs and I dont see how that is getting applied at the logstash layer or at the filebeat layer. It was also sending logs before and just stopped working.

```auto
{
  "application-2018.01.14": {
    "mappings": {
      "bebf52d2-7d9d-4b4b-a31b-3779dc9d1c8a": {
        "properties": {
          "@timestamp": {
            "type": "date"
          },

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [January 15, 2018, 5:29pm UTC](https://discuss.elastic.co/t/as-the-final-mapping-would-have-more-than-1-type-error/115457/4 "2018-01-15T17:29:53Z")

</div>

I can't tell you what. But for sure something is creating this mapping.

You can see it in elasticsearch logs. You should see either the index creation or the update mapping message. Then you'll get a date and that might give you a clue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 12, 2018, 5:30pm UTC](https://discuss.elastic.co/t/as-the-final-mapping-would-have-more-than-1-type-error/115457/5 "2018-02-12T17:30:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
