# Elastic Search 6.4.0 log file filling up the with WARNing messages

**URL:** <https://discuss.elastic.co/t/elastic-search-6-4-0-log-file-filling-up-the-with-warning-messages/151081>\
**Category:** Elasticsearch\
**Created:** [October 4, 2018, 4:28pm UTC](https://discuss.elastic.co/t/elastic-search-6-4-0-log-file-filling-up-the-with-warning-messages/151081 "2018-10-04T16:28:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kkr78](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kkr78/32/33806_2.png) [@kkr78](https://discuss.elastic.co/u/kkr78)\
**Post date:** [October 4, 2018, 4:28pm UTC](https://discuss.elastic.co/t/elastic-search-6-4-0-log-file-filling-up-the-with-warning-messages/151081/1 "2018-10-04T16:28:51Z")

</div>

ELASTICSEARCH\_VERSION=6.4.0

[2018-10-04T16:25:14,539][WARN][o.e.d.s.f.s.DocValueFieldsFetchSubPhase] Doc-value field [@timestamp] is not using a format. The output will change in 7.0 when doc value fields get formatted based on mappings by default. It is recommended to pass [format=use\_field\_mapping] with the doc value field in order to opt in for the future behaviour and ease the migration to 7.0.

I updated the template for date fields to have format. But I still see those warnings in the logs. The issue is too many warning messages printed in the logs.

"mappings": {  
"applog": {  
"properties": {  
"@timestamp": {"type": "date","format":"yyyy-MM-dd'T'HH:mm:ss.SSSZ"},

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [October 5, 2018, 8:09am UTC](https://discuss.elastic.co/t/elastic-search-6-4-0-log-file-filling-up-the-with-warning-messages/151081/2 "2018-10-05T08:09:28Z")

</div>

I think this is due to [https://github.com/elastic/elasticsearch/pull/29639](https://github.com/elastic/elasticsearch/pull/29639) which adds the `format` option to _searches_ returning docvalue fields. The warning is there to tell you to be explicit about the format you want to avoid incompatibility with 7.0. To suppress the warnings, add `"format": "use_field_mapping"` to the searches that are causing them.

[https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-docvalue-fields.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-docvalue-fields.html)

---

<div class="post-metadata">

**Author:** ![kkr78](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kkr78/32/33806_2.png) [@kkr78](https://discuss.elastic.co/u/kkr78)\
**Post date:** [October 5, 2018, 3:00pm UTC](https://discuss.elastic.co/t/elastic-search-6-4-0-log-file-filling-up-the-with-warning-messages/151081/3 "2018-10-05T15:00:48Z")

</div>

Ok, got it. How can I specify field mapping on Kibana? I updated the format for the date fields under KIbana Index Pattern but that didn't help.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [October 5, 2018, 4:07pm UTC](https://discuss.elastic.co/t/elastic-search-6-4-0-log-file-filling-up-the-with-warning-messages/151081/4 "2018-10-05T16:07:54Z")

</div>

Sorry, I don't know enough about Kibana to answer that definitively. I suggest you ask in the [Kibana forum](https://discuss.elastic.co/c/kibana).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2018, 4:07pm UTC](https://discuss.elastic.co/t/elastic-search-6-4-0-log-file-filling-up-the-with-warning-messages/151081/5 "2018-11-02T16:07:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
