# Failed to parse mapping \[\_default\_\]: Mapping definition for \[error\] has unsupported parameters

**URL:** <https://discuss.elastic.co/t/failed-to-parse-mapping--default--mapping-definition-for-error-has-unsupported-parameters/98259>\
**Category:** Beats\
**Created:** [August 24, 2017, 3:35pm UTC](https://discuss.elastic.co/t/failed-to-parse-mapping--default--mapping-definition-for-error-has-unsupported-parameters/98259 "2017-08-24T15:35:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ianseyer](https://avatars.discourse-cdn.com/v4/letter/i/edb3f5/32.png) [@ianseyer](https://discuss.elastic.co/u/ianseyer)\
**Post date:** [August 24, 2017, 3:35pm UTC](https://discuss.elastic.co/t/failed-to-parse-mapping--default--mapping-definition-for-error-has-unsupported-parameters/98259/1 "2017-08-24T15:35:22Z")

</div>

I am using a lightly customized installation of all 6.0.0-beta1 beats.

However, When attempting to start them, they all spew this error:

```auto
 2017/08/22 19:58:16.455956 client.go:465: WARN Can not index event (status=400): {"type":"mapper_parsing_exception","reason":"Failed to parse mapping [_default_]: Mapping definition for [error] has unsupported parameters: [properties : {code={type=long}, message={norms=false, type=text}, type={ignore_above=1024, type=keyword}}]","caused_by":{"type":"mapper_parsing_exception","reason":"Mapping definition for [error] has unsupported parameters: [properties : {code={type=long}, message={norms=false, type=text}, type={ignore_above=1024, type=keyword}}]"}}

```

I have set `setup.template.overwrite: true`in all of the config files, and I have also run `docker run --add-host "elasticsearch:xxx.xxx.xx.xx" docker.elastic.co/beats/<beat>beat:6.0.0-beta1 setup --template`

I am not sure how to interpret this error at all; I am trying to use defaults.

Running on amazonlinux, docker 17.03.1-ce, elasticsearch 5.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [August 24, 2017, 6:05pm UTC](https://discuss.elastic.co/t/failed-to-parse-mapping--default--mapping-definition-for-error-has-unsupported-parameters/98259/2 "2017-08-24T18:05:16Z")

</div>

Hi @ianseyer,

Thank you for the report! I've tested several versions of Elasticsearch and didn't reproduce the issue, could you please share the exact version of Elasticsearch you are using?

Best regards

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 24, 2017, 6:07pm UTC](https://discuss.elastic.co/t/failed-to-parse-mapping--default--mapping-definition-for-error-has-unsupported-parameters/98259/3 "2017-08-24T18:07:23Z")

</div>

I also was unable to reproduce with Filebeat 6.0.0-beta1 and Elasticsearch 5.5.2. Can you please post the Filebeat config you are using too.

---

<div class="post-metadata">

**Author:** ![ianseyer](https://avatars.discourse-cdn.com/v4/letter/i/edb3f5/32.png) [@ianseyer](https://discuss.elastic.co/u/ianseyer)\
**Post date:** [August 28, 2017, 2:55pm UTC](https://discuss.elastic.co/t/failed-to-parse-mapping--default--mapping-definition-for-error-has-unsupported-parameters/98259/4 "2017-08-28T14:55:15Z")

</div>

ElasticSearch version:

```auto
 "version": {
    "number": "5.5.1",
    "build_hash": "19c13d0",
    "build_date": "2017-07-18T20:44:24.823Z",
    "build_snapshot": false,
    "lucene_version": "6.6.0"
  },

```

My `filebeat.yml`:

```auto
filebeat.config:
  prospectors:
    path: ${path.config}/prospectors.d/*.yml
    reload.enabled: false
  modules:
    path: ${path.config}/modules.d/*.yml
    reload.enabled: false

processors:
- add_cloud_metadata:

output.elasticsearch:
  hosts: ['elasticsearch:9200']

name: "msgio-admin"
tags: ["msgio-admin"]

setup.template.overwrite: true

```

And my prospectors:

```auto
- input_type: log
  paths:
    - /mnt/log/httpd/access_log

- input_type: log
  paths:
    - /mnt/log/php/laravel.log

```

I have set `elasticsearch` to point to my actual es host via extra\_hosts in docker compose.

I have also confirmed read/write abilities on the prospector paths, and tried disabling my apache module both to no avail. Nothing is getting written to the `logs/` directory either.

UPDATE: I have since been able to nail this down to an issue with my laravel log file. Still no idea how to resolve it, though. Removing the laravel log from the prospectors file solves the problem. However, I need that file to be logged.

I have confirmed that can successfully read from the mounted directory by launching an alpine image with the same mounted volumes and `cat`ing their contents.

@andrewkroh @exekias any ideas?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 29, 2017, 8:57pm UTC](https://discuss.elastic.co/t/failed-to-parse-mapping--default--mapping-definition-for-error-has-unsupported-parameters/98259/5 "2017-08-29T20:57:49Z")

</div>

So when you remove

```auto
- input_type: log
  paths:
    - /mnt/log/php/laravel.log

```

from your config file the `mapper_parsing_exception` stops?

If that's the case then I would disable the ES output temporarily and enable the file output to inspect the events being generated from the `laravel.log` file. Alternatively you could temporarily enable debug logging (that should log the events being sent to ES).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2017, 3:35pm UTC](https://discuss.elastic.co/t/failed-to-parse-mapping--default--mapping-definition-for-error-has-unsupported-parameters/98259/6 "2017-09-14T15:35:36Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
