# Change in document \_type?

**URL:** <https://discuss.elastic.co/t/change-in-document-type/107807>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 15, 2017, 7:01pm UTC](https://discuss.elastic.co/t/change-in-document-type/107807 "2017-11-15T19:01:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 15, 2017, 7:01pm UTC](https://discuss.elastic.co/t/change-in-document-type/107807/1 "2017-11-15T19:01:51Z")

</div>

I am ingesting both G1 and J9 garbage collection logs into elasticsearch. Filebeat sends them to kafka, and logstash pulls them in from there. I installed 6.0 GA this morning, and deleted data/nodes/0 before starting es. I am having an issue.

```
[2017-11-15T12:38:23,158][INFO][o.e.c.m.MetaDataCreateIndexService] [hostname][logs.g1gc-2017.11] creating index, cause [auto(bulk api)], templates [g1gc], shards [2]/[1], mappings [_default_]
[2017-11-15T12:38:23,292][INFO][o.e.c.m.MetaDataMappingService] [hostname] [logs.g1gc-2017.11/Be7hUystQYSw-tmIhWjDKg] create_mapping [doc]
[2017-11-15T12:38:23,315][INFO][o.e.c.m.MetaDataMappingService] [hostname] [logs.g1gc-2017.11/Be7hUystQYSw-tmIhWjDKg] update_mapping [doc]
[...]
[2017-11-15T12:38:30,281][DEBUG][o.e.a.a.i.m.p.TransportPutMappingAction] [hostname] failed to put mappings on indices [[[logs.g1gc-2017.11/Be7hUystQYSw-tmIhWjDKg]]], type [log]
java.lang.IllegalArgumentException: Rejecting mapping update to [logs.g1gc-2017.11] as the final mapping would have more than 1 type: [log, doc]
        at org.elasticsearch.index.mapper.MapperService.internalMerge(MapperService.java:494) ~[elasticsearch-6.0.0.jar:6.0.0]
```

I think the problem is that events from my server (just upgraded to 6.0 GA) are of type doc, and events coming from a colleague's 5.x box are of type log. Did that change in filebeat? I did not find it in a quick review of the release notes.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 16, 2017, 4:58am UTC](https://discuss.elastic.co/t/change-in-document-type/107807/2 "2017-11-16T04:58:31Z")

</div>

Yes, this did change. Elasticsearch 6.0 removed support for types: [https://www.elastic.co/guide/en/elasticsearch/reference/master/removal-of-types.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/removal-of-types.html) That mean in beats now the type that is used is the default type `doc`. I assume the file instances you use on the other boxes are before 5.6?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 16, 2017, 3:41pm UTC](https://discuss.elastic.co/t/change-in-document-type/107807/3 "2017-11-16T15:41:39Z")

</div>

Yes, he runs 5.4 if I recall correctly. He doesn't upgrade every two weeks like I do 😉

I can set document\_type on the es output in logstash to fix this.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 16, 2017, 11:11pm UTC](https://discuss.elastic.co/t/change-in-document-type/107807/4 "2017-11-16T23:11:38Z")

</div>

Great you have a workaround.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2017, 11:12pm UTC](https://discuss.elastic.co/t/change-in-document-type/107807/5 "2017-12-14T23:12:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
