# ELK 6 and Future 7 and single type indexes

**URL:** <https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341>\
**Category:** Elasticsearch\
**Created:** [February 24, 2018, 4:10pm UTC](https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341 "2018-02-24T16:10:18Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [February 24, 2018, 4:10pm UTC](https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341/1 "2018-02-24T16:10:18Z")

</div>

I am trying to figure out the details on a single type index as I am on Elk 5 and upgrading to ELK6 and will upgrade to elk7 as soon as it is in beta.

My question is, since the \_type field is getting removed, but I am heavily dependant on it for searches, dashboards monitoring etc. Is there a way I can just "Disable" the field of having any special meaning? in ELK6 ( is \_type the same as type ?)

I know I could create different indexes for each type, but that would be over 300 different indexes each day. I probably could just set the same type for them all as I am just doing log aggregation, but then I would have to change every kibana dashboard, nagios query string, and any other developer process, as well as re-educate more user base to use a different field.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 24, 2018, 5:03pm UTC](https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341/2 "2018-02-24T17:03:06Z")

</div>

Did you read yet: [https://www.elastic.co/blog/removal-of-mapping-types-elasticsearch](https://www.elastic.co/blog/removal-of-mapping-types-elasticsearch) ?

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [February 24, 2018, 5:48pm UTC](https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341/3 "2018-02-24T17:48:31Z")

</div>

Yes, i have read through it well actually [https://www.elastic.co/guide/en/elasticsearch/reference/current/removal-of-types.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/removal-of-types.html) and was going to read it again but it covers so many different pieces that makes it vague in my mind.

I get creating a custom type field but in the past the \_type and type have the same value in prior versions. As I never created a type field but yet it exists and always seems to be the same value as \_type.

I guess the confusion is not the actual field in the index that I have a problem with, but how to deal with it with Logstash. maybe this should have been under logstash as a question instead

Since I set the "type" =\> "sometype" in each of the file inputs. I am not sure what I need to do and instead of just experimenting thought I would ask.

`input{ file { path => "/var/log/message" type => "somevalue" }}`

do I need to do something like  
`'input{ file {path => "/var/log/message" type=> "log", add_field => {"type","somvalue"}}}`

I guess it could also be mutated in a filter too but, I am trying to figure how to transition my existing rules with the least amount of effort.

I was just thinking about doing as I suggested by doing a mutate to "modify" \_type to a common value which will allow others to keep using "type" field without an issue.

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [February 26, 2018, 5:06pm UTC](https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341/4 "2018-02-26T17:06:10Z")

</div>

ok, found the solution to my logstash delema

just setting the  
output{  
elasticsearch {  
...  
...  
document\_type =\>  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 27, 2018, 3:29am UTC](https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341/5 "2018-02-27T03:29:15Z")

</div>

Just use the `tags` directive in Logstash, it'll add a similar thing.

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [February 27, 2018, 3:43am UTC](https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341/6 "2018-02-27T03:43:44Z")

</div>

How will adding a "tags" directive fix having multiple different \_type values in one index?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 27, 2018, 3:51am UTC](https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341/7 "2018-02-27T03:51:06Z")

</div>

Because you then don't define `document_type` and let the default apply.

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [February 27, 2018, 3:53am UTC](https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341/8 "2018-02-27T03:53:35Z")

</div>

I don't understand, but I will give it a try and see the results. (And read up on the details)

That is the best part of Dev cluster, I get to try anything! 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 27, 2018, 3:55am UTC](https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341/9 "2018-02-27T03:55:16Z")

</div>

`_type` is just a lucene field, it was just used in a way in Elasticsearch that wasn't the best.

So all you are doing is moving the values from `_type` into `tags`.

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [February 27, 2018, 2:27pm UTC](https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341/10 "2018-02-27T14:27:06Z")

</div>

Ah I got yah,

Oh I am not worrying about losing the \_type value, "type" is what everyone  
here uses but in the past \_type and type got set to the same value. So  
while I am using Logstash 2.3 on my remote systems, Kafka .09 and Logstash  
Indexer 5.6 talking to ES 6. I have to manipulate the \_type so I can  
keep the same functionality.

This will "supper" hybrid environment won't last as I am upgrading  
everything to 6 but I need some transition time so just trying to what is  
easy to get from point A to point Z with the least amount of effort.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2018, 2:27pm UTC](https://discuss.elastic.co/t/elk-6-and-future-7-and-single-type-indexes/121341/11 "2018-03-27T14:27:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
