# Fails to index due to conflicting doc type

**URL:** <https://discuss.elastic.co/t/fails-to-index-due-to-conflicting-doc-type/200748>\
**Category:** Logstash\
**Created:** [September 23, 2019, 8:21pm UTC](https://discuss.elastic.co/t/fails-to-index-due-to-conflicting-doc-type/200748 "2019-09-23T20:21:40Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [September 23, 2019, 8:21pm UTC](https://discuss.elastic.co/t/fails-to-index-due-to-conflicting-doc-type/200748/1 "2019-09-23T20:21:41Z")

</div>

Got the classic issue with a 6.8.3 cluster, I defined an index template and created it with ?include\_type\_name=false

```
{
  "index_patterns": ["esxi_firewall-*"],
  "mappings": {
    "properties": {
      "@timestamp": {
        "type": "date"
      },
      "fw": {
        "properties": {
          "ttl" : { "type": "long" },
          "len" : { "type": "long" },
          "id" : { "type": "long" },
          "urgp" : { "type": "long" },
          "window" : { "type": "long" },
          "tos" : { "type": "keyword" },
          "res" : { "type": "keyword" },
          "prec" : { "type": "keyword" },
          "proto" : { "type": "keyword" },
          "mark" : { "type": "keyword" },
          "out" : { "type": "keyword" }
        }
      },
      "ecs": {
        "properties": {
          "version": {
            "type": "keyword"
          }
        }
      },
      "message": {
        "type": "text",
        "fields": {
           "keyword": { "type" : "keyword" }
        }
      },
      "host": {
        "properties": {
          "name": {
            "type": "keyword"
          }
        }
      },
      "destination": {
        "properties": {
          "address": {
            "type": "keyword",
            "fields": {
              "text": { "type" : "text" }
            }
          },
          "ip": {
            "type": "ip"
          },
          "port": {
            "type": "long"
          }
        }
      },
      "source": {
        "properties": {
          "address": {
            "type": "keyword",
            "fields": {
              "text": { "type" : "text" }
            }
          },
          "ip": {
            "type": "ip"
          },
          "port": {
            "type": "long"
          }
        }
      }
    }
  }
}

```

but when logstash attempt to index documents I get the conflicting document type:

```
[2019-09-23T21:59:42,025][WARN][logstash.outputs.elasticsearch] Could not index
sponse=>{"index"=>{"_index"=>"esxi_firewall-2019.09.23", "_type"=>"doc", "_id"=>...
would have more than 1 type: [_doc, doc]"}}}}

```

output plugin configured without any document\_type:

```
elasticsearch {
   #cluster => 'mxes2data'
   id => 'mxes2data'
   index => '%{[@metadata][esindex]}-%{+YYYY.MM.dd}'
   action => 'index'
   codec => 'plain'
   user => '<redacted>'
   password => '<redacted>'
   sniffing => false
   manage_template => false
   template_overwrite => true
   hosts => ['<redacted>:9200','<redacted>:9200','<redacted>:9200']
}

```

}

wondering from where the 'doc' value comes?

Also attempting to map as much as possible to ECS 1.1, only not sure if the core field: ecs.version is just a dotted name or true nested and what nested field prefix to hide custom field under.

Any hints appreciated!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 23, 2019, 9:37pm UTC](https://discuss.elastic.co/t/fails-to-index-due-to-conflicting-doc-type/200748/2 "2019-09-23T21:37:23Z")

</div>

> [@stefws](#):
>
> wondering from where the 'doc' value comes?

An [old](https://discuss.elastic.co/t/how-to-move-away-from-default-document-type-mapping-doc/157095/4) version of filebeat?

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [September 23, 2019, 9:45pm UTC](https://discuss.elastic.co/t/fails-to-index-due-to-conflicting-doc-type/200748/3 "2019-09-23T21:45:48Z")

</div>

Nope got no data or no index until first doc/event is processed by logstash. It'll create the index but it holds no documents after this and logstash just complains as if it is trying to store the first 'doc' typed document, only ES refuses as it expects \_type to be \_doc...

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 23, 2019, 9:48pm UTC](https://discuss.elastic.co/t/fails-to-index-due-to-conflicting-doc-type/200748/4 "2019-09-23T21:48:31Z")

</div>

Right, and the first document that is indexed has type \_doc, so you cannot subsequently insert a document of type doc.

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [September 24, 2019, 4:22am UTC](https://discuss.elastic.co/t/fails-to-index-due-to-conflicting-doc-type/200748/5 "2019-09-24T04:22:26Z")

</div>

But the first doc to get indexed is failing as such and I don’t specify any document type anywhere, so from where is the type doc picked up by logstash?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 24, 2019, 4:31am UTC](https://discuss.elastic.co/t/fails-to-index-due-to-conflicting-doc-type/200748/6 "2019-09-24T04:31:00Z")

</div>

It looks like `doc` and not `_doc` is the [default of the elasticsearch output plugin](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-document_type). Is this really correct??

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [September 24, 2019, 5:59am UTC](https://discuss.elastic.co/t/fails-to-index-due-to-conflicting-doc-type/200748/7 "2019-09-24T05:59:07Z")

</div>

Seems that way as tcpdump shows this is POSTed from logstash 6.8.3 for the first doc and ES expects type: \_doc:

```
..[.....POST /_bulk HTTP/1.1
Connection: Keep-Alive
Content-Type: application/json
Content-Length: 942
Host: <redacted>:9200
User-Agent: Manticore 0.6.4
Accept-Encoding: gzip,deflate
Authorization: Basic <redacted>

{"index":{"_id":null,"_index":"esxi_firewall-2019.09.24","_type":"doc","routing":null}}
....

```

And are not allowed to do mutate+add\_field for meta data field \_type, so howto alter this I dunno 😕

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [September 24, 2019, 6:33am UTC](https://discuss.elastic.co/t/fails-to-index-due-to-conflicting-doc-type/200748/8 "2019-09-24T06:33:06Z")

</div>

Changed the template to include the type 'doc' for now... to get this to work 🙂

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [September 24, 2019, 6:57am UTC](https://discuss.elastic.co/t/fails-to-index-due-to-conflicting-doc-type/200748/9 "2019-09-24T06:57:28Z")

</div>

> [@stefws](#):
>
> Also attempting to map as much as possible to ECS 1.1, only not sure if the core field: ecs.version is just a dotted name or true nested and what nested field prefix to hide custom field under.

Any comments concerning ECS adaption?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2019, 6:57am UTC](https://discuss.elastic.co/t/fails-to-index-due-to-conflicting-doc-type/200748/10 "2019-10-22T06:57:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
