# Document\_type deprecated?

**URL:** <https://discuss.elastic.co/t/document-type-deprecated/96441>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 9, 2017, 1:37pm UTC](https://discuss.elastic.co/t/document-type-deprecated/96441 "2017-08-09T13:37:52Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [August 9, 2017, 1:37pm UTC](https://discuss.elastic.co/t/document-type-deprecated/96441/1 "2017-08-09T13:37:52Z")

</div>

Upgrading from 5.4 to 5.5, I see that document\_type in Filebeat is deprecated because \_type is going away in Elasticsearch 6.0.

Not a problem, as I'm not using multiple types per index.

But what do I do right now? - my natural inclination is to delete anything deprecated as soon as it becomes deprecated so I don't have anything breaking later, when it finally goes away. But I've got "document\_type: wombat" in my filebeat.yml, and a matching

`"mappings": { "wombat": {`

in my template definition. Won't the template stop working if I simply delete the document\_type?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 9, 2017, 1:55pm UTC](https://discuss.elastic.co/t/document-type-deprecated/96441/2 "2017-08-09T13:55:42Z")

</div>

I think that you will need to declare `document_type` as a custom field under `fields`, this way the `type` field will take the place of the `_type` field, as stated on this [link](https://www.elastic.co/guide/en/elasticsearch/reference/6.0/removal-of-types.html).

I use the `type` field to allow me filter to in logstash, to use it with Filebeat 5.5 I've just declared it as a custom field under `fields`, as the example bellow

```auto
filebeat:
 prospectors:
  - input_type: log
    paths:
     - C:\inetpub\logs\LogFiles\W3SVC1\*.log
    fields:
      document_type: my-type
    exclude_lines: ["^#"]
    exclude_files: [".zip"]
    fields_under_root: true
    ignore_older: 24h

```

---

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [August 9, 2017, 3:27pm UTC](https://discuss.elastic.co/t/document-type-deprecated/96441/3 "2017-08-09T15:27:45Z")

</div>

I think that doesn't answer my question. I don't want or need multiple types, I'm not using them. What I've asked is what would happen to the template if I removed document\_type (obviously replacing it with a custom field of my own would be replacing it with a field that the template knew nothing about).

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 10, 2017, 12:35pm UTC](https://discuss.elastic.co/t/document-type-deprecated/96441/4 "2017-08-10T12:35:02Z")

</div>

`document_type` is not used for `_type` field. Beats (since 5.5) default `_type` to `docs`. This behaviour can not be overwritten. Still `document_type` sets the `type` field.

---

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [August 10, 2017, 1:51pm UTC](https://discuss.elastic.co/t/document-type-deprecated/96441/5 "2017-08-10T13:51:33Z")

</div>

That's not what I see. I've now got 5.5.1 running and I'm seeing "\_type" still set to the value of "document\_type".

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 10, 2017, 2:41pm UTC](https://discuss.elastic.co/t/document-type-deprecated/96441/6 "2017-08-10T14:41:19Z")

</div>

Hm.... checking the 5.5 branch I clearly see `_type` being hardcoded to `docs`.

The `_type` field is set here: [https://github.com/elastic/beats/blob/5.5/libbeat/outputs/elasticsearch/client.go#L325](https://github.com/elastic/beats/blob/5.5/libbeat/outputs/elasticsearch/client.go#L325)

with `eventType` being hardcoded to `"doc"`: [https://github.com/elastic/beats/blob/5.5/libbeat/outputs/elasticsearch/client.go#L96](https://github.com/elastic/beats/blob/5.5/libbeat/outputs/elasticsearch/client.go#L96)

Are you using the Elasticsearch output or Logstash?

---

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [August 11, 2017, 9:43am UTC](https://discuss.elastic.co/t/document-type-deprecated/96441/7 "2017-08-11T09:43:24Z")

</div>

Sorry, I misread you - I thought you'd said the changed behaviour was in Elasticsearch 5.5 but you said it was in Beats 5.5. Just right now I'm running Elasticsearch 5.5, Logstash 5.5, but Filebeat still at 5.4 (until I've done some fiddling with the Ansible scripts that deploys it).

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 11, 2017, 3:21pm UTC](https://discuss.elastic.co/t/document-type-deprecated/96441/8 "2017-08-11T15:21:34Z")

</div>

Yep, it's in filebeat.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2017, 3:21pm UTC](https://discuss.elastic.co/t/document-type-deprecated/96441/9 "2017-09-08T15:21:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
