# Change mapping question

**URL:** <https://discuss.elastic.co/t/change-mapping-question/110451>\
**Category:** Elasticsearch\
**Created:** [December 6, 2017, 3:31am UTC](https://discuss.elastic.co/t/change-mapping-question/110451 "2017-12-06T03:31:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![peterch](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@peterch](https://discuss.elastic.co/u/peterch)\
**Post date:** [December 6, 2017, 3:31am UTC](https://discuss.elastic.co/t/change-mapping-question/110451/1 "2017-12-06T03:31:50Z")

</div>

Dear All,

I would like change one of the field type from "text" to "IP" for geoip use but fail. May i know how to do that. Thanks

GET /syslog/\_mapping  
{  
"syslog": {  
"mappings": {  
"doc": {  
"properties": {  
"@timestamp": {  
"type": "date"  
},  
"@version": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Description": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Destination IP": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Destination Port": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Signature ID": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Signature IS": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Signature Name": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Signature Severity": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"Source IP": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
}  
}  
}  
}  
}  
}

Tried to change source IP type from text to IP by following  
PUT /syslog  
{  
"properties": {  
"Destination IP": {  
"type": "IP",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
}  
}  
}

Result

{  
"error": {  
"root\_cause": [  
{  
"type": "illegal\_argument\_exception",  
"reason": "unknown setting [index.properties.Destination IP.fields.keyword.ignore\_above] please check that any required plugins are installed, or check the breaking changes documentation for removed settings"  
}  
],  
"type": "illegal\_argument\_exception",  
"reason": "unknown setting [index.properties.Destination IP.fields.keyword.ignore\_above] please check that any required plugins are installed, or check the breaking changes documentation for removed settings"  
},  
"status": 400  
}

---

<div class="post-metadata">

**Author:** ![mujtabahussain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mujtabahussain/32/17514_2.png) [@mujtabahussain](https://discuss.elastic.co/u/mujtabahussain)\
**Post date:** [December 6, 2017, 4:35am UTC](https://discuss.elastic.co/t/change-mapping-question/110451/2 "2017-12-06T04:35:14Z")

</div>

This section is particularly relevant from [here](https://www.elastic.co/blog/changing-mapping-with-zero-downtime), even though the post is old.

> [@](#):
>
> Elasticsearch (and Lucene) stores its indices in immutable segments — each segment is a “mini" inverted index. These segments are never updated in place. Updating a document actually creates a new document and marks the old document as deleted. As you add more documents (or update existing documents), new segments are created. A merge process runs in the background merging several smaller segments into a new big segment, after which the old segments are removed entirely.
> 
> Typically, an index in Elasticsearch will contain documents of different types. Each \_type has its own schema or mapping. A single segment may contain documents of any type. **So, if you want to change the field definition for a single field in a single type, you have little option but to reindex all of the documents in your index**.

It's far easier to simply add a new field with the correct mapping and then send the data to it.

---

<div class="post-metadata">

**Author:** ![peterch](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@peterch](https://discuss.elastic.co/u/peterch)\
**Post date:** [December 7, 2017, 3:33am UTC](https://discuss.elastic.co/t/change-mapping-question/110451/3 "2017-12-07T03:33:03Z")

</div>

Thanks for your reply. I success to change type after delete the mapping and PUT again. However, the old data cannot search

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2018, 3:33am UTC](https://discuss.elastic.co/t/change-mapping-question/110451/4 "2018-01-04T03:33:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
