# Elasticsearch / Logstash mapping error after upgrade

**URL:** <https://discuss.elastic.co/t/elasticsearch-logstash-mapping-error-after-upgrade/119814>\
**Category:** Logstash\
**Created:** [February 14, 2018, 2:12pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-mapping-error-after-upgrade/119814 "2018-02-14T14:12:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![petegriggs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/petegriggs/32/84177_2.png) [@petegriggs](https://discuss.elastic.co/u/petegriggs)\
**Post date:** [February 14, 2018, 2:12pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-mapping-error-after-upgrade/119814/1 "2018-02-14T14:12:41Z")

</div>

Hi,

Just upgraded to Elasticsearch and Logstash 6.2.0, everything was going well however logstash now can't put data in to elasticsearch. We are using this for IDS traffic the error we are getting is:

[2018-02-14T14:11:35,508][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-2018.02.14", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x7b67818b], :response=\>{"index"=\>{"\_index"=\>"logstash-2018.02.14", "\_type"=\>"doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"Failed to parse mapping [_default_]: No handler for type [string] declared on field [@version]", "caused\_by"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"No handler for type [string] declared on field [@version]"}}}}}

I am guessing we need to change @version to be text, I suspect its using the logstash default template but I'll be damned if I can find it.

Any help greatly appreciated.

Thanks  
Pete.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 14, 2018, 2:24pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-mapping-error-after-upgrade/119814/2 "2018-02-14T14:24:38Z")

</div>

Question moved to #logstash.

---

<div class="post-metadata">

**Author:** ![petegriggs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/petegriggs/32/84177_2.png) [@petegriggs](https://discuss.elastic.co/u/petegriggs)\
**Post date:** [February 19, 2018, 10:07am UTC](https://discuss.elastic.co/t/elasticsearch-logstash-mapping-error-after-upgrade/119814/3 "2018-02-19T10:07:56Z")

</div>

Bump. Does anyone have any ideas?

---

<div class="post-metadata">

**Author:** ![petegriggs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/petegriggs/32/84177_2.png) [@petegriggs](https://discuss.elastic.co/u/petegriggs)\
**Post date:** [February 26, 2018, 1:34pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-mapping-error-after-upgrade/119814/4 "2018-02-26T13:34:57Z")

</div>

Issue was done to Logstash 5 template - using template\_overwrite =\> true in logstash output fixed it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 26, 2018, 1:35pm UTC](https://discuss.elastic.co/t/elasticsearch-logstash-mapping-error-after-upgrade/119814/5 "2018-03-26T13:35:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
