# Howto find docids based on field type rather than field value?

**URL:** <https://discuss.elastic.co/t/howto-find-docids-based-on-field-type-rather-than-field-value/59190>\
**Category:** Elasticsearch\
**Created:** [August 29, 2016, 1:44pm UTC](https://discuss.elastic.co/t/howto-find-docids-based-on-field-type-rather-than-field-value/59190 "2016-08-29T13:44:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [August 29, 2016, 1:44pm UTC](https://discuss.elastic.co/t/howto-find-docids-based-on-field-type-rather-than-field-value/59190/1 "2016-08-29T13:44:20Z")

</div>

when developing a new logstash filter, I initially by mistake got fields mapped as string rather than number, now I want to search out all the docIDs where specific fields are of type string rather than numbers so I can search my docs from Kibana and avoid this warning from Kibana:

> Mapping conflict! 6 fields are defined as several types (string, integer, etc) across the indices that match this pattern. You may still be able to use these conflict fields in parts of Kibana, but they will be unavailable for functions that require Kibana to know their type. Correcting this issue will require reindexing your data

Q is just howto do this, hints are much appreciated!

---

<div class="post-metadata">

**Author:** ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)\
**Post date:** [August 30, 2016, 8:14am UTC](https://discuss.elastic.co/t/howto-find-docids-based-on-field-type-rather-than-field-value/59190/2 "2016-08-30T08:14:45Z")

</div>

Hi @stefws,

you don't need to find the individual doc ids but rather the index names as all documents in an index will be indexed using the same mapping. Hence, you need to use the mapping API to find out which indices are affected.

Here is an example: Say, your index pattern is "logstash-\*", then you can find the mappings of all indices with

```auto
GET /logstash-*/_mapping 

```

Now, there is a nice little utility called [gron](https://github.com/tomnomnom/gron) which you can use to grep for the fields that you're interested in. Say, the field is called `foo`, then you can issue:

```auto
gron http://localhost:9200/logstash-\*/_mapping | fgrep 'foo.type = "string"'

```

which produces something like:

```auto
json["logstash-2016"].mappings._default_.properties.foo.type = "string";
json["logstash-2016"].mappings.my_type.properties.foo.type = "string";

```

From which you can see that the affected index is `logstash-2016`. If it's just a couple of indices this is probably manageable, otherwise you should postprocess the result with ask or the like.

You can also try [jq](https://stedolan.github.io/jq/) but it was easier for me with gron in this case.

When you know the affected indices, you can then create a new index with a proper mapping and reindex all documents.

Daniel

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [August 30, 2016, 8:39am UTC](https://discuss.elastic.co/t/howto-find-docids-based-on-field-type-rather-than-field-value/59190/3 "2016-08-30T08:39:43Z")

</div>

Thanks, got jq, but it seems the mapping is primary dynamic:

```
{
  "collectd-2016-08-26": {
    "mappings": {
      "_default_": {
        "_all": {
          "enabled": true,
          "omit_norms": true
        },
        "dynamic_templates": [
          {
            "template1": {
              "mapping": {
                "ignore_above": 64,
                "index": "not_analyzed",
                "type": "{dynamic_type}",
                "doc_values": true
              },
              "match": "*"
            }
          }
        ],
        "properties": {
          "@timestamp": {
            "type": "date",
            "format": "strict_date_optional_time||epoch_millis"
          },
          "collectd_type": {
            "type": "string",
            "index": "not_analyzed"
          },
          "host": {
            "type": "string",
            "index": "not_analyzed"
          },
          "plugin": {
            "type": "string",
            "index": "not_analyzed"
          },
          "plugin_instance": {
            "type": "string",
            "index": "not_analyzed"
          },
          "type_instance": {
            "type": "string",
            "index": "not_analyzed"
          }
        }
      }
    }
  }
}

```

The reason for finding the docs was I just wanted to remove the few initially created doc which has the field wrongly mapped as strings. Also it puzzles me that logstash grok filters matching %{INT:field-name} ends up as strings. I fixed this with a logstash ruby plugin section doing v\_to\_i on such fields.

Any good pointers for reindexing an index?

---

<div class="post-metadata">

**Author:** ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)\
**Post date:** [August 30, 2016, 8:52am UTC](https://discuss.elastic.co/t/howto-find-docids-based-on-field-type-rather-than-field-value/59190/4 "2016-08-30T08:52:57Z")

</div>

Hi @stefws,

> [@stefws](#):
>
> it seems the mapping is primary dynamic

You have dynamic mapping enabled, yes. Below `properties` you see which properties are defined in the mapping for the index `collectd-2016-08-26`.

> [@stefws](#):
>
> I just wanted to remove the few initially created doc

All documents in an index will have the same mapping (except for very few exceptions see [user docs](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html#updating-field-mappings)).

> [@stefws](#):
>
> Also it puzzles me that logstash grok filters matching %{INT:field-name} ends up as strings.

I cannot really say much about that but maybe somebody in the Logstash forum can clear up this confusion.

> [@stefws](#):
>
> Any good pointers for reindexing an index?

If you're on Elasticsearch 2.3 or above you can use the [reindex API](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html). You should also consider using aliases, so you can change the underlying index name transparently for the application (see [the Definitive Guide](https://www.elastic.co/guide/en/elasticsearch/guide/master/index-aliases.html)).

Daniel

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [August 30, 2016, 9:01am UTC](https://discuss.elastic.co/t/howto-find-docids-based-on-field-type-rather-than-field-value/59190/5 "2016-08-30T09:01:11Z")

</div>

Only get the few above properties when asking for \_mapping (all output shown) though I got many more fields in the index. How could I change the mapping for an existing index, pointers?

I'm on 2.3.5

```
 # rpm -q elasticsearch
 elasticsearch-2.3.5-1.noarch

```

Thanks, will looking into the reindex API and aliases...

Will take the grok question to logstash forum of course 🙂

---

<div class="post-metadata">

**Author:** ![stefws](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefws/32/6442_2.png) [@stefws](https://discuss.elastic.co/u/stefws)\
**Post date:** [August 30, 2016, 11:44am UTC](https://discuss.elastic.co/t/howto-find-docids-based-on-field-type-rather-than-field-value/59190/6 "2016-08-30T11:44:57Z")

</div>

I managed to create a new index with correct mapping and reindex data into to this, and removed old index and aliased it's name to the new created index, thanks.

Also it turned out there was a bad date plugin format specifier in my new logstash filter, so @timestamp became wrong and thus docs were put in wrong indices 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:24pm UTC](https://discuss.elastic.co/t/howto-find-docids-based-on-field-type-rather-than-field-value/59190/7 "2017-07-05T22:24:04Z")

</div>


