# Default \_ttl causes MapperParsingException due to already expired document

**URL:** <https://discuss.elastic.co/t/default--ttl-causes-mapperparsingexception-due-to-already-expired-document/17413>\
**Category:** Elasticsearch\
**Created:** [May 8, 2014, 5:17pm UTC](https://discuss.elastic.co/t/default--ttl-causes-mapperparsingexception-due-to-already-expired-document/17413 "2014-05-08T17:17:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mallox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mallox/32/1580_2.png) [@mallox](https://discuss.elastic.co/u/mallox)\
**Post date:** [May 8, 2014, 5:17pm UTC](https://discuss.elastic.co/t/default--ttl-causes-mapperparsingexception-due-to-already-expired-document/17413/1 "2014-05-08T17:17:23Z")

</div>

I have a river importing data from Big Query and I import it into an index  
via bulk that has a default \_ttl of 30 days configured. I don't set the ttl  
anywhere on the document when importing, so every document should just get  
the ttl set from the default value.

Unfortunately though I keep getting exceptions such as this one:

2014-05-08 00:04:54,819][DEBUG][action.index] [prod\_log\_3]  
[prod\_-2014.05.08][4], node[7iHEb2ciTsGSaR3LxKbw8w], [P], s[STARTED]:  
Failed to execute [index  
{[prod\_-2014.05.08][logging][g-6CRDhSS2OksWfF3OpCTg],  
source[{"message":"Message returned successfully. Size:  
2","timestamp":"1399507397000","level":"INFO","mdc":"{"time\_received":"1399507397320","time\_responded":"1399507397333","user\_device":""xxx"","response\_length":"2","user\_anchor":"0","response\_size":"2","returned\_models":"0","user\_tag":""production"","user\_model":""5.06""}","thread":"Request  
717C91C3","logger":my.pkg.Servlet"}]}]  
org.elasticsearch.index.mapper.MapperParsingException: failed to parse  
[\_ttl]  
at  
org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(AbstractFieldMapper.java:418)  
at  
org.elasticsearch.index.mapper.internal.TTLFieldMapper.postParse(TTLFieldMapper.java:177)  
at  
org.elasticsearch.index.mapper.DocumentMapper.parse(DocumentMapper.java:523)  
at  
org.elasticsearch.index.mapper.DocumentMapper.parse(DocumentMapper.java:462)  
at  
org.elasticsearch.index.shard.service.InternalIndexShard.prepareCreate(InternalIndexShard.java:363)  
at  
org.elasticsearch.action.index.TransportIndexAction.shardOperationOnPrimary(TransportIndexAction.java:215)  
at  
org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction.performOnPrimary(TransportShardReplicationOperationAction.java:556)  
at  
org.elasticsearch.action.support.replication.TransportShardReplicationOperationAction$AsyncShardOperationAction$1.run(TransportShardReplicationOperationAction.java:426)  
at  
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)  
at  
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)  
at java.lang.Thread.run(Thread.java:744)  
Caused by: org.elasticsearch.index.AlreadyExpiredException: already expired  
[prod\_context\_eng-2014.05.08]/[logging]/[g-6CRDhSS2OksWfF3OpCTg] due to  
expire at [3991507494] and was processed at [1399507494819]  
at  
org.elasticsearch.index.mapper.internal.TTLFieldMapper.innerParseCreateField(TTLFieldMapper.java:215)  
at  
org.elasticsearch.index.mapper.core.NumberFieldMapper.parseCreateField(NumberFieldMapper.java:215)  
at  
org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(AbstractFieldMapper.java:408)  
... 10 more

The mapping for the index looks like this:

logging: {  
\_timestamp: {  
enabled: true  
},  
\_ttl: {  
enabled: true,  
default: 2592000000  
},  
properties: {  
timestamp: {  
type: string  
},  
message: {  
type: string  
},  
level: {  
type: string  
},  
mdc: {  
type: string  
},  
thread: {  
type: string  
},  
logger: {  
type: string  
}  
}  
}

I've checked if the clocks on each of the three nodes is in sync, and there  
was only negligible skew.  
The cluster is running ES version 1.1.1 on GCE using standard n1 instances  
with dedicated disks.

The connector used for nodes to find each other  
is [https://github.com/mallocator/Elasticsearch-GCE-Discovery](https://github.com/mallocator/Elasticsearch-GCE-Discovery)

The river used to import data  
is [https://github.com/mallocator/Elasticsearch-BigQuery-River](https://github.com/mallocator/Elasticsearch-BigQuery-River)

Any suggestions on what I can do to fix/improve this issue would be very  
welcome.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/dc0d6f32-fc06-4598-9f85-f78e6d342cb3%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/dc0d6f32-fc06-4598-9f85-f78e6d342cb3%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Benjamin\_Deveze](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjamin_deveze/32/1577_2.png) [@Benjamin\_Deveze](https://discuss.elastic.co/u/Benjamin_Deveze)\
**Post date:** [May 8, 2014, 6:17pm UTC](https://discuss.elastic.co/t/default--ttl-causes-mapperparsingexception-due-to-already-expired-document/17413/2 "2014-05-08T18:17:36Z")

</div>

Hi Ravi,

After a quick investigation I would say that the problem is here:

> <https://github.com/mallocator/Elasticsearch-BigQuery-River/blob/master/src/main/java/org/elasticsearch/river/bigquery/BigQueryRiver.java#L391>

The timestamp should be set in milliseconds so removing the / 1000 should  
solve your issue.

Hope this help

--  
Benjamin DEVEZE

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CABecc28Fa7eM\_ixGWzkkhw8c6ACOzc0FX-tkWf51uxFJKJBBbQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CABecc28Fa7eM_ixGWzkkhw8c6ACOzc0FX-tkWf51uxFJKJBBbQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![mallox](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mallox/32/1580_2.png) [@mallox](https://discuss.elastic.co/u/mallox)\
**Post date:** [May 8, 2014, 8:05pm UTC](https://discuss.elastic.co/t/default--ttl-causes-mapperparsingexception-due-to-already-expired-document/17413/3 "2014-05-08T20:05:09Z")

</div>

Wow, awesome! That was quick.

Thanks a lot.

On Thursday, May 8, 2014 11:17:36 AM UTC-7, Benjamin Devèze wrote:

> Hi Ravi,
> 
> After a quick investigation I would say that the problem is here:
> 
> [https://github.com/mallocator/Elasticsearch-BigQuery-River/blob/master/src/main/java/org/elasticsearch/river/bigquery/BigQueryRiver.java#L391](https://github.com/mallocator/Elasticsearch-BigQuery-River/blob/master/src/main/java/org/elasticsearch/river/bigquery/BigQueryRiver.java#L391)
> 
> The timestamp should be set in milliseconds so removing the / 1000 should  
> solve your issue.
> 
> Hope this help
> 
> --  
> Benjamin DEVEZE

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/24313452-97da-4dbd-af7a-1ed6003d93d8%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/24313452-97da-4dbd-af7a-1ed6003d93d8%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:30am UTC](https://discuss.elastic.co/t/default--ttl-causes-mapperparsingexception-due-to-already-expired-document/17413/4 "2017-07-06T01:30:41Z")

</div>


