Hi,
I have tried to create a template, but I now I can see 400 code from elasticsearch in fluentd logs.
curl -X PUT "localhost:9200/_template/nh_template" -H 'Content-Type: application/json' -d'
{
"index_patterns": ["nh-*"],
"settings": {
"number_of_shards": 1
},
"mappings": {
"fluentd": {
"_source": {
"enabled": true
},
"properties": {
"START_DATETIME": {
"type": "date",
"format": "dd-MM-yyyy HH:mm:ss"
},
"END_DATETIME": {
"type": "date",
"format": "dd-MM-yyyy HH:mm:ss"
},
"API_TASK":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"COUNTRY_CODE":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"DST_SYS":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"ERR_CODE":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"ERR_DATETIME":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"ERR_DETAILS":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"ERR_ID":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"NH_API":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"OCN":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"RELATIVE_ERR_ID":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"REQ_MSG":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"SRC_SYS":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"SRV_PROFILE":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"TXN_ID":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
},
"tag":{
"type":"text",
"fields":{
"keyword":{
"type":"keyword",
"ignore_above":256
}
}
}
}
}
}
}'
In Fluentd logs I can see following message
2019-04-19 11:51:06 +0530 [warn]: #0 dump an error event: error_class=Fluent::Plugin::ElasticsearchErrorHandler::ElasticsearchError error="400 - Rejected by Elasticsearch" location=nil tag="nh.wmtest" time=2019-04-19 11:51:02.021301738 +0530 record={"SRC_SYS"=>"wm", "COUNTRY_CODE"=>"JP", "SRV_PROFILE"=>"PROF3", "TXN_ID"=>"47118951", "NH_API"=>"NH_API6", "REQ_MSG"=>"MSG4", "OCN"=>"WKV5760727", "START_DATETIME"=>"19/04/2019 11:42:40", "END_DATETIME"=>"19/04/2019 11:51:02"}
Not sure whats wrong.
Regards,
-Manish