# Dynamic-Template Errors After Upgrading to ES 6.8

**URL:** <https://discuss.elastic.co/t/dynamic-template-errors-after-upgrading-to-es-6-8/200771>\
**Category:** Elasticsearch\
**Created:** [September 24, 2019, 1:35am UTC](https://discuss.elastic.co/t/dynamic-template-errors-after-upgrading-to-es-6-8/200771 "2019-09-24T01:35:47Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticTrouble](https://avatars.discourse-cdn.com/v4/letter/e/a88e57/32.png) [@elasticTrouble](https://discuss.elastic.co/u/elasticTrouble)\
**Post date:** [September 24, 2019, 1:35am UTC](https://discuss.elastic.co/t/dynamic-template-errors-after-upgrading-to-es-6-8/200771/1 "2019-09-24T01:35:47Z")

</div>

Evening ES. I'm having some trouble successfully indexing certain events after migrating / upgrading to ES 6.8 from 5.3. I believe the root cause of the error I'm experiencing is due to an improper mapping on one of the dynamic templates created by our previous ES administrator.

Both the error and template are below. Please bear with me as I have next to no Elastic experience beyond what I've done to migrate our on-prem cluster to AWS ES and upgrade to 6.8 from 5.3.

Please let me know if I can provide any additional information to assist.

Logstash is spitting out the following error while indexing certain documents:

```auto
[2019-09-23T19:46:13,918][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"logstash-2019.09", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x6aba739e>], :response=>{"index"=>{"_index"=>"logstash-2019.09", "_type"=>"doc", "_id"=>"AW1gu6dtBNlnaFfEigoR", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to find type parsed [string] for [level]"}}}}

```

Template in question:

```auto
{
  "logstash" : {
    "order" : 0,
    "version" : 60001,
    "index_patterns" : [
      "logstash-*"
    ],
    "settings" : {
      "index" : {
        "refresh_interval" : "5s"
      }
    },
    "mappings" : {
      "_default_" : {
        "dynamic_templates" : [
          {
            "message_field" : {
              "path_match" : "message",
              "mapping" : {
                "norms" : false,
                "type" : "text"
              },
              "match_mapping_type" : "string"
            }
          },
          {
            "string_fields" : {
              "mapping" : {
                "norms" : false,
                "type" : "text",
                "fields" : {
                  "keyword" : {
                    "ignore_above" : 256,
                    "type" : "keyword"
                  }
                }
              },
              "match_mapping_type" : "string",
              "match" : "*"
            }
          }
        ],
        "properties" : {
          "@timestamp" : {
            "type" : "date"
          },
          "geoip" : {
            "dynamic" : true,
            "properties" : {
              "ip" : {
                "type" : "ip"
              },
              "latitude" : {
                "type" : "half_float"
              },
              "location" : {
                "type" : "geo_point"
              },
              "longitude" : {
                "type" : "half_float"
              }
            }
          },
          "@version" : {
            "type" : "keyword"
          }
        }
      }
    },
    "aliases" : { }

```

Posts I've been referencing:

> **[Elasticsearch replaces string type with two new types text and keyword.](https://www.elastic.co/blog/strings-are-dead-long-live-strings)**
>
> On using text types for full text search and keyword type for keyword search in Elasticsearch 5.0.

> [@Mapper\_parsing\_exception", "reason"=\>"failed to parse \[severity\]"](https://discuss.elastic.co/t/mapper-parsing-exception-reason-failed-to-parse-severity/128781):
>
> full error: [2018-04-20T00:33:26,274][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-2018.04.20-ea1", :\_type=\>"doc", :\_routing=\>nil}, #\<LogStash::Event:0x5a7f3243\>], :response=\>{"index"=\> . {"\_index"=\>"logstash-2018.04.20-ea1", "\_type"=\>"doc", "\_id"=\>"KZJ44GIBORYB4ebWWD38", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse [severity]", "caused\_by"=\>{"type"=\>…

> [@Error in using dynamic mapping: Elasticsearch 6.2](https://discuss.elastic.co/t/error-in-using-dynamic-mapping-elasticsearch-6-2/133699):
>
> I have upgraded to ElasticSearch 6.2 from 5.0. I am facing challenges in dynamic template. Template I have uploaded to ES is: curl -XPOST localhost:9200/\_template/mytemplate -H 'Content-Type: application/json' -d' { "index\_patterns": ["my\*"], "settings": { "number\_of\_shards": 2 }, "mappings": { "mytype": { "dynamic\_templates": [ { "string\_fields": { "match\_mapping\_type": "string", "match": "\*", "mapping": { "index": "not\_analyzed", "ignore\_above": 256, "type": "string" } …

> [@Dynamic template mappins are failing on ELasticsearch 6.0](https://discuss.elastic.co/t/dynamic-template-mappins-are-failing-on-elasticsearch-6-0/109903):
>
> We rolled over to new indexes yesterday, and this is the first time we've rolled over after upgrading to ES6. Immediately we started getting exceptions from logstash and missing data with errors like this: [2017-12-01T09:40:09,385][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>"864b96d9-ac21-46f5-b166-3e0cd7930ea0", :\_index=\>"iis\_log\_prod-2017.12", :\_type=\>"iis\_log\_entry", :\_routing=\>nil}, 2017-12-01T09:40:07.848Z z49os2s…

