# How to change ignore\_above?

**URL:** <https://discuss.elastic.co/t/how-to-change-ignore-above/111873>\
**Category:** Elasticsearch\
**Created:** [December 14, 2017, 11:06pm UTC](https://discuss.elastic.co/t/how-to-change-ignore-above/111873 "2017-12-14T23:06:19Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![marksarnold](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marksarnold/32/25611_2.png) [@marksarnold](https://discuss.elastic.co/u/marksarnold)\
**Post date:** [December 14, 2017, 11:06pm UTC](https://discuss.elastic.co/t/how-to-change-ignore-above/111873/1 "2017-12-14T23:06:19Z")

</div>

I have an index with an auto-generated mapping (see [attachment](https://github.com/marksarnold/elastic_post_files/tree/master/change_ignore_above)).

The field "log4j\_root\_cause" contains a Java stacktrace that might be quite lengthy.  
After importing data, I see that there are many documents that have a full stacktrace in log4j\_root\_cause.  
However, for many of those, the field log4j\_root\_cause.keyword is empty, even though field log4j\_root\_cause is not.

I assume that has to do with the content of log4j\_root\_cause being longer than 256 (the value of ignore\_above).

How can I change this?

I tried this:  
curl -XPUT 'localhost:9200/log4j2-generic/\_mapping/javastacktrace' -H 'Content-Type: application/json' -d'  
{  
"properties": {  
"log4j\_root\_cause": {  
"ignore\_above": 20000,  
"type": "keyword",  
"index":"true"  
}  
}  
}  
'  
but it gave me  
`{"error":{"root_cause":[{"type":"illegal_argument_exception","reason":"mapper [log4j_root_cause] cannot be changed from type [text] to [keyword]"}],"type":"illegal_argument_exception","reason":"mapper [log4j_root_cause] cannot be changed from type [text] to [keyword]"},"status":400}`

I also tried to download the entire index (which resulted in the file I linked to above), changing the limit in that file, and then dropping and recreating the index with this:

`curl -XPUT 'localhost:9200/log4j2-generic' -H 'Content-Type: application/json' -d @<my file>`

but that resulted in

`{"error":{"root_cause":[{"type":"illegal_argument_exception","reason":"unknown setting [index.log4j2-generic.mappings.doc.properties.@timestamp.type] please check that any required plugins are installed, or check the breaking changes documentation for removed settings"}],"type":"illegal_argument_exception","reason":"unknown setting [index.log4j2-generic.mappings.doc.properties.@timestamp.type] please check that any required plugins are installed, or check the breaking changes documentation for removed settings"},"status":400}`

Ultimately, I just want to be able to do visualizations based on log4j\_root\_cause regardless of how long that field is. How do I do that? The visualization editor only lets me select the .keyword versions of the field, that's why I figured I need to change the length limit.  
What is the right way to do this?

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2018, 11:06pm UTC](https://discuss.elastic.co/t/how-to-change-ignore-above/111873/2 "2018-01-11T23:06:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
