# How to change the default type

**URL:** <https://discuss.elastic.co/t/how-to-change-the-default-type/125318>\
**Category:** Elasticsearch\
**Created:** [March 23, 2018, 7:36am UTC](https://discuss.elastic.co/t/how-to-change-the-default-type/125318 "2018-03-23T07:36:55Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [March 23, 2018, 7:36am UTC](https://discuss.elastic.co/t/how-to-change-the-default-type/125318/1 "2018-03-23T07:36:55Z")

</div>

Hi everyone, when I index the flow data to ES, the IPV4\_SRC\_ADDR and IPV4\_DST\_ADDR are string type, and I want to change it to ip type.  
this is the mapping config:

```
PUT /_template/logstash
{
"index_patterns": "logstash-*", 
"order": 1, 
"settings": {
"index": {
"refresh_interval": "5s"
}
},
"mappings": {
"default": { 

"properties": {
"IPV4_SRC_ADDR": { "type": "ip"},
"IPV4_DST_ADDR": { "type": "ip"},
"PROTOCOL": { "type": "integer"}
}
}
}
} 

```

there has a error message:  
`Rejecting mapping update to as the final mapping would have more than 1 type: [log, doc]`

thank you in advance!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 23, 2018, 8:14am UTC](https://discuss.elastic.co/t/how-to-change-the-default-type/125318/2 "2018-03-23T08:14:04Z")

</div>

That will probably depend on your Logstash config, it looks like something is setting `document_type` to log.

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [March 23, 2018, 8:20am UTC](https://discuss.elastic.co/t/how-to-change-the-default-type/125318/3 "2018-03-23T08:20:33Z")

</div>

HI, this is my logstash config:

```
input{

        tcp{
                host => "172.30.154.74"
                port => 5510
                codec => json
        }
}
filter{
         mutate{
                remove_field =>["SRC_IP_COUNTRY","SRC_IP_LOCATION","DST_IP_LOCATION","TCP_FLAGS","SERVER_NW_LATENCY_MS","NTOPNG_INSTANCE_NAME","LAST_SWITCHED","INTERFACE","DST_IP_LOCATION","DST_IP_COUNTRY","CLIENT_NW_LATENCY_MS","IN_PKTS","OUT_PKTS","IN_SRC_MAC","OUT_SRC_MAC","OUT_DST_MAC","FIRST_SWITCHED","host","ntop_timestamp","port","json","L4_DST_PORT","L4_SRC_PORT","@version","_type"]
                }

}
output{
elasticsearch {
                codec => "json"
                hosts => ["172.30.124.254:9200","172.30.451.52:9200"]

        }
                stdout{codec => rubydebug}

}

```

after set the template, then the ES can't store the data anymore

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 23, 2018, 8:28am UTC](https://discuss.elastic.co/t/how-to-change-the-default-type/125318/4 "2018-03-23T08:28:15Z")

</div>

Is this the only Logstash instance talking to your cluster?

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [March 23, 2018, 8:35am UTC](https://discuss.elastic.co/t/how-to-change-the-default-type/125318/5 "2018-03-23T08:35:39Z")

</div>

yes .  
this is the logstash error messgae:

`[2018-03-23T16:34:26,924][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"logstash-2018.03.23", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x751a88a7>], :response=>{"index"=>{"_index"=>"logstash-2018.03.23", "_type"=>"doc", "_id"=>"jEb-UWIBJRgB5JfYn-uk", "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"Rejecting mapping update tgB5JfYn-uk", "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"Rejecting mapping update to [logstash-2018.03.23] as the final mapping would have more than 1 type: [default, doc]"}}}}`

the problem didn't happen in version ES 5.X.

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [March 23, 2018, 9:42am UTC](https://discuss.elastic.co/t/how-to-change-the-default-type/125318/6 "2018-03-23T09:42:37Z")

</div>

the problem is solved after modifing the mapping template config:

```
PUT _template/logstash
{
  "index_patterns": ["logstash-*"],
  "settings": {
    "number_of_shards": 1
  },
  "mappings": {
    "doc": {
      "_source": {
        "enabled": false
      },
      "properties": {
        "IPV4_SRC_ADDR": { "type": "ip"},
        "IPV4_DST_ADDR": { "type": "ip"},
        "PROTOCOL": { "type": "integer"}
      }
    }
  }
}

```

I have another question that what value of "number\_of\_shards" is better for my cluster which has four nodes and large data in it.

thank you very much.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2018, 9:51am UTC](https://discuss.elastic.co/t/how-to-change-the-default-type/125318/7 "2018-03-23T09:51:30Z")

</div>

Are you using daily indices? If so, how large are they?

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [March 23, 2018, 9:57am UTC](https://discuss.elastic.co/t/how-to-change-the-default-type/125318/8 "2018-03-23T09:57:14Z")

</div>

yes, about 20G per day.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2018, 10:03am UTC](https://discuss.elastic.co/t/how-to-change-the-default-type/125318/9 "2018-03-23T10:03:52Z")

</div>

Then I suspect 2 primary shards would be suitable. With 1 replica configured that gives 4 total shards per index, which matches your node count.

---

<div class="post-metadata">

**Author:** ![f26227279](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/f26227279/32/21296_2.png) [@f26227279](https://discuss.elastic.co/u/f26227279)\
**Post date:** [March 23, 2018, 10:23am UTC](https://discuss.elastic.co/t/how-to-change-the-default-type/125318/10 "2018-03-23T10:23:43Z")

</div>

ok. I got it! thanks a lot 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2018, 10:23am UTC](https://discuss.elastic.co/t/how-to-change-the-default-type/125318/11 "2018-04-20T10:23:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
