# Disable \_source field

**URL:** <https://discuss.elastic.co/t/disable-source-field/132036>\
**Category:** Elasticsearch\
**Created:** [May 16, 2018, 6:05am UTC](https://discuss.elastic.co/t/disable-source-field/132036 "2018-05-16T06:05:24Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![nsphaniraj](https://avatars.discourse-cdn.com/v4/letter/n/7feea3/32.png) [@nsphaniraj](https://discuss.elastic.co/u/nsphaniraj)\
**Post date:** [May 16, 2018, 6:05am UTC](https://discuss.elastic.co/t/disable-source-field/132036/1 "2018-05-16T06:05:24Z")

</div>

Hello,

I had harvested 100 csv files. using filebeat -\> logstash (Using csv filter) -\> Elasticsearch. The disk size of 100 CSV flat files is 609 MB and translated to 1 GB in elasticsearch (pri.store.size).

I am aware of the advantages of \_source field. However, I am trying to see the space that we could save by disabling \_source field in elasticsearch 6.2.4 version. Using below command to disable the \_source field

**Index Name** : perflogs-2018.19

```auto
PUT perflogs-2018.19
{
  "mappings": {
    "_doc": {
      "_source": {
        "enabled": false
      }
    }
  }
}

```

I am getting below error. Please let me know if I am doing anything wrong.

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "resource_already_exists_exception",
        "reason": "index [perflogs-2018.19/CH-f47yTRqCAjfxZiEKI3A] already exists",
        "index_uuid": "CH-f47yTRqCAjfxZiEKI3A",
        "index": "perflogs-2018.19"
      }
    ],
    "type": "resource_already_exists_exception",
    "reason": "index [perflogs-2018.19/CH-f47yTRqCAjfxZiEKI3A] already exists",
    "index_uuid": "CH-f47yTRqCAjfxZiEKI3A",
    "index": "perflogs-2018.19"
  },
  "status": 400
}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 16, 2018, 6:06am UTC](https://discuss.elastic.co/t/disable-source-field/132036/2 "2018-05-16T06:06:29Z")

</div>

You cannot do it if the index already exists, so you will need to delete the index, add the mapping and then reprocess.

---

<div class="post-metadata">

**Author:** ![nsphaniraj](https://avatars.discourse-cdn.com/v4/letter/n/7feea3/32.png) [@nsphaniraj](https://discuss.elastic.co/u/nsphaniraj)\
**Post date:** [May 16, 2018, 6:47am UTC](https://discuss.elastic.co/t/disable-source-field/132036/3 "2018-05-16T06:47:26Z")

</div>

Hi Warkolm,

Thanks for the quick response.

I followed the below steps and getting below error.

1. Delete perflogs-2018.19 index
2. Add Mapping to disable \_source field

```auto
PUT perflogs-2018.19
{
  "mappings": {
    "_doc": {
      "_source": {
        "enabled": false
      }
    }
  }
}