---

<div class="post-metadata">

**Author:** ![elasticTrouble](https://avatars.discourse-cdn.com/v4/letter/e/a88e57/32.png) [@elasticTrouble](https://discuss.elastic.co/u/elasticTrouble)\
**Post date:** [September 24, 2019, 9:18pm UTC](https://discuss.elastic.co/t/dynamic-template-errors-after-upgrading-to-es-6-8/200771/2 "2019-09-24T21:18:33Z")

</div>

Bumping this up to the top for extra eyes. I believe I understand the root cause of the issue being the "string" type has been deprecated according to the Elastic blog post linked below. I used the mapping API to retrieve the mapping of our Logstash index using `GET /logstash-2019.09/_mapping`. The only two places where the "string" type is used are posted below.

Digging through the rest of the index mapping for the other values I'm getting mapper\_parsing\_exception errors on seems to show me that the values causing errors are mapped properly using the "keyword" type.

Is there any way to up the character limit on these posts? I'd like to post the full index mapping. Unfortunately though, the full map is over 7,000 lines long. Which I suspect is a problem in of itself.

Also for what it is worth I started our ES migration by uploading existing data from our on-prem deployment (5.3) to our new Amazon ES deployment (6.8) by using the Snapshot/Restore API. I am now trying to index live events using Logstash 6.8. Could this be part of the problem? Is it possible I need to re-index the existing data in some way?

```auto
GET /logstash-2019.09/_mapping

```

Mapping Snippet with "string"

```auto
            "string_fields" : {
              "match" : "*",
              "match_mapping_type" : "string",
              "mapping" : {
                "fielddata" : {
                  "format" : "disabled"
                },
                "fields" : {
                  "raw" : {
                    "ignore_above" : 256,
                    "index" : "not_analyzed",
                    "type" : "string"

```

Sample Mapping Snippets:

```auto
There are 19 occurrences of this same mapping for "syslog_text" all of them are defined the same. 

[2019-09-23T19:53:02,394][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"logstash-2019.09", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x3fa39351>], :response=>{"index"=>{"_index"=>"logstash-2019.09", "_type"=>"doc", "_id"=>"AW1gweMirQfrb52qfo0M", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to find type parsed [string] for [syslog_text]"}}}}

          },
          "syslog_text" : {
            "type" : "text",
            "norms" : false,
            "fields" : {
              "raw" : {
                "type" : "keyword",
                "ignore_above" : 256
              }

```

```auto
There are 18 occurrences of this same mapping for "path" all of them are defined the same. 

[2019-09-23T19:53:02,395][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"logstash-2019.09", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x701eb47d>], :response=>{"index"=>{"_index"=>"logstash-2019.09", "_type"=>"doc", "_id"=>"AW1gweMirQfrb52qfo0O", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to find type parsed [string] for [path]"}}}}

          "path" : {
            "type" : "text",
            "norms" : false,
            "fields" : {
              "raw" : {
                "type" : "keyword",
                "ignore_above" : 256

```

---

<div class="post-metadata">

**Author:** ![gabriel\_tessier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel_tessier/32/27911_2.png) [@gabriel\_tessier](https://discuss.elastic.co/u/gabriel_tessier)\
**Post date:** [September 25, 2019, 4:54am UTC](https://discuss.elastic.co/t/dynamic-template-errors-after-upgrading-to-es-6-8/200771/3 "2019-09-25T04:54:47Z")

</div>

Hi @elasticTrouble

> [@elasticTrouble](#):
>
> Is there any way to up the character limit on these posts? I'd like to post the full index mapping. Unfortunately though, the full map is over 7,000 lines long. Which I suspect is a problem in of itself.

You can use Gist or pastebin or... to share bigger content.

I think it's better to make a remote reindex, you can set a new clean template and mapping on your 6.x (destination server) and start reindexing your data from there.

> **[Reindex from a remote cluster | Elasticsearch Guide \[6.8\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/reindex-upgrade-remote.html)**

---

<div class="post-metadata">

**Author:** ![elasticTrouble](https://avatars.discourse-cdn.com/v4/letter/e/a88e57/32.png) [@elasticTrouble](https://discuss.elastic.co/u/elasticTrouble)\
**Post date:** [September 25, 2019, 5:13pm UTC](https://discuss.elastic.co/t/dynamic-template-errors-after-upgrading-to-es-6-8/200771/4 "2019-09-25T17:13:53Z")

</div>

@gabriel_tessier Thanks for the advice on using gist or pastebin. I'm not sure why I didn't think of those in the first place. Unfortunately since I'm using AWS ES (Hosted Service not EC2 Instances) I do not believe the reindex from remote API is available to me or else I would have started down that path long ago.

Thankfully I was able to solve my issue by deleting the latest logstash index from my cluster and restarting the flow of events from logstash. I believe the root cause of my issue was initially feeding every document from logstash into the logstash index on accident.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2019, 5:13pm UTC](https://discuss.elastic.co/t/dynamic-template-errors-after-upgrading-to-es-6-8/200771/5 "2019-10-23T17:13:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
