# How to alter GET /index/\_mapping output to work with PUT /index/\_mapping

**URL:** <https://discuss.elastic.co/t/how-to-alter-get-index-mapping-output-to-work-with-put-index-mapping/219260>\
**Category:** Elasticsearch\
**Created:** [February 13, 2020, 5:17pm UTC](https://discuss.elastic.co/t/how-to-alter-get-index-mapping-output-to-work-with-put-index-mapping/219260 "2020-02-13T17:17:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![LansK](https://avatars.discourse-cdn.com/v4/letter/l/dc4da7/32.png) [@LansK](https://discuss.elastic.co/u/LansK)\
**Post date:** [February 13, 2020, 5:17pm UTC](https://discuss.elastic.co/t/how-to-alter-get-index-mapping-output-to-work-with-put-index-mapping/219260/1 "2020-02-13T17:17:19Z")

</div>

I am upgrading elasticsearch from 2.x to 7.x. I am trying to re-add index mappings from 2.x. I want to know how to alter a mapping to make it compatible with 7.x.

Here is the result of GET /syslog/\_mapping from 2.x

```
{
	"syslog": {
		"mappings": {
			"syslog": {
				"properties": {
					"@timestamp": {
						"type": "date",
						"format": "dateOptionalTime"
					},
					"@version": {
						"type": "string"
					},
					"_index": {
						"type": "string"
					},
					"_type": {
						"type": "string"
					},
					"file": {
						"type": "string"
					},
					"host": {
						"type": "string"
					},
					"message": {
						"type": "string"
					},
					"offset": {
						"type": "string"
					},
					"received_at": {
						"type": "date",
						"format": "dateOptionalTime"
					},
					"received_from": {
						"type": "string"
					},
					"syslog_facility": {
						"type": "string"
					},
					"syslog_facility_code": {
						"type": "long"
					},
					"syslog_hostname": {
						"type": "string"
					},
					"syslog_message": {
						"type": "string"
					},
					"syslog_pid": {
						"type": "string"
					},
					"syslog_program": {
						"type": "string"
					},
					"syslog_severity": {
						"type": "string"
					},
					"syslog_severity_code": {
						"type": "long"
					},
					"syslog_timestamp": {
						"type": "string"
					}
				}
			}
		}
	}
}

```

I try adding adding the mapping by doing this in 7.6

```
PUT /syslog/_mapping
{
	"syslog": {
		"mappings": {
			"syslog": {
				"properties": {
					"@timestamp": {
						"type": "date",
						"format": "dateOptionalTime"
					},
					"@version": {
						"type": "string"
					},
					"_index": {
						"type": "string"
					},
					"_type": {
						"type": "string"
					},
					"file": {
						"type": "string"
					},
					"host": {
						"type": "string"
					},
					"message": {
						"type": "string"
					},
					"offset": {
						"type": "string"
					},
					"received_at": {
						"type": "date",
						"format": "dateOptionalTime"
					},
					"received_from": {
						"type": "string"
					},
					"syslog_facility": {
						"type": "string"
					},
					"syslog_facility_code": {
						"type": "long"
					},
					"syslog_hostname": {
						"type": "string"
					},
					"syslog_message": {
						"type": "string"
					},
					"syslog_pid": {
						"type": "string"
					},
					"syslog_program": {
						"type": "string"
					},
					"syslog_severity": {
						"type": "string"
					},
					"syslog_severity_code": {
						"type": "long"
					},
					"syslog_timestamp": {
						"type": "string"
					}
				}
			}
		}
	}
}

```

But I get the following error

```
{
  "error" : {
    "root_cause" : [
      {
        "type" : "mapper_parsing_exception",
        "reason" : "Root mapping definition has unsupported parameters: [syslog : {mappings={syslog={properties={syslog_pid={type=string}, syslog_severity_code={type=long}, _index={type=string}, offset={type=string}, syslog_facility={type=string}, _type={type=string}, syslog_facility_code={type=long}, syslog_program={type=string}, message={type=string}, syslog_message={type=string}, syslog_severity={type=string}, received_from={type=string}, @timestamp={format=dateOptionalTime, type=date}, file={type=string}, syslog_hostname={type=string}, received_at={format=dateOptionalTime, type=date}, syslog_timestamp={type=string}, @version={type=string}, host={type=string}}}}}]"
      }
    ],
    "type" : "mapper_parsing_exception",
    "reason" : "Root mapping definition has unsupported parameters: [syslog : {mappings={syslog={properties={syslog_pid={type=string}, syslog_severity_code={type=long}, _index={type=string}, offset={type=string}, syslog_facility={type=string}, _type={type=string}, syslog_facility_code={type=long}, syslog_program={type=string}, message={type=string}, syslog_message={type=string}, syslog_severity={type=string}, received_from={type=string}, @timestamp={format=dateOptionalTime, type=date}, file={type=string}, syslog_hostname={type=string}, received_at={format=dateOptionalTime, type=date}, syslog_timestamp={type=string}, @version={type=string}, host={type=string}}}}}]"
  },
  "status" : 400
}

