# ElasticSearch: Mapping not applied to AWS ELK

**URL:** <https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326>\
**Category:** Elasticsearch\
**Created:** [October 16, 2020, 9:44am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326 "2020-10-16T09:44:24Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![gyana\_nayak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gyana_nayak/32/56498_2.png) [@gyana\_nayak](https://discuss.elastic.co/u/gyana_nayak)\
**Post date:** [October 16, 2020, 9:44am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/1 "2020-10-16T09:44:24Z")

</div>

While applying below mapping to my local ElasticSearch 7.4.1

```auto
private static void addIndexMapping(RestHighLevelClient client, String indexName) throws IOException {
        PutMappingRequest request = new PutMappingRequest(indexName);
        XContentBuilder builder = XContentFactory.jsonBuilder();
        builder.startObject();
        {
            builder.startObject("properties");
            {
                builder.startObject("modifiedDate");
                {
                    builder.field("type", "date").field("format","yyyy-MM-dd HH:mm:ss.SSS");

                }
                builder.endObject();
            }
            builder.endObject();
        }
        builder.endObject();
        request.source(builder);
        client.indices().putMapping(request, RequestOptions.DEFAULT);
    }

```

i can see below mapping got created

```auto
{
  "sandbox" : {
    "mappings" : {
      "modifiedDate" : {
        "full_name" : "modifiedDate",
        "mapping" : {
          "modifiedDate" : {
            "type" : "date",
            "format" : "yyyy-MM-dd HH:mm:ss.SSS"
          }
        }
      }
    }
  }
}

```

but when applying same mapping on AWS elk 7.4.2 i am seeing below mapping

```auto
{
  "sandbox" : {
    "mappings" : {
      "modifiedDate" : {
        "full_name" : "modifiedDate",
        "mapping" : {
          "modifiedDate" : {
            "type" : "text",
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          }
        }
      }
    }
  }
}

```

In my local i have installed ElasticSearch 7.4.1 and in production ElasticSearch 7.4.2. Couldn't understand what is wrong with my configuration.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 16, 2020, 11:13am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/2 "2020-10-16T11:13:15Z")

</div>

May be the index already exists with a mapping before you are calling the `addIndexMapping` method?

You should may be check the result of

```
client.indices().putMapping(request, RequestOptions.DEFAULT);

```

?

BTW did you look at [Cloud by Elastic](https://www.elastic.co/cloud), also available if needed from [AWS Marketplace](https://aws.amazon.com/marketplace/pp/B01N6YCISK) ?

Cloud by elastic is one way to have access to **all features** , all managed by us. Think about what is there yet like Security, Monitoring, Reporting, SQL, Canvas, Maps UI, Alerting and built-in solutions named [Observability](https://www.elastic.co/observability), [Security](https://www.elastic.co/security), [Enterprise Search](https://www.elastic.co/enterprise-search) and what is coming next 🙂 ...

---

<div class="post-metadata">

**Author:** ![gyana\_nayak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gyana_nayak/32/56498_2.png) [@gyana\_nayak](https://discuss.elastic.co/u/gyana_nayak)\
**Post date:** [October 16, 2020, 11:51am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/3 "2020-10-16T11:51:17Z")

</div>

@dadoonet May be the index already exists with a mapping before you are calling the `addIndexMapping` method?  
No. I verified this.

Just before inserting the first data i am creating index with required mapping.

> [@dadoonet](#):
>
> BTW did you look at [Cloud by Elastic](https://www.elastic.co/cloud), also available if needed from [AWS Marketplace](https://aws.amazon.com/marketplace/pp/B01N6YCISK) ?

This is not in my hand to suggest.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 16, 2020, 12:06pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/4 "2020-10-16T12:06:12Z")

</div>

> [@gyana\_nayak](#):
>
> Just before inserting the first data i am creating index with required mapping.

Is there a chance your code is multithreaded and an index operation is added before the index is actually created?

In general, I'd recommend using index templates instead. So if by mistake an index is created by a PUT document request, the right mapping will be created.

