# Filebeat v6 and elasticsearch v6

**URL:** <https://discuss.elastic.co/t/filebeat-v6-and-elasticsearch-v6/107925>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 16, 2017, 11:52am UTC](https://discuss.elastic.co/t/filebeat-v6-and-elasticsearch-v6/107925 "2017-11-16T11:52:59Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gianluca\_Tranelli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gianluca_tranelli/32/24321_2.png) [@Gianluca\_Tranelli](https://discuss.elastic.co/u/Gianluca_Tranelli)\
**Post date:** [November 16, 2017, 11:53am UTC](https://discuss.elastic.co/t/filebeat-v6-and-elasticsearch-v6/107925/1 "2017-11-16T11:53:00Z")

</div>

I set up filebeat and elasticsearch on the same machine and till v5.6 all was working good.  
Now in elasticsearch log i found the following error line each per event:

2017-11-16T12:45:06+01:00 WARN Can not index event (status=400): {"type":"mapper\_parsing\_exception","reason":"Failed to parse mapping [doc]: Mapping definition for [error] has unsupported parameters: [properties : {code={type=long}, type={ignore\_above=1024, type=keyword}, message={norms=false, type=text}}]","caused\_by":{"type":"mapper\_parsing\_exception","reason":"Mapping definition for [error] has unsupported parameters: [properties : {code={type=long}, type={ignore\_above=1024, type=keyword}, message={norms=false, type=text}}]"}}

What can it be the problem?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 16, 2017, 2:12pm UTC](https://discuss.elastic.co/t/filebeat-v6-and-elasticsearch-v6/107925/2 "2017-11-16T14:12:19Z")

</div>

Can you share your filebeat configuration? The default index names in recent filebeat are versioned as well. There shouldn't be a conflict, unless you still write in the old index.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [November 16, 2017, 2:19pm UTC](https://discuss.elastic.co/t/filebeat-v6-and-elasticsearch-v6/107925/3 "2017-11-16T14:19:05Z")

</div>

Also, using Kibana Console, can you do `GET /filebeat-*/_mapping` and `GET _template/filebeat-*` and paste the output in a pastebin or similar. Unless you have added custom fields to the templates, those two commands shouldn't leak any private information.

---

<div class="post-metadata">

**Author:** ![Gianluca\_Tranelli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gianluca_tranelli/32/24321_2.png) [@Gianluca\_Tranelli](https://discuss.elastic.co/u/Gianluca_Tranelli)\
**Post date:** [November 17, 2017, 1:06pm UTC](https://discuss.elastic.co/t/filebeat-v6-and-elasticsearch-v6/107925/4 "2017-11-17T13:06:28Z")

</div>

Here is the filebeat configuration

[https://pastebin.com/embed\_iframe/sXg1yU18](https://pastebin.com/embed_iframe/sXg1yU18)

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Gianluca\_Tranelli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gianluca_tranelli/32/24321_2.png) [@Gianluca\_Tranelli](https://discuss.elastic.co/u/Gianluca_Tranelli)\
**Post date:** [November 17, 2017, 1:15pm UTC](https://discuss.elastic.co/t/filebeat-v6-and-elasticsearch-v6/107925/5 "2017-11-17T13:15:54Z")

</div>

Note that logstash and winlogbeat works perfectly, only filebeat have problem.  
Here is :  
GET /filebeat-_/\_mapping  
{  
"error": {  
"root\_cause": [  
{  
"type": "index\_not\_found\_exception",  
"reason": "no such index",  
"index\_uuid": "na",  
"index": "filebeat-_"  
}  
],  
"type": "index\_not\_found\_exception",  
"reason": "no such index",  
"index\_uuid": "_na_",  
"index": "filebeat-\*"  
},  
"status": 404  
}

and

GET \_template/filebeat-\*  
[https://pastebin.com/miak7wbu](https://pastebin.com/miak7wbu)

---

<div class="post-metadata">

**Author:** ![nsteinmetz](https://avatars.discourse-cdn.com/v4/letter/n/fbc32d/32.png) [@nsteinmetz](https://discuss.elastic.co/u/nsteinmetz)\
**Post date:** [November 29, 2017, 2:38pm UTC](https://discuss.elastic.co/t/filebeat-v6-and-elasticsearch-v6/107925/6 "2017-11-29T14:38:46Z")

</div>

Hi,

Just had the same issue, you need to update the template for filebeat & es6.

You have the new mapping file in `/etc/filebeat/filebeat.template-es6.json`

I deleted the previous one and load the new one but there may be a better option if you need to keep your data.

```auto
curl -XDELETE http://localhost:9200/_template/filebeat
curl -XPUT -H 'Content-Type: application/json' http://localhost:9200/_template/filebeat -d@filebeat.template-es6x.json

```

See [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html)

Maybe there is a smarter way with some alias ?

---

<div class="post-metadata">

**Author:** ![nsteinmetz](https://avatars.discourse-cdn.com/v4/letter/n/fbc32d/32.png) [@nsteinmetz](https://discuss.elastic.co/u/nsteinmetz)\
**Post date:** [December 5, 2017, 3:54pm UTC](https://discuss.elastic.co/t/filebeat-v6-and-elasticsearch-v6/107925/7 "2017-12-05T15:54:27Z")

</div>

Seems a better option is to have a dedicated template for filebeat 6.0.0 to avoid compatibility issues between 2 différent versions.

> [@nsteinmetz](#):
>
> curl -XPUT -H 'Content-Type: application/json' [http://localhost:9200/\_template/filebeat-6.0.0](http://localhost:9200/_template/filebeat-6.0.0) -d@filebeat.template-es6x.json

And then voilà 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2018, 3:54pm UTC](https://discuss.elastic.co/t/filebeat-v6-and-elasticsearch-v6/107925/8 "2018-01-02T15:54:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