```

It does not tell me what the unsupported parameters are (and instead lists everything). Which parameters are not supported? How can I format it correctly so that is is accepted by the mapping API?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 14, 2020, 9:31am UTC](https://discuss.elastic.co/t/how-to-alter-get-index-mapping-output-to-work-with-put-index-mapping/219260/2 "2020-02-14T09:31:14Z")

</div>

The JSON structure has been changed over the years, and you need to change yours in order to work with Elasticsearch 7 here.

---

<div class="post-metadata">

**Author:** ![LansK](https://avatars.discourse-cdn.com/v4/letter/l/dc4da7/32.png) [@LansK](https://discuss.elastic.co/u/LansK)\
**Post date:** [February 16, 2020, 10:12am UTC](https://discuss.elastic.co/t/how-to-alter-get-index-mapping-output-to-work-with-put-index-mapping/219260/3 "2020-02-16T10:12:47Z")

</div>

I have tried to match what I found here [https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html)

but I still get the same error using this updated JSON

```
PUT /syslog/_mapping
{
	"mappings": {
		"properties": {
			"@timestamp": {
				"type": "date",
				"format": "dateOptionalTime"
			},
			"@version": {
				"type": "string"
			},
			"_index": {
				"type": "string"
			},
			"_type": {
				"type": "string"
			},
			"file": {
				"type": "string"
			},
			"host": {
				"type": "string"
			},
			"message": {
				"type": "string"
			},
			"offset": {
				"type": "string"
			},
			"received_at": {
				"type": "date",
				"format": "dateOptionalTime"
			},
			"received_from": {
				"type": "string"
			},
			"syslog_facility": {
				"type": "string"
			},
			"syslog_facility_code": {
				"type": "long"
			},
			"syslog_hostname": {
				"type": "string"
			},
			"syslog_message": {
				"type": "string"
			},
			"syslog_pid": {
				"type": "string"
			},
			"syslog_program": {
				"type": "string"
			},
			"syslog_severity": {
				"type": "string"
			},
			"syslog_severity_code": {
				"type": "long"
			},
			"syslog_timestamp": {
				"type": "string"
			}
		}
	}
}

```

Because the error is unhelpful I am unable to solve this. I don't know if it is a bad property, bad JSON, or anything else. Please let me know what the error is with my mapping statement as I am unable to figure it out from the error elasticsearch gives and the docs.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [February 16, 2020, 12:32pm UTC](https://discuss.elastic.co/t/how-to-alter-get-index-mapping-output-to-work-with-put-index-mapping/219260/4 "2020-02-16T12:32:36Z")

</div>

According to the [Put Mapping API docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html) a put-mapping request looks like this:

```nohighlight
PUT /syslog/_mapping
{
  "properties": {
     ...
  }
}

```

Yours looks different:

```nohighlight
PUT /syslog/_mapping
{
  "mappings": {
    "properties": {
      ...
    }
  }
}

```

The error message says `Root mapping definition has unsupported parameters: [mappings : {properties ...` which tells you that the `mappings` key is indeed unexpected here.

---

<div class="post-metadata">

**Author:** ![LansK](https://avatars.discourse-cdn.com/v4/letter/l/dc4da7/32.png) [@LansK](https://discuss.elastic.co/u/LansK)\
**Post date:** [February 16, 2020, 1:43pm UTC](https://discuss.elastic.co/t/how-to-alter-get-index-mapping-output-to-work-with-put-index-mapping/219260/5 "2020-02-16T13:43:40Z")

</div>

Thank you! I am getting errors I can look up now, so progress is being made. I was mistakenly focused on this part of the docs since it was closest to the older formulation [https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html#add-multi-fields-existing-field-ex](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html#add-multi-fields-existing-field-ex)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2020, 1:43pm UTC](https://discuss.elastic.co/t/how-to-alter-get-index-mapping-output-to-work-with-put-index-mapping/219260/6 "2020-03-15T13:43:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