```

1. Harvest logs to perflogs-2018.19 index. I see below error in elasticsearch logs

```auto
[2018-05-16T06:44:41,919][DEBUG][o.e.a.b.TransportShardBulkAction] [perflogs-2018.19][0] failed to execute bulk item (index) BulkShardRequest [[perflogs-2018.19][0]] containing [12] requests
java.lang.IllegalArgumentException: Rejecting mapping update to [perflogs-2018.19] as the final mapping would have more than 1 type: [_doc, log]
        at org.elasticsearch.index.mapper.MapperService.internalMerge(MapperService.java:501) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.index.mapper.MapperService.internalMerge(MapperService.java:353) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.index.mapper.MapperService.merge(MapperService.java:285) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.cluster.metadata.MetaDataMappingService$PutMappingExecutor.applyRequest(MetaDataMappingService.java:313) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.cluster.metadata.MetaDataMappingService$PutMappingExecutor.execute(MetaDataMappingService.java:230) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.cluster.service.MasterService.executeTasks(MasterService.java:643) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.cluster.service.MasterService.calculateTaskOutputs(MasterService.java:273) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.cluster.service.MasterService.runTasks(MasterService.java:198) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.cluster.service.MasterService$Batcher.run(MasterService.java:133) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.cluster.service.TaskBatcher.runIfNotProcessed(TaskBatcher.java:150) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.cluster.service.TaskBatcher$BatchedTask.run(TaskBatcher.java:188) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.common.util.concurrent.ThreadContext$ContextPreservingRunnable.run(ThreadContext.java:573) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.runAndClean(PrioritizedEsThreadPoolExecutor.java:244) ~[elasticsearch-6.2.4.jar:6.2.4]
        at org.elasticsearch.common.util.concurrent.PrioritizedEsThreadPoolExecutor$TieBreakingPrioritizedRunnable.run(PrioritizedEsThreadPoolExecutor.java:207) ~[elasticsearch-6.2.4.jar:6.2.4]
        at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) [?:1.8.0_171]
        at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) [?:1.8.0_171]
        at java.lang.Thread.run(Thread.java:748) [?:1.8.0_171]

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 16, 2018, 7:24am UTC](https://discuss.elastic.co/t/disable-source-field/132036/4 "2018-05-16T07:24:29Z")

</div>

> [@nsphaniraj](#):
>
> Rejecting mapping update to [perflogs-2018.19] as the final mapping would have more than 1 type: [\_doc, log]

That'll depend on what other data is going into Elasticsearch, but are you using Logstash?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 16, 2018, 8:36am UTC](https://discuss.elastic.co/t/disable-source-field/132036/5 "2018-05-16T08:36:04Z")

</div>

Without reindexing and removing `_source` you can also ask for a better compression:

See `index.codec` in [https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-modules.html)

Then run a `_forcemerge` call to rewrite the segments.

But also instead of removing the `_source` field which I do not recommend as you will miss a lot of feature then, have a look at your mapping and see what else you can optimize instead.

---

<div class="post-metadata">

**Author:** ![nsphaniraj](https://avatars.discourse-cdn.com/v4/letter/n/7feea3/32.png) [@nsphaniraj](https://discuss.elastic.co/u/nsphaniraj)\
**Post date:** [May 16, 2018, 9:03am UTC](https://discuss.elastic.co/t/disable-source-field/132036/6 "2018-05-16T09:03:08Z")

</div>

Hi Warkolm/dadoonet,

Yes, we use logstash in the data pipeline. How do we fix "Multiple mapping" issue?  
The data pipeline is filebeat -\> logstash -\> elasticsearch.

With default compression codec, 608 MB flat file size translated to 1 GB of index store size.  
With best\_compression codec, 608 MB flat file size translated to 740 MB of index store size. Even best\_compression codec seems to be little high on disk utilization. Hence, would like to know the disk usage of index store size when \_source field is disabled.

Thanks  
Phaniraj

---

<div class="post-metadata">

**Author:** ![nsphaniraj](https://avatars.discourse-cdn.com/v4/letter/n/7feea3/32.png) [@nsphaniraj](https://discuss.elastic.co/u/nsphaniraj)\
**Post date:** [May 16, 2018, 9:11am UTC](https://discuss.elastic.co/t/disable-source-field/132036/7 "2018-05-16T09:11:08Z")

</div>

[quote="nsphaniraj, post:6, topic:132036"]  
Hi Warkolm/dadoonet,

\_forcemerge did help to reduce the store size from 740 MB to 619 MB

But, would like to see the store size by disabling \_source field.

Thanks  
Phaniraj

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 16, 2018, 9:41am UTC](https://discuss.elastic.co/t/disable-source-field/132036/8 "2018-05-16T09:41:27Z")

</div>

We can probably help but to solve what? I mean that do you think it is worth it?

What are you going to do with your data? And again what is your current mapping?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 16, 2018, 9:51am UTC](https://discuss.elastic.co/t/disable-source-field/132036/9 "2018-05-16T09:51:40Z")

</div>

Have a look at [this documentation](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/tune-for-disk-usage.html#_disable_the_features_you_do_not_need) for guidance on how to optimise mappings.

---

<div class="post-metadata">

**Author:** ![nsphaniraj](https://avatars.discourse-cdn.com/v4/letter/n/7feea3/32.png) [@nsphaniraj](https://discuss.elastic.co/u/nsphaniraj)\
**Post date:** [May 17, 2018, 5:53am UTC](https://discuss.elastic.co/t/disable-source-field/132036/10 "2018-05-17T05:53:28Z")

</div>

Hi All,

Thank you all for the help.

I was able to disable the \_source field after fixing the mapping name. Looks like logstash uses "log" as mapping name and I used the same name to disable \_source field. 608 MB of log translated to 301 MB with best\_compression codec.

```auto
PUT perflogs-2018.19
{
  "mappings": {
    "log": {
      "_source": {
        "enabled": false
      }
    }
  }
}

```

Thanks  
Phaniraj

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2018, 5:53am UTC](https://discuss.elastic.co/t/disable-source-field/132036/11 "2018-06-14T05:53:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
