# Error message in logfile : Parse Failure \[No mapping found for \[@timestamp\] in order to sort on\]

**URL:** <https://discuss.elastic.co/t/error-message-in-logfile-parse-failure-no-mapping-found-for-timestamp-in-order-to-sort-on/17227>\
**Category:** Elasticsearch\
**Created:** [April 28, 2014, 9:24am UTC](https://discuss.elastic.co/t/error-message-in-logfile-parse-failure-no-mapping-found-for-timestamp-in-order-to-sort-on/17227 "2014-04-28T09:24:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![HansPeterSloot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hanspetersloot/32/51132_2.png) [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Post date:** [April 28, 2014, 9:24am UTC](https://discuss.elastic.co/t/error-message-in-logfile-parse-failure-no-mapping-found-for-timestamp-in-order-to-sort-on/17227/1 "2014-04-28T09:24:44Z")

</div>

Hello,

I see the message further below in the elastic search logfile:  
Can someone tell what is wrong?

Regards HansP

[2014-04-28 11:02:44,612][DEBUG][action.search.type] [u3060p]  
[kibana-int][0], node[8LhzSgxJSf2RxW9wFgxBLA], [P], s[STARTED]: Failed to  
execute [org.elasticsearch.action.search.SearchRequest@1bae4d4f] lastShard  
[true]  
org.elasticsearch.search.SearchParseException: [kibana-int][0]:  
query[filtered(ConstantScore(_:_))-\>BooleanFilter(+_:_  
+cache(@timestamp:[1398654164260 TO now])  
+BooleanFilter(+_:_))],from[-1],size[500]: Parse Failure [Failed to parse  
source  
[{"query":{"filtered":{"query":{"bool":{"should":[{"query\_string":{"query":"_"}}]}},"filter":{"bool":{"must":[{"match\_all":{}},{"range":{"@timestamp":{"from":1398654164260,"to":"now"}}},{"bool":{"must":[{"match\_all":{}}]}}]}}}},"highlight":{"fields":{},"fragment\_size":2147483647,"pre\_tags":["@start-highlight@"],"post\_tags":["@end-highlight@"]},"size":500,"sort":[{"@timestamp":{"order":"desc"}}]}]]  
at  
org.elasticsearch.search.SearchService.parseSource(SearchService.java:595)  
at  
org.elasticsearch.search.SearchService.createContext(SearchService.java:498)  
at  
org.elasticsearch.search.SearchService.createAndPutContext(SearchService.java:472)  
at  
org.elasticsearch.search.SearchService.executeQueryPhase(SearchService.java:244)  
at  
org.elasticsearch.search.action.SearchServiceTransportAction.sendExecuteQuery(SearchServiceTransportAction.java:202)  
at  
org.elasticsearch.action.search.type.TransportSearchQueryThenFetchAction$AsyncAction.sendExecuteFirstPhase(TransportSearchQueryThenFetchAction.java:80)  
at  
org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction.performFirstPhase(TransportSearchTypeAction.java:216)  
at  
org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction.performFirstPhase(TransportSearchTypeAction.java:203)  
at  
org.elasticsearch.action.search.type.TransportSearchTypeAction$BaseAsyncAction$2.run(TransportSearchTypeAction.java:186)  
at  
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1146)  
at  
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)  
at java.lang.Thread.run(Thread.java:701)  
Caused by: org.elasticsearch.search.SearchParseException: [kibana-int][0]:  
query[filtered(ConstantScore(_:_))-\>BooleanFilter(+_:\*  
+cache(@timestamp:[1398654164260 TO now])  
+BooleanFilter(+_:_))],from[-1],size[500]: Parse Failure [No mapping found  
for [@timestamp] in order to sort on]  
at  
org.elasticsearch.search.sort.SortParseElement.addSortField(SortParseElement.java:198)  
at  
org.elasticsearch.search.sort.SortParseElement.addCompoundSortField(SortParseElement.java:172)  
at  
org.elasticsearch.search.sort.SortParseElement.parse(SortParseElement.java:80)  
at  
org.elasticsearch.search.SearchService.parseSource(SearchService.java:583)  
... 11 more

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/296d044a-066c-4c82-b947-5a9db5ff8125%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/296d044a-066c-4c82-b947-5a9db5ff8125%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Binh\_Ly\_2](https://avatars.discourse-cdn.com/v4/letter/b/d07c76/32.png) [@Binh\_Ly\_2](https://discuss.elastic.co/u/Binh_Ly_2)\
**Post date:** [April 28, 2014, 1:45pm UTC](https://discuss.elastic.co/t/error-message-in-logfile-parse-failure-no-mapping-found-for-timestamp-in-order-to-sort-on/17227/2 "2014-04-28T13:45:05Z")

</div>

Is it possible that one of in the indexes you're querying against does not  
have the field @timestamp?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/70f2b01d-a10a-4dea-9fdd-f58e7dc56c19%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/70f2b01d-a10a-4dea-9fdd-f58e7dc56c19%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![HansPeterSloot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hanspetersloot/32/51132_2.png) [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Post date:** [April 29, 2014, 6:47am UTC](https://discuss.elastic.co/t/error-message-in-logfile-parse-failure-no-mapping-found-for-timestamp-in-order-to-sort-on/17227/3 "2014-04-29T06:47:19Z")

</div>

Well I am using elasticsearch as a logstash repository.

