# ES 6.x: mapping types

**URL:** <https://discuss.elastic.co/t/es-6-x-mapping-types/119079>\
**Category:** Elasticsearch\
**Created:** [February 8, 2018, 3:30pm UTC](https://discuss.elastic.co/t/es-6-x-mapping-types/119079 "2018-02-08T15:30:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jeroen\_Ruigrok\_van\_d](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeroen_ruigrok_van_d/32/27477_2.png) [@Jeroen\_Ruigrok\_van\_d](https://discuss.elastic.co/u/Jeroen_Ruigrok_van_d)\
**Post date:** [February 8, 2018, 3:30pm UTC](https://discuss.elastic.co/t/es-6-x-mapping-types/119079/1 "2018-02-08T15:30:27Z")

</div>

Currently in the process of upgrading our Elastic setup to 6.x and I am a bit lost with the intent of some changes made.

In the past I had set up Logstash to accept apache log files via filebeat as well as a manual spooling process via the input plugin. With the input plugin I had things like:

```
input {
  file {
    path => "/path/to/site_access.log"
    start_position => "beginning"
    "[@metadata][type]" => "apache"
  }
}

filter {
  if [@metadata][type] == "apache" {
    mutate {
      replace => {
        "host" => "indexer01"
      }
    }
  }
}

```

And then the apache filter:

```
filter {
  if [@metadata][type] == "apache" {
    grok {
      match => { "message" => "\A\[%{HTTPDATE:accept_date}\] %{IP:client_ip} %{NOTSPACE:tls_protocol} %{NOTSPACE:cipher} \"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:http_version})?|%{DATA:raw_request})\" %{NUMBER:status_code:int} %{NOTSPACE:bytes:int} %{NUMBER:duration:int} %{QS:referrer} %{QS:agent}" }
    }
    date {
      match => ["accept_date", "dd/MMM/yyyy:HH:mm:ss Z"]
    }
    mutate {
      gsub => [
        "agent", "\"", "",
        "referrer", "\"", ""
      ]
    }
    ruby {
      code => "
        begin
          event.set('bytes', nil) if event.get('bytes') == '-'
          event.set('duration', nil) if event.get('duration') == '-'
          event.set('agent', nil) if event.get('agent') == '-'
          event.set('referrer', nil) if event.get('referrer') == '-'
        end
      "
    }
  }
}

```

Followed by elasticsearch output:

```
output {
  elasticsearch {
    hosts => ["http://storage01:9200"]
    index => "%{[@metadata][type]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
  }
}

```

And on Elasticsearch I have a template:

```
{
  "index_patterns": ["apache-*"],
  "mappings": {
    "apache": {
      "properties": {
        "accept_date": {
          "type": "date",
          "format": "dd/MMM/yyyy:HH:mm:ss Z||strict_date_optional_time||epoch_millis"
        },
        "agent": {
          "type": "keyword"
        },
        "bytes": {
          "type": "long"
        },
        "cipher": {
          "type": "keyword"
        },
        "client_ip": {
          "type": "ip"
        },
        "duration": {
          "type": "long"
        },
        "host": {
          "type": "keyword"
        },
        "http_version": {
          "type": "keyword"
        },
        "referrer": {
          "type": "text"
        },
        "request": {
          "type": "text"
        },
        "status_code": {
          "type": "keyword"
        },
        "tls_protocol": {
          "type": "keyword"
        },
        "verb": {
          "type": "keyword"
        }
      }
    }
  }
}

```

This will result in data in Elasticsearch with `_type` set to apache.

Now, the moment I remove `document_type`, since it's deprecated, the elasticsearch output plugin will set `_type` to `doc` (as documented on [document\_type](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-document_type)). This will result in an error: Rejecting mapping update to [apache-2018.02.08] as the final mapping would have more than 1 type: [apache, doc]

What is the intended way forward? I can work around it by specifying the mapping name in the apache template as `doc`, but that seems a bit silly. I can also keep `document_type` around to set it to apache, which will then match the template's mapping name, but that would sort of defeat the whole purpose of removing deprecated things.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [February 9, 2018, 2:47am UTC](https://discuss.elastic.co/t/es-6-x-mapping-types/119079/2 "2018-02-09T02:47:27Z")

</div>

The best way forward is to just create a new index with a new template that uses `doc` instead of `apache`.

You might need to delete the current apache-2018.02.08 for this to work. Or, you could stop ingestion, reindex that index to `apache-2018.02.08_1` with `doc` as the mapping type, and then delete the old `apache-2018.02.08` and let Logstash create a "new" version with `doc` as the mapping type, preserving your index data.

---

<div class="post-metadata">

**Author:** ![Jeroen\_Ruigrok\_van\_d](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeroen_ruigrok_van_d/32/27477_2.png) [@Jeroen\_Ruigrok\_van\_d](https://discuss.elastic.co/u/Jeroen_Ruigrok_van_d)\
**Post date:** [February 9, 2018, 8:36am UTC](https://discuss.elastic.co/t/es-6-x-mapping-types/119079/3 "2018-02-09T08:36:59Z")

</div>

@theuntergeek Alright, then I'll do that. No need for reindexing, thankfully, since I am able to build everything from scratch at the moment.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2018, 8:37am UTC](https://discuss.elastic.co/t/es-6-x-mapping-types/119079/4 "2018-03-09T08:37:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
