in a newly created ELK setup I have done the mistake of not explicitly setting the type to integer (or float) on some fields.
What do I need to do in Elasticsearch (and/or Kibana) after I have setup everything correct in Logstash with the grok or mutate filter? As far as I understand I need to completely erase the existing index and create it new. Is this correct? Or is there another way to do this? Just deleting only the fields I need to change?
What will happen if I change the type in Logstash without changing anything on the Elasticsearch index?
As far as I understand I need to completely erase the existing index and create it new. Is this correct? Or is there another way to do this? Just deleting only the fields I need to change?
Yes, you have to reindex. You can do that with Logstash (example configs have been posted in the past) or third-party tools like es-reindex. After reindexing to a new name (e.g. the original name with an underscore appended) you can delete the original index and create an alias named like the original index that points to the new index. Thereby everything will work as before.
What will happen if I change the type in Logstash without changing anything on the Elasticsearch index?
Then the next index that's created (the next day if you use daily indexes) will have the correct mappings.
And which is better to use grok or mutate?
Use for what, making a field an integer or float? Using the grok filter is typically easier, but not all fields are created by that filter.
Thanks again Magnus for the answer. You really helped me a lot for this setup! At least I have plan now :-).
One last question: What problems might arise when I do not change anything in Elasticsearch and do not reindex? (Only change the values in Logstash with grok and mutate? I have daily indexes (as recommended) and at the moment I do not care about the old data. The setup will be used in production sometime next week and old data is not of any interest at the moment.
As long as you don't attempt aggregations or range queries that span over days with both string values and integer/float values I you're going to be okay.
The type changed from the date on where I did the change. But as
expected the older data kept it's data type. The problem with this is
that you can not visualize any data with this correctly for this index
field.
As I wanted to avoid reindexing the whole data, I just changed the name
of the index field. But this only worked because the older data was not
important. Otherwise reindexing is a must.
Sorry for bumping an old thread but could you be so kind to explain exactly what you did to get it solved?
I need to change one field from 'string' to 'integer' (bytes filed from apache logs) but for some reason can't. I have added 'mutate { convert => { "bytes" => "integer" } }' to an appropriate logstash conf but see no result. Also tried to create a new index wth correct values but it seems that I have to somehow change the default index (logstash-*)...
I am fine with reindexing or/and removing all the data.
Feeling lot here
Probably worth creating your own thread, but offhand it appears that your searched the wrong field? Logstash creates a @timestamp field by default, not a date field. Perhaps you crated the date field though.
Why a new thread - the title is about re-indexing?
I took the example JSON from the Elastic Search article... I took your advice and changed the search field from "date" to "@timestamp" - but still no difference to my conflicted field in the Settings tab.
So I removed the search field altogether and ran:
GET /logstash-2016.05.*/_search?scroll=1m
{
"sort": ["_doc"],
"size": 1000
}
I have posted the same question in another thread "Number format Exception" but after read this thread i though it is related as well.
I have same issue recently. i have production index mapping where i defined "auid" as "string", then later on i found it should be "integer" so i created a new index with mapping "auid" as integer, then using reindex API to re-index data from old index to the newindex, but I am getting the exception below??
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.