# Failing to Create Mappings Logstash/Elasticsearch

**URL:** <https://discuss.elastic.co/t/failing-to-create-mappings-logstash-elasticsearch/52540>\
**Category:** Elasticsearch\
**Created:** [June 12, 2016, 4:08pm UTC](https://discuss.elastic.co/t/failing-to-create-mappings-logstash-elasticsearch/52540 "2016-06-12T16:08:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![fikse](https://avatars.discourse-cdn.com/v4/letter/f/c0e974/32.png) [@fikse](https://discuss.elastic.co/u/fikse)\
**Post date:** [June 12, 2016, 4:08pm UTC](https://discuss.elastic.co/t/failing-to-create-mappings-logstash-elasticsearch/52540/1 "2016-06-12T16:08:03Z")

</div>

I'm experiencing a problem where I'm trying to create new mappings for the indexed data, but I receive an error:

```auto
{
   "error": {
      "root_cause": [
         {
            "type": "illegal_argument_exception",
            "reason": "Mapper for [request] conflicts with existing mapping in other types:\n[mapper [request] has different [index] values, mapper [request] has different [doc_values] values, cannot change from disabled to enabled, mapper [request] has different [analyzer]]"
         }
      ],
      "type": "illegal_argument_exception",
      "reason": "Mapper for [request] conflicts with existing mapping in other types:\n[mapper [request] has different [index] values, mapper [request] has different [doc_values] values, cannot change from disabled to enabled, mapper [request] has different [analyzer]]"
   },
   "status": 400
}

```

I need to reindex, however, the data was thrown into elasticserach with the elasticserach logstash plugin... I used something like this to parse the nginx log.

At the very least I need the request field index type to be `not_analyzed`. Is there a way to index the data appropriately with logstash without needing to send a PUT request after the data is indexed. If not, how can I reindex the data which the elasticsearch logstash plugin output?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 12, 2016, 4:51pm UTC](https://discuss.elastic.co/t/failing-to-create-mappings-logstash-elasticsearch/52540/2 "2016-06-12T16:51:53Z")

</div>

Use index templates to set certain mappings for all new indexes whose name match a pattern. In this you need to make a copy of Logstash's original index template and modify it so the `request` field isn't analyzed. You'll also have to modify the index name pattern so it matches your actual index name. The default pattern assumes that the index name matches logstash-\*.

I note that your log index name doesn't include the date, i.e. the index will grow and grow indefinitely. That's not a good idea. Stick with time-series indexes.

---

<div class="post-metadata">

**Author:** ![fikse](https://avatars.discourse-cdn.com/v4/letter/f/c0e974/32.png) [@fikse](https://discuss.elastic.co/u/fikse)\
**Post date:** [June 14, 2016, 3:35pm UTC](https://discuss.elastic.co/t/failing-to-create-mappings-logstash-elasticsearch/52540/3 "2016-06-14T15:35:24Z")

</div>

Or is there a way to tell the client to search all `logstash-*` indices? Maybe I can query aliases?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 14, 2016, 4:55pm UTC](https://discuss.elastic.co/t/failing-to-create-mappings-logstash-elasticsearch/52540/4 "2016-06-14T16:55:30Z")

</div>

> Or is there a way to tell the client to search all logstash-\* indices?

Yes; see [Multi-target syntax | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/multi-index.html).

> Maybe I can query aliases?

That too.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:43pm UTC](https://discuss.elastic.co/t/failing-to-create-mappings-logstash-elasticsearch/52540/5 "2017-07-05T22:43:53Z")

</div>


