# Can not create an index

**URL:** <https://discuss.elastic.co/t/can-not-create-an-index/258055>\
**Category:** Logstash\
**Created:** [December 8, 2020, 9:42pm UTC](https://discuss.elastic.co/t/can-not-create-an-index/258055 "2020-12-08T21:42:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![zaeemmasood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zaeemmasood/32/102383_2.png) [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Post date:** [December 8, 2020, 9:42pm UTC](https://discuss.elastic.co/t/can-not-create-an-index/258055/1 "2020-12-08T21:42:36Z")

</div>

Hi. I am trying to create a new index in Kibana. My logstash conf file looks like below:

```auto
       if [type] == "uatelectron_appLog" {
                mutate {
                        split => ["message", "|"]
                        add_field =>{
                          "timestamp" => "%{[message][0]}"
                          "requestId" => "%{[message][1]}"
                          "requestType" => "%{[message][2]}"
                          "environment" => "%{[message][3]}"
                          "version" => "%{[message][4]}"
                          "service" => "%{[message][5]}"
                          "RegionSsoid" => "%{[message][6]}"
                          "detail" => "%{[message][7]}"
                          "detailName" => "%{[message][8]}"
                          "detailValue" => "%{[message][9]}"
                          "other" => "%{[message][10]}"
                       }
                }
                grok{
                        patterns_dir => ["/opt/gp/portal/elasticsearch/app/logstash/patterns"]
                        match => ["reqID","%{GREEDYDATA}%{REQUEST_ID:requestId}"]
                }
                date{
                        match => ["timestamp", "yyyy-MM-dd'T'HH:mm:ss.SSS'Z'"]
                }
               }
        mutate{
                add_field =>{ "_ELKId" => "%{@timestamp}%{offset}" }
        }
        mutate{
              convert => {
                          "timestamp" => "string"
                          "requestId" => "string"
                          "requestType" => "string"
                          "Region" => "string"
                   }
              }

```

I see the following error in the log when message is pushed through filebeat:

```auto
[2020-12-08T10:04:17,691][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"uatelectron_applog-2020.12.08", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x127f9e22>], :response=>{"index"=>{"_index"=>"uat_cv_electron_applog-2020.12.08", "_type"=>"_doc", "_id"=>"3H_hQnYBZDd5lC9rt2fO", "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"mapper [message] of different type, current_type [text], merged_type [date]"}}}}

```

Please help suggest a solution.

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 8, 2020, 9:55pm UTC](https://discuss.elastic.co/t/can-not-create-an-index/258055/2 "2020-12-08T21:55:57Z")

</div>

> [@zaeemmasood](#):
>
> `mapper [message] of different type, current_type [text], merged_type [date]`

It looks like you have a mapping mismatch. Can you add a `stdout` in the output to see if you can catch the message causing this?

---

<div class="post-metadata">

**Author:** ![zaeemmasood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zaeemmasood/32/102383_2.png) [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Post date:** [December 8, 2020, 10:22pm UTC](https://discuss.elastic.co/t/can-not-create-an-index/258055/3 "2020-12-08T22:22:00Z")

</div>

Hi Mark,

Sure. Can you please let me know how to add stdout in the output?

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [December 8, 2020, 10:22pm UTC](https://discuss.elastic.co/t/can-not-create-an-index/258055/4 "2020-12-08T22:22:45Z")

</div>

[https://www.elastic.co/guide/en/logstash/current/plugins-outputs-stdout.html](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-stdout.html) goes into that.

---

<div class="post-metadata">

**Author:** ![zaeemmasood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zaeemmasood/32/102383_2.png) [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Post date:** [December 9, 2020, 5:42pm UTC](https://discuss.elastic.co/t/can-not-create-an-index/258055/5 "2020-12-09T17:42:08Z")

</div>

Thanks. Will try that

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 6, 2021, 5:42pm UTC](https://discuss.elastic.co/t/can-not-create-an-index/258055/6 "2021-01-06T17:42:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