Can you give me a curl statement to check whether there are indexes without  
@timestamp?

Op maandag 28 april 2014 15:45:05 UTC+2 schreef Binh Ly:

> Is it possible that one of in the indexes you're querying against does not  
> have the field @timestamp?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/d5f858f8-5ab7-4b86-9c3d-bcb41647b548%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/d5f858f8-5ab7-4b86-9c3d-bcb41647b548%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [May 5, 2014, 10:18am UTC](https://discuss.elastic.co/t/error-message-in-logfile-parse-failure-no-mapping-found-for-timestamp-in-order-to-sort-on/17227/4 "2014-05-05T10:18:18Z")

</div>

Hey,

the problem is, that you are trying to search over all indices. One of  
those indices contains your kibana dashboards - which is just fine. However  
that index (named kibana-int) does not contain a timestamp field.

The most simple solution might be, to change your search to not search in  
that index or only include the indices you want to search in.

--Alex

On Tue, Apr 29, 2014 at 8:47 AM, HansPeterSloot  
[hanspeter.sloot@gmail.com](mailto:hanspeter.sloot@gmail.com)wrote:

> Well I am using elasticsearch as a logstash repository.
> 
> Can you give me a curl statement to check whether there are indexes  
> without @timestamp?
> 
> Op maandag 28 april 2014 15:45:05 UTC+2 schreef Binh Ly:
> 
> > Is it possible that one of in the indexes you're querying against does  
> > not have the field @timestamp?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/d5f858f8-5ab7-4b86-9c3d-bcb41647b548%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/d5f858f8-5ab7-4b86-9c3d-bcb41647b548%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/d5f858f8-5ab7-4b86-9c3d-bcb41647b548%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/d5f858f8-5ab7-4b86-9c3d-bcb41647b548%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .
> 
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAGCwEM\_xzp7MC%3Dx7j68Qn%3Dma6gkHnDyPkX3q4YE0nnzD-ZDxUA%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAGCwEM_xzp7MC%3Dx7j68Qn%3Dma6gkHnDyPkX3q4YE0nnzD-ZDxUA%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Firass\_Gzayil](https://avatars.discourse-cdn.com/v4/letter/f/90ced4/32.png) [@Firass\_Gzayil](https://discuss.elastic.co/u/Firass_Gzayil)\
**Post date:** [May 15, 2014, 12:41pm UTC](https://discuss.elastic.co/t/error-message-in-logfile-parse-failure-no-mapping-found-for-timestamp-in-order-to-sort-on/17227/5 "2014-05-15T12:41:38Z")

</div>

Goto your dashboard-\>settings-\>index and replace [\_all] with [logstash\*]

Firass

On Monday, May 5, 2014 1:18:18 PM UTC+3, Alexander Reelsen wrote:

> Hey,
> 
> the problem is, that you are trying to search over all indices. One of  
> those indices contains your kibana dashboards - which is just fine. However  
> that index (named kibana-int) does not contain a timestamp field.
> 
> The most simple solution might be, to change your search to not search in  
> that index or only include the indices you want to search in.
> 
> --Alex
> 
> On Tue, Apr 29, 2014 at 8:47 AM, HansPeterSloot \<[hanspet...@gmail.com](mailto:hanspet...@gmail.com)\<javascript:\>
> 
> > wrote:
> 
> > Well I am using elasticsearch as a logstash repository.
> > 
> > Can you give me a curl statement to check whether there are indexes  
> > without @timestamp?
> > 
> > Op maandag 28 april 2014 15:45:05 UTC+2 schreef Binh Ly:
> > 
> > > Is it possible that one of in the indexes you're querying against does  
> > > not have the field @timestamp?
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/d5f858f8-5ab7-4b86-9c3d-bcb41647b548%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/d5f858f8-5ab7-4b86-9c3d-bcb41647b548%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/d5f858f8-5ab7-4b86-9c3d-bcb41647b548%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/d5f858f8-5ab7-4b86-9c3d-bcb41647b548%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .
> > 
> > For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/3e65ee59-3d96-42cb-8507-9feba27db3f9%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3e65ee59-3d96-42cb-8507-9feba27db3f9%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:29am UTC](https://discuss.elastic.co/t/error-message-in-logfile-parse-failure-no-mapping-found-for-timestamp-in-order-to-sort-on/17227/6 "2017-07-06T01:29:11Z")

</div>


