# Errors after Elastic 6

**URL:** <https://discuss.elastic.co/t/errors-after-elastic-6/107776>\
**Category:** Logstash\
**Created:** [November 15, 2017, 3:15pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776 "2017-11-15T15:15:54Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![ocabj](https://avatars.discourse-cdn.com/v4/letter/o/f6c823/32.png) [@ocabj](https://discuss.elastic.co/u/ocabj)\
**Post date:** [November 15, 2017, 3:15pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/1 "2017-11-15T15:15:55Z")

</div>

I did an upgrade on my personal ELK stack to 6 yesterday and everything was fine until 1600PST / 0000 UTC.

[2017-11-14T16:00:05,887][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"apache-2017.11.15", :\_type=\>"apache", :\_routing=\>nil}, #LogStash::Event:0x53f53a4b], :response=\>{"index"=\>{"\_index"=\>"apache-2017.11.15", "\_type"=\>"apache", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"Failed to parse mapping [_default_]: No handler for type [string] declared on field [message]", "caused\_by"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"No handler for type [string] declared on field [message]"}}}}}

I am guessing that it has something to do with an incorrect index template. I tried to update the mapping template using:

# filebeat setup --template

Loaded index template

But it doesn't seem to help any.

---

<div class="post-metadata">

**Author:** ![ocabj](https://avatars.discourse-cdn.com/v4/letter/o/f6c823/32.png) [@ocabj](https://discuss.elastic.co/u/ocabj)\
**Post date:** [November 15, 2017, 3:34pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/2 "2017-11-15T15:34:29Z")

</div>

I resolved my own problem. The manual method to load the new template failed, so I added the elasticsearch output in filebeat to do the autoload, but I had a typo in the path to fields.yml.

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [December 4, 2017, 2:36pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/3 "2017-12-04T14:36:15Z")

</div>

I'm getting the same error, can you be more specific on how you fixed it?

---

<div class="post-metadata">

**Author:** ![ocabj](https://avatars.discourse-cdn.com/v4/letter/o/f6c823/32.png) [@ocabj](https://discuss.elastic.co/u/ocabj)\
**Post date:** [December 4, 2017, 2:52pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/4 "2017-12-04T14:52:51Z")

</div>

[https://www.elastic.co/guide/en/beats/filebeat/6.0/filebeat-template.html](https://www.elastic.co/guide/en/beats/filebeat/6.0/filebeat-template.html)

I used the default autoload method because the manual method failed. It  
required commenting out the logstash output since you can only have one  
output type in the filebeat config.

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [December 4, 2017, 3:47pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/5 "2017-12-04T15:47:51Z")

</div>

I exported the template with this

> sudo ./filebeat -c /etc/filebeat/filebeat.yml export template &\> ~/filebeat.template.json

Then loaded it with this since the machine running filebeat does not have access to elasticsearch.

> curl -XPUT -H 'Content-Type: application/json' [http://localhost:9200/\_template/filebeat-6.0.0](http://localhost:9200/_template/filebeat-6.0.0) -d@filebeat.template.json

But I am still getting the same errors. I restarted filebeat on the remote machine, logstash and elasticsearch on the es machine. What can I try next?

---

<div class="post-metadata">

**Author:** ![ocabj](https://avatars.discourse-cdn.com/v4/letter/o/f6c823/32.png) [@ocabj](https://discuss.elastic.co/u/ocabj)\
**Post date:** [December 4, 2017, 4:04pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/6 "2017-12-04T16:04:49Z")

</div>

Can you run filebeat locally on the same box as your elastic node?

Beyond that, I don't know why the manual install doesn't work as indicated  
in the docs.

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [December 4, 2017, 4:20pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/7 "2017-12-04T16:20:39Z")

</div>

No I have filebeat running on my AWS VMs to send apache logs to Logstash/ES which is local. Anyone else have ideas? Thanks!

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [December 4, 2017, 4:38pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/8 "2017-12-04T16:38:34Z")

</div>

Do I need to remove my old indices?

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [December 8, 2017, 3:49pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/9 "2017-12-08T15:49:06Z")

</div>

Does anyone have more ideas that can help? I can't seem to figure this out! I have a feeling I had upgraded incorrectly from 5.6 to 6.0 and that has something to do with it.

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [December 8, 2017, 6:28pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/10 "2017-12-08T18:28:03Z")

</div>

I've tried stopping logstash, importing the template again manually from the docs, deleting all old indices and filebeat indices and still this is occurring. Please help!

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [December 9, 2017, 12:35am UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/11 "2017-12-09T00:35:14Z")

</div>

Hours and hours later still can't get this to work, hoping for some help thanks.

---

<div class="post-metadata">

**Author:** ![gioadami](https://avatars.discourse-cdn.com/v4/letter/g/7ea924/32.png) [@gioadami](https://discuss.elastic.co/u/gioadami)\
**Post date:** [December 14, 2017, 3:02pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/12 "2017-12-14T15:02:47Z")

</div>

I had a similar problem

org.elasticsearch.index.mapper.MapperParsingException: Failed to parse mapping [_default_]: No handler for type [string] declared on field ...

and I solved it by changing the mapping type from " **string**" to " **text**" in the template.

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [December 14, 2017, 3:36pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/13 "2017-12-14T15:36:43Z")

</div>

Since I couldn't get help I ended up deleting my whole stack and starting over. Maybe for someone else this could help, where did you change the mapping type? How did you do it? What is the command or config change to fix it? For new people to ELK the docs are sparse and hard to understand.

---

<div class="post-metadata">

**Author:** ![gioadami](https://avatars.discourse-cdn.com/v4/letter/g/7ea924/32.png) [@gioadami](https://discuss.elastic.co/u/gioadami)\
**Post date:** [December 14, 2017, 4:03pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/14 "2017-12-14T16:03:39Z")

</div>

Here is the [documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html)

I made a PUT request on localhost:9200/\_template/mytemplate  
with body  
\_\_{template=mytemplate-\*, mappings={_default_={properties={logLevel={type=text}, timestamp={type=date}, eventType={type=text}}}}}  
and Authorization basic auth.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2018, 4:04pm UTC](https://discuss.elastic.co/t/errors-after-elastic-6/107776/15 "2018-01-11T16:04:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