---

<div class="post-metadata">

**Author:** ![gyana\_nayak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gyana_nayak/32/56498_2.png) [@gyana\_nayak](https://discuss.elastic.co/u/gyana_nayak)\
**Post date:** [October 16, 2020, 12:14pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/5 "2020-10-16T12:14:02Z")

</div>

After applying below template still seeing same issue,Could you suggest me the required template.

```auto
PUT _template/template_1
{
  "index_patterns": [
    "te*",
    "bar*"
  ],
  "settings": {
    "number_of_shards": 3
  },
  "mappings": {
    "_source": {
      "enabled": false
    },
    "properties": {
      "host_name": {
        "type": "keyword"
      },
      "created_at": {
        "type": "date",
        "format": "EEE MMM dd HH:mm:ss Z yyyy"
      },
      "@timestamp": {
        "type": "date"
      },
      "@version": {
        "type": "keyword"
      }
    }
  }
} 

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 16, 2020, 12:26pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/6 "2020-10-16T12:26:11Z")

</div>

What is the index name?

Could you run:

```auto
GET /_cat/indices?v

```

---

<div class="post-metadata">

**Author:** ![gyana\_nayak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gyana_nayak/32/56498_2.png) [@gyana\_nayak](https://discuss.elastic.co/u/gyana_nayak)\
**Post date:** [October 16, 2020, 12:29pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/7 "2020-10-16T12:29:26Z")

</div>

> [@dadoonet](#):
>
> `GET /_cat/indices?v`

my index name is `sandbox`

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 16, 2020, 12:35pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/8 "2020-10-16T12:35:06Z")

</div>

Could you share the full output please?

---

<div class="post-metadata">

**Author:** ![gyana\_nayak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gyana_nayak/32/56498_2.png) [@gyana\_nayak](https://discuss.elastic.co/u/gyana_nayak)\
**Post date:** [October 16, 2020, 12:51pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/9 "2020-10-16T12:51:00Z")

</div>

After applying above index template, i see data is not pushing to index  
`health status index uuid pri rep docs.count docs.deleted store.size pri.store.size`  
`green open sandbox xZnFTDadQwWQUienyA38AA 3 2 0 0 2kb 690b`

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 16, 2020, 12:53pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/10 "2020-10-16T12:53:38Z")

</div>

The index template above does not apply to the `sandbox` index as the pattern specified does not match. What is the relevance of this template?

---

<div class="post-metadata">

**Author:** ![gyana\_nayak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gyana_nayak/32/56498_2.png) [@gyana\_nayak](https://discuss.elastic.co/u/gyana_nayak)\
**Post date:** [October 16, 2020, 1:10pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/11 "2020-10-16T13:10:32Z")

</div>

sorry for the confusion i actually modified the pattern

```auto
{
  "template_1" : {
    "order" : 0,
    "index_patterns" : [
      "san*",
      "bar*"
    ],
    "settings" : {
      "index" : {
        "number_of_shards" : "3"
      }
    },
    "mappings" : {
      "_source" : {
        "enabled" : false
      },
      "properties" : {
        "@timestamp" : {
          "type" : "date"
        },
        "@version" : {
          "type" : "keyword"
        },
        "created_at" : {
          "format" : "EEE MMM dd HH:mm:ss Z yyyy",
          "type" : "date"
        },
        "host_name" : {
          "type" : "keyword"
        }
      }
    },
    "aliases" : { }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 16, 2020, 1:58pm UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/12 "2020-10-16T13:58:42Z")

</div>

What mapping do you get if you recreate the index once this template has been uploaded?

---

<div class="post-metadata">

**Author:** ![gyana\_nayak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gyana_nayak/32/56498_2.png) [@gyana\_nayak](https://discuss.elastic.co/u/gyana_nayak)\
**Post date:** [October 18, 2020, 5:38am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/13 "2020-10-18T05:38:00Z")

</div>

thank you very much for your support. I could resolve the issue by applying proper index template.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 15, 2020, 5:38am UTC](https://discuss.elastic.co/t/elasticsearch-mapping-not-applied-to-aws-elk/252326/14 "2020-11-15T05:38:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
