# Difference between type and \_type

**URL:** <https://discuss.elastic.co/t/difference-between-type-and--type/96058>\
**Category:** Elasticsearch\
**Created:** [August 7, 2017, 8:10am UTC](https://discuss.elastic.co/t/difference-between-type-and--type/96058 "2017-08-07T08:10:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![DFrant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dfrant/32/20512_2.png) [@DFrant](https://discuss.elastic.co/u/DFrant)\
**Post date:** [August 7, 2017, 8:10am UTC](https://discuss.elastic.co/t/difference-between-type-and--type/96058/1 "2017-08-07T08:10:42Z")

</div>

Hello,

I would like to know what's the difference between `type` and `_type` and how to define it?

Thanks.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 7, 2017, 8:35am UTC](https://discuss.elastic.co/t/difference-between-type-and--type/96058/2 "2017-08-07T08:35:35Z")

</div>

`_type` is an internal field which is set to the value of `my_type` in the following example:

```auto
PUT index/my_type/1
{
  "foo": "bar"
}

```

I don't know what you refer as `type`. Any link, context?

---

<div class="post-metadata">

**Author:** ![DFrant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dfrant/32/20512_2.png) [@DFrant](https://discuss.elastic.co/u/DFrant)\
**Post date:** [August 7, 2017, 9:06am UTC](https://discuss.elastic.co/t/difference-between-type-and--type/96058/3 "2017-08-07T09:06:37Z")

</div>

OK! just because I have to different `_type` for the same kind of data. And, I don't really understand why...

Here, `"_type": "log"`:

```
{
  "_index": "carxx-2017.07.02",
  "_type": "log",
  "_id": "AV2761sGfp2Rn6-j1rT1",
  "_version": 1,
  "_score": null,
  "_source": {
    "fulltx": "XM25",
    "offset": 31576132,
    "nndossier": "07031005239",
    "heurereponse": "213137",
    "input_type": "log",
    "source": "/opt/carxx/carxx_test1",
    "codetx": "25",
    "type": "log",
    "tags": [
      "beats_input_codec_plain_applied"
    ],
    "ins": "05000",
    "iin": "0136",
    "typetx": "XM",
    "carxxtimestamp": "170702213137",
    "@timestamp": "2017-07-02T19:31:37.000Z",
    "iout": "2724",
    "@version": "1",
    "beat": {
      "hostname": "elasticpoc",
      "name": "elasticpoc",
      "version": "5.5.1"
    },
    "host": "elasticpoc",
    "id": "01158284000",
    "nnutilisateur": "000000000000",
    "fields": {
      "env": "staging",
      "type": "carxx"
    }
  },
  "fields": {
    "@timestamp": [
      1499023897000
    ]
  },
  "sort": [
    1499023897000
  ]
}

```

and here `"_type": "doc"`:

```
{
  "_index": "filebeat-2017.08.07",
  "_type": "doc",
  "_id": "AV273s80fp2Rn6-j1p3B",
  "_version": 1,
  "_score": null,
  "_source": {
    "@timestamp": "2017-08-07T08:41:13.831Z",
    "beat": {
      "hostname": "elasticpoc",
      "name": "elasticpoc",
      "version": "5.5.1"
    },
    "fields": {
      "env": "staging",
      "type": "carxx"
    },
    "input_type": "log",
    "message": "01157774000170702213023%XM%00000000000070331015168480913213023050000080RRN0002W900500000000C0000000000000500024464063100100 33101516848 300 R00 ",
    "offset": 31462457,
    "source": "/opt/carxx/carxx_test1",
    "type": "log"
  },
  "fields": {
    "@timestamp": [
      1502095273831
    ]
  },
  "sort": [
    1502095273831
  ]
}
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 7, 2017, 9:26am UTC](https://discuss.elastic.co/t/difference-between-type-and--type/96058/4 "2017-08-07T09:26:33Z")

</div>

> [@DFrant](#):
>
> And, I don’t really understand why…

How could I know? I have no idea of what you are doing.

It sounds like you are injecting 2 kind of data:

- one coming from your app or may be from logstash? `carxx-2017.07.02`
- another source coming from filebeat: `filebeat-2017.08.07`

But, is the `_type` really a problem here?

I'd encourage you always using `doc` as the type name as type will be removed in the future.  
From 6.0 it defaults to `doc`.

---

<div class="post-metadata">

**Author:** ![DFrant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dfrant/32/20512_2.png) [@DFrant](https://discuss.elastic.co/u/DFrant)\
**Post date:** [August 7, 2017, 9:50am UTC](https://discuss.elastic.co/t/difference-between-type-and--type/96058/5 "2017-08-07T09:50:31Z")

</div>

Yes you are right. The problem was that both elasticsearch and logstash were enable in my filebeat configuration..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2017, 9:50am UTC](https://discuss.elastic.co/t/difference-between-type-and--type/96058/6 "2017-09-04T09:50:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
