# \_data\_stream\_timestamp conflicts?

**URL:** <https://discuss.elastic.co/t/data-stream-timestamp-conflicts/287814>\
**Category:** Elasticsearch\
**Tags:** datastreams\
**Created:** [October 27, 2021, 3:45pm UTC](https://discuss.elastic.co/t/data-stream-timestamp-conflicts/287814 "2021-10-27T15:45:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![TimWardFS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timwardfs/32/65108_2.png) [@TimWardFS](https://discuss.elastic.co/u/TimWardFS)\
**Post date:** [October 27, 2021, 3:45pm UTC](https://discuss.elastic.co/t/data-stream-timestamp-conflicts/287814/1 "2021-10-27T15:45:38Z")

</div>

Does anyone know what this means please? I get this on every attempt Logstash makes to index an event.

```auto
"status"=>400,
"error"=>{"type"=>"illegal_argument_exception",
"reason"=>"Mapper for [_data_stream_timestamp] conflicts with existing mapper:\n\tCannot update parameter [enabled] from [true] to [false]"

```

This my first attempt to use a "data stream". I don't know what \_data\_stream\_timestamp is, I haven't set it to anything, and I can't find any documentation on it.

The Logstash output configuration is

```auto
    output {
      elasticsearch {
        hosts => ["...:9200"]
        ilm_rollover_alias => "filebeat"
        ilm_pattern => "000001"
        ilm_policy => "filebeat-ilm-policy"
        document_type => "log"
        user => "elastic"
        password => "${ELASTIC_PASSWORD}"
        manage_template => false
        action => "create"
      }
    }

```

---

<div class="post-metadata">

**Author:** ![TimWardFS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timwardfs/32/65108_2.png) [@TimWardFS](https://discuss.elastic.co/u/TimWardFS)\
**Post date:** [October 28, 2021, 10:58am UTC](https://discuss.elastic.co/t/data-stream-timestamp-conflicts/287814/2 "2021-10-28T10:58:56Z")

</div>

Well, I've fixed it. I'm not sure what I did, but the addition of the previously missing `template.settings.index.lifecycle.name` from the index template might have been what made the difference.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 25, 2021, 10:59am UTC](https://discuss.elastic.co/t/data-stream-timestamp-conflicts/287814/3 "2021-11-25T10:59:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
