# Dynamic template mappins are failing on ELasticsearch 6.0

**URL:** <https://discuss.elastic.co/t/dynamic-template-mappins-are-failing-on-elasticsearch-6-0/109903>\
**Category:** Elasticsearch\
**Created:** [December 1, 2017, 9:46am UTC](https://discuss.elastic.co/t/dynamic-template-mappins-are-failing-on-elasticsearch-6-0/109903 "2017-12-01T09:46:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![trondhindenes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trondhindenes/32/10534_2.png) [@trondhindenes](https://discuss.elastic.co/u/trondhindenes)\
**Post date:** [December 1, 2017, 9:46am UTC](https://discuss.elastic.co/t/dynamic-template-mappins-are-failing-on-elasticsearch-6-0/109903/1 "2017-12-01T09:46:27Z")

</div>

We rolled over to new indexes yesterday, and this is the first time we've rolled over after upgrading to ES6. Immediately we started getting exceptions from logstash and missing data with errors like this:

```auto
[2017-12-01T09:40:09,385][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>"864b96d9-ac21-46f5-b166-3e0cd7930ea0", :_index=>"iis_log_prod-2017.12", :_type=>"iis_log_entry", :_routing=>nil}, 2017-12-01T09:40:07.848Z z49os2swb016 %{message}], :response=>{"index"=>{"_index"=>"iis_log_prod-2017.12", "_type"=>"iis_log_entry", "_id"=>"864b96d9-ac21-46f5-b166-3e0cd7930ea0", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to find type parsed [string] for [log_timestamp]"}}}}

```

We use a lot of dynamic templates, and the one failing above is using this template:

```auto
iis_log": {
        "order": 0,
        "index_patterns": [
            "iis_log*"
        ],
        "settings": {
            "index": {
                "refresh_interval": "5s"
            }
        },
        "mappings": {
            "iis_log_entry": {
                "properties": {
                    "win32response": {
                        "type": "integer"
                    },
                    "@timestamp": {
                        "type": "date"
                    },
                    "timetaken": {
                        "type": "integer"
                    },
                    "serverIP": {
                        "type": "ip"
                    },
                    "response": {
                        "type": "integer"
                    },
                    "clientIP": {
                        "type": "ip"
                    },
                    "subresponse": {
                        "type": "integer"
                    },
                    "port": {
                        "type": "integer"
                    }
                },
                "dynamic_templates": [
                    {
                        "notanalyzed": {
                            "match_mapping_type": "string",
                            "mapping": {
                                "index": "not_analyzed",
                                "type": "string"
                            },
                            "match": "*"
                        }
                    }
                ]
            }
        },
        "aliases": {}
    }

```

We were originally running Logstash 5.6, but upgraded to 6.0 to see if that would help.

I don't understand what I can do in order to get my log pipeline working again.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 1, 2017, 3:02pm UTC](https://discuss.elastic.co/t/dynamic-template-mappins-are-failing-on-elasticsearch-6-0/109903/2 "2017-12-01T15:02:35Z")

</div>

Hey,

can you replace the `mapping` part of your `notanalyzed` dynamic template with

```auto
            "mapping": {
              "type": "keyword"
            },

```

and see if that changes anything?

---

<div class="post-metadata">

**Author:** ![trondhindenes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trondhindenes/32/10534_2.png) [@trondhindenes](https://discuss.elastic.co/u/trondhindenes)\
**Post date:** [December 1, 2017, 5:08pm UTC](https://discuss.elastic.co/t/dynamic-template-mappins-are-failing-on-elasticsearch-6-0/109903/3 "2017-12-01T17:08:08Z")

</div>

Thanks! Yes, finally figured it out, implementing the same setting as you propose above. I guess it was one more place where we trusted the upgrade advisor too much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2017, 5:08pm UTC](https://discuss.elastic.co/t/dynamic-template-mappins-are-failing-on-elasticsearch-6-0/109903/4 "2017-12-29T17:08:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
