# Elasticsearch mapper\_parsing\_exception

**URL:** <https://discuss.elastic.co/t/elasticsearch-mapper-parsing-exception/50158>\
**Category:** Elasticsearch\
**Created:** [May 16, 2016, 10:07pm UTC](https://discuss.elastic.co/t/elasticsearch-mapper-parsing-exception/50158 "2016-05-16T22:07:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dkota](https://avatars.discourse-cdn.com/v4/letter/d/46a35a/32.png) [@dkota](https://discuss.elastic.co/u/dkota)\
**Post date:** [May 16, 2016, 10:07pm UTC](https://discuss.elastic.co/t/elasticsearch-mapper-parsing-exception/50158/1 "2016-05-16T22:07:10Z")

</div>

When I'm making changes to my mapping template, all the input is written to logstash.log file and no index is created; along with the below errors.

MApping.json

{  
"template" : "gfn\*",  
"order" : 0,  
"template" : "gfn\*",  
"settings" : {  
"index" : {  
"routing" : {  
"allocation" : {  
"require" : {  
"box\_type" : "hot"  
}  
}  
}  
}  
},  
"mappings" : {  
"_default_" : {  
"\_all" : {  
"enabled" : false  
}  
},  
"properties" : {  
"Action" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"DeviceTime" : {  
"format" : "strict\_date\_optional\_time||epoch\_millis",  
"type" : "date"  
},  
"EventOutcome" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"Category" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"CEF\_Version" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"URLaccessed" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"RequestMethod" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"DeviceGroup" : {  
"type" : "string"  
},  
"SourcePort" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"DestinationPort" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"out" : {  
"index" : "not\_analyzed",  
"type" : "long"  
},  
"SignatureID" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"SessionInformation" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"SourceIP" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"act" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"DeviceProduct" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"host" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"DeviceVendor" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"Significance" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"DeviceHost" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"in" : {  
"index" : "not\_analyzed",  
"type" : "long"  
},  
"index" : {  
"index" : "analyzed",  
"type" : "string"  
},  
"Severity" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"SourceHostname" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"message" : {  
"index" : "analyzed",  
"type" : "string"  
},  
"DestinationHostname" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"DestinationIP" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"TimeZone" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"Username" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"port" : {  
"index" : "not\_analyzed",  
"type" : "long"  
},  
"EventID" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"Object" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"Application" : {  
"index" : "not\_analyzed",  
"type" : "string"  
},  
"ignore\_malformed": true  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![dkota](https://avatars.discourse-cdn.com/v4/letter/d/46a35a/32.png) [@dkota](https://discuss.elastic.co/u/dkota)\
**Post date:** [May 16, 2016, 10:07pm UTC](https://discuss.elastic.co/t/elasticsearch-mapper-parsing-exception/50158/2 "2016-05-16T22:07:22Z")

</div>

Logstash.log

"status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"Failed to parse mapping [properties]: Root mapping definition has unsupported parameters: [Action : {index=not\_analyzed, type=string}] [DeviceTime : {format=strict\_date\_optional\_time||epoch\_millis, type=date}] [EventOutcome : {index=not\_analyzed, type=string}] [Category : {index=not\_analyzed, type=string}] [CEF\_Version : {index=not\_analyzed, type=string}] [URLaccessed : {index=not\_analyzed, type=string}] [RequestMethod : {index=not\_analyzed, type=string}] [DeviceGroup : {type=string}] [ignore\_malformed : true] [SourcePort : {index=not\_analyzed, type=string}] [DestinationPort : {index=not\_analyzed, type=string}] [out : {index=not\_analyzed, type=long}] [SignatureID : {index=not\_analyzed, type=string}] [SessionInformation : {index=not\_analyzed, type=string}] [SourceIP : {index=not\_analyzed, type=string}] [act : {index=not\_analyzed, type=string}] [DeviceProduct : {index=not\_analyzed, type=string}] [host : {index=not\_analyzed, type=string}] [DeviceVendor : {index=not\_analyzed, type=string}] [Significance : {index=not\_analyzed, type=string}] [DeviceHost : {index=not\_analyzed, type=string}] [in : {index=not\_analyzed, type=long}] [index : {index=analyzed, type=string}] [Severity : {index=not\_analyzed, type=string}] [SourceHostname : {index=not\_analyzed, type=string}] [message : {index=analyzed, type=string}] [DestinationHostname : {index=not\_analyzed, type=string}] [DestinationIP : {index=not\_analyzed, type=string}] [TimeZone : {index=not\_analyzed, type=string}] [Username : {index=not\_analyzed, type=string}] [port : {index=not\_analyzed, type=long}] [EventID : {index=not\_analyzed, type=string}] [Object : {index=not\_analyzed, type=string}] [Application : {index=not\_analyzed, type=string}]", "caused\_by"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"Root mapping definition has unsupported parameters: [Action : {index=not\_analyzed, type=string}] [DeviceTime : {format=strict\_date\_optional\_time||epoch\_millis, type=date}] [EventOutcome : {index=not\_analyzed, type=string}] [Category : {index=not\_analyzed, type=string}] [CEF\_Version : {index=not\_analyzed, type=string}] [URLaccessed : {index=not\_analyzed, type=string}] [RequestMethod : {index=not\_analyzed, type=string}] [DeviceGroup : {type=string}] [ignore\_malformed : true] [SourcePort : {index=not\_analyzed, type=string}] [DestinationPort : {index=not\_analyzed, type=string}] [out : {index=not\_analyzed, type=long}] [SignatureID : {index=not\_analyzed, type=string}] [SessionInformation : {index=not\_analyzed, type=string}] [SourceIP : {index=not\_analyzed, type=string}] [act : {index=not\_analyzed, type=string}] [DeviceProduct : {index=not\_analyzed, type=string}] [host : {index=not\_analyzed, type=string}] [DeviceVendor : {index=not\_analyzed, type=string}] [Significance : {index=not\_analyzed, type=string}] [DeviceHost : {index=not\_analyzed, type=string}] [in : {index=not\_analyzed, type=long}] [index : {index=analyzed, type=string}] [Severity : {index=not\_analyzed, type=string}] [SourceHostname : {index=not\_analyzed, type=string}] [message : {index=analyzed, type=string}] [DestinationHostname : {index=not\_analyzed, type=string}] [DestinationIP : {index=not\_analyzed, type=string}] [TimeZone : {index=not\_analyzed, type=string}] [Username : {index=not\_analyzed, type=string}] [port : {index=not\_analyzed, type=long}] [EventID : {index=not\_analyzed, type=string}] [Object : {index=not\_analyzed, type=string}] [Application : {index=not\_analyze d, type=string}]"}}}}, :level=\>:warn}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 17, 2016, 2:45pm UTC](https://discuss.elastic.co/t/elasticsearch-mapper-parsing-exception/50158/3 "2016-05-17T14:45:01Z")

</div>

What does your LS config look like?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:51pm UTC](https://discuss.elastic.co/t/elasticsearch-mapper-parsing-exception/50158/4 "2017-07-05T22:51:02Z")

</div>


