# Elasticsearch update mapping from text field to multifield with keyword fails

**URL:** <https://discuss.elastic.co/t/elasticsearch-update-mapping-from-text-field-to-multifield-with-keyword-fails/89651>\
**Category:** Elasticsearch\
**Created:** [June 16, 2017, 5:33am UTC](https://discuss.elastic.co/t/elasticsearch-update-mapping-from-text-field-to-multifield-with-keyword-fails/89651 "2017-06-16T05:33:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![test\_user](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@test\_user](https://discuss.elastic.co/u/test_user)\
**Post date:** [June 16, 2017, 5:33am UTC](https://discuss.elastic.co/t/elasticsearch-update-mapping-from-text-field-to-multifield-with-keyword-fails/89651/1 "2017-06-16T05:33:28Z")

</div>

Hi,

I am using

- Kibana 5.4:
- ElsaticSearch 5.4:
- Logstash: 5.4

I want to upgrade on my mapping (index without document delete documents with \_delete\_by\_query) one single filed single field to multifiled.

Current Mapping:  
curl -XGET 'localhost:9200/filebeat-2017.06.13/\_mapping?pretty'  
.  
.  
"message" : {  
"type" : "text",  
"norms" : false  
},  
.  
.

My Idea is to add "keyword" type field (as recommended mutlti field documentation) with following curl request, but it fails:

mpx@mqzhlmpx07:~\> curl -XPUT 'localhost:9200/filebeat-2017.06.13/\_mapping/log?pretty' -H 'Content-Type: application/json' -d'  
{  
"properties": {  
"message": {  
"type": "keyword"  
}  
}  
}  
'  
{  
"error" : {  
"root\_cause" : [  
{  
"type" : "illegal\_argument\_exception",  
"reason" : "mapper [message] of different type, current\_type [text], merged\_type [keyword]"  
}  
],  
"type" : "illegal\_argument\_exception",  
"reason" : "mapper [message] of different type, current\_type [text], merged\_type [keyword]"  
},  
"status" : 400  
}

Please help

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 16, 2017, 7:28am UTC](https://discuss.elastic.co/t/elasticsearch-update-mapping-from-text-field-to-multifield-with-keyword-fails/89651/2 "2017-06-16T07:28:34Z")

</div>

You can not update mappings on an existing index, so you will need to reindex into a new index with the updated mappings.

---

<div class="post-metadata">

**Author:** ![test\_user](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@test\_user](https://discuss.elastic.co/u/test_user)\
**Post date:** [June 16, 2017, 8:06am UTC](https://discuss.elastic.co/t/elasticsearch-update-mapping-from-text-field-to-multifield-with-keyword-fails/89651/3 "2017-06-16T08:06:45Z")

</div>

It is an empty index (all documents deleted by curl request) in order to avoid reindexing. According [https://www.elastic.co/blog/changing-mapping-with-zero-downtime](https://www.elastic.co/blog/changing-mapping-with-zero-downtime), I did following:  
mpx@mqzhlmpx07:/var/opt/six/mpx/Kibana\> curl -XPUT 'localhost:9200/filebeat-2017.06.13/\_mapping/log?pretty' -H 'Content-Type: application/json' -d'  
{  
"log": {  
"properties": {  
"message": {  
"type": "multi\_field",  
"fields": {  
"message": { "type": "text" },  
"message\_k": { "type": "keyword" }  
}  
}  
}  
}  
}  
'  
{  
"error" : {  
"root\_cause" : [  
{  
"type" : "mapper\_parsing\_exception",  
"reason" : "No handler for type [multi\_field] declared on field [message]"  
}  
],  
"type" : "mapper\_parsing\_exception",  
"reason" : "No handler for type [multi\_field] declared on field [message]"  
},  
"status" : 400  
}

Please tell me what is now wrong? (something to do with norms property?)

---

<div class="post-metadata">

**Author:** ![test\_user](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@test\_user](https://discuss.elastic.co/u/test_user)\
**Post date:** [July 10, 2017, 8:22pm UTC](https://discuss.elastic.co/t/elasticsearch-update-mapping-from-text-field-to-multifield-with-keyword-fails/89651/4 "2017-07-10T20:22:49Z")

</div>

Hello all,

Thanks to my valuable team members, I could elegantly solve the issue: Quoting the expression is solving the issue.  
Example:  
GET \_search  
{  
"query": {  
"query\_string": {"query": "message: "215.SODHK""}  
}  
}

Thus there is no need for an update on generated mapping. For me is this case closed

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 7, 2017, 8:22pm UTC](https://discuss.elastic.co/t/elasticsearch-update-mapping-from-text-field-to-multifield-with-keyword-fails/89651/5 "2017-08-07T20:22:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
