# Document\_type is being ignored

**URL:** <https://discuss.elastic.co/t/document-type-is-being-ignored/109667>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 30, 2017, 12:13am UTC](https://discuss.elastic.co/t/document-type-is-being-ignored/109667 "2017-11-30T00:13:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vivek\_Menon](https://avatars.discourse-cdn.com/v4/letter/v/ce7236/32.png) [@Vivek\_Menon](https://discuss.elastic.co/u/Vivek_Menon)\
**Post date:** [November 30, 2017, 12:13am UTC](https://discuss.elastic.co/t/document-type-is-being-ignored/109667/1 "2017-11-30T00:13:14Z")

</div>

I am new to file beat. I am using filebeat to forward logs to logstash, from where it gets forwarded to elastic search.  
I am using version 6.0 for all of them.

The problem I am having is that even if I set document\_type, the value that ends up in elastic for \_type is doc.  
I know I am doing something wrong, but can't figure what.

This is how my filebeat.yml looks like

```
filebeat.prospectors:

# Each - is a prospector. Most options can be set at the prospector level, so
# you can use different prospectors for various configurations.
# Below are the prospector specific configurations.

- type: log

  # Change to true to enable this prospector configuration.
  enabled: false

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - E:\someLoc\IISLogs\inetpub\logs\LogFiles\W3SVC1\*.log
  document_type: iis_log

```

This is how my logstash config looks like

```
input {
    beats {
     port =>"5043"
    }
  
}

output {
  elasticsearch {
    hosts => ["127.0.0.1:9200"]
    index => "%{[@metadata][beat]}"
    document_type => "%{[@metadata][type]}"
  }
}

```

This is a sample of what ends up in elastic search

```
 {
                "_index": "filebeat",
                "_type": "doc",
                "_id": "IjYyCmABLUTmLp82mEUK",
                "_score": 1,
                "_source": {
                    "@timestamp": "2017-11-29T23:52:53.452Z",
                    "offset": 1168146,
                    "@version": "1",
                    "beat": {
                        "name": "XXXX",
                        "hostname": "XXXX",
                        "version": "6.0.0"
                    },
                    "host": "XXXX",
                    "prospector": {
                        "type": "log"
                    },
                    "source": "ZZZZ\IISLogs\\inetpub\\logs\\LogFiles\\W3SVC1\\u_ex171116.log",
                    "message": "Blah",
                    "tags": [
                        "beats_input_codec_plain_applied"
                    ]
                }
            }
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 30, 2017, 1:04am UTC](https://discuss.elastic.co/t/document-type-is-being-ignored/109667/2 "2017-11-30T01:04:38Z")

</div>

[docuement\_type](https://www.elastic.co/guide/en/beats/filebeat/5.6/configuration-filebeat-options.html#filebeat-document-type) was deprecated in 5.5 and completely removed in 6.0 because [`_type` is being removed from Elasticsearch](https://www.elastic.co/guide/en/elasticsearch/reference/6.0/removal-of-types.html).

You can add your own `type` field (not `_type`) with [fields](https://www.elastic.co/guide/en/beats/filebeat/6.0/configuration-general-options.html#libbeat-configuration-fields).

```auto
filebeat.prospectors:
- paths:
    - 'E:\someLoc\IISLogs\inetpub\logs\LogFiles\W3SVC1\*.log'
  fields_under_root: true
  fields:
    type: iis_log

```

---

<div class="post-metadata">

**Author:** ![Vivek\_Menon](https://avatars.discourse-cdn.com/v4/letter/v/ce7236/32.png) [@Vivek\_Menon](https://discuss.elastic.co/u/Vivek_Menon)\
**Post date:** [November 30, 2017, 1:13am UTC](https://discuss.elastic.co/t/document-type-is-being-ignored/109667/3 "2017-11-30T01:13:07Z")

</div>

Thank you Andrew!

How do I filter in logstash using this field? In the old way the log stash config would had looked like

```
    filter {
       

        if [type] == "iis_log" {
           

            grok {
                match => { xxx}
            } 

        }
    }

```

How would I do that if its in a field now? Also can i add a column with this field in logstash?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [November 30, 2017, 2:04pm UTC](https://discuss.elastic.co/t/document-type-is-being-ignored/109667/4 "2017-11-30T14:04:46Z")

</div>

> [@Vivek\_Menon](#):
>
> How do I filter in logstash using this field?

It's the same way. What you have should work fine if you are using the config I gave.

---

<div class="post-metadata">

**Author:** ![Vivek\_Menon](https://avatars.discourse-cdn.com/v4/letter/v/ce7236/32.png) [@Vivek\_Menon](https://discuss.elastic.co/u/Vivek_Menon)\
**Post date:** [November 30, 2017, 6:29pm UTC](https://discuss.elastic.co/t/document-type-is-being-ignored/109667/5 "2017-11-30T18:29:03Z")

</div>

That worked for me! Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2017, 6:29pm UTC](https://discuss.elastic.co/t/document-type-is-being-ignored/109667/6 "2017-12-28T18:29:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
