# \[illegal\_argument\_exception\] unknown type for collapse field \`cluster\_uuid\`, only keywords and numbers are accepted: Check the Elasticsearch Monitoring cluster network connection or the load level of the nodes

**URL:** <https://discuss.elastic.co/t/illegal-argument-exception-unknown-type-for-collapse-field-cluster-uuid-only-keywords-and-numbers-are-accepted-check-the-elasticsearch-monitoring-cluster-network-connection-or-the-load-level-of-the-nodes/224575>\
**Category:** Kibana\
**Tags:** elastic-stack-monitoring\
**Created:** [March 22, 2020, 7:59pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-unknown-type-for-collapse-field-cluster-uuid-only-keywords-and-numbers-are-accepted-check-the-elasticsearch-monitoring-cluster-network-connection-or-the-load-level-of-the-nodes/224575 "2020-03-22T19:59:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![gururjrk](https://avatars.discourse-cdn.com/v4/letter/g/43a26b/32.png) [@gururjrk](https://discuss.elastic.co/u/gururjrk)\
**Post date:** [March 22, 2020, 7:59pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-unknown-type-for-collapse-field-cluster-uuid-only-keywords-and-numbers-are-accepted-check-the-elasticsearch-monitoring-cluster-network-connection-or-the-load-level-of-the-nodes/224575/1 "2020-03-22T19:59:10Z")

</div>

In Kibana when I click on Monitoring getting error  
[illegal\_argument\_exception] unknown type for collapse field `cluster_uuid`, only keywords and numbers are accepted: Check the Elasticsearch Monitoring cluster network connection or the load level of the nodes.

In the Elasticsearch log file

```auto
[2020-03-22T10:40:25,595][DEBUG][o.e.a.s.TransportSearchAction] [ausplgicuesmon1_2dcmon] [.monitoring-es-7-mb-2020.03.22][0], node[zm8CYKFZQeuJSWmcoIfYNA], [R], s[STARTED], a[id=8Dm7sY0dRyqQrnX8Cho8pA]: Failed to execute [SearchRequest{searchType=QUERY_THEN_FETCH, indices=[.monitoring-es-7-mb-2020.03.22], indicesOptions=IndicesOptions[ignore_unavailable=true, allow_no_indices=true, expand_wildcards_open=true, expand_wildcards_closed=false, allow_aliases_to_multiple_indices=true, forbid_closed_indices=true, ignore_aliases=false, ignore_throttled=true], types=[], routing='null', preference='null', requestCache=null, scroll=null, maxConcurrentShardRequests=0, batchedReduceSize=512, preFilterShardSize=128, allowPartialSearchResults=true, localClusterAlias=null, getOrCreateAbsoluteStartMillis=-1, ccsMinimizeRoundtrips=true, source={"size":10000,"query":{"bool":{"filter":[{"term":{"type":{"value":"cluster_stats","boost":1.0}}},{"range":{"timestamp":{"from":1584888025379,"to":1584891625379,"include_lower":true,"include_upper":true,"format":"epoch_millis","boost":1.0}}}],"adjust_pure_negative":true,"boost":1.0}},"sort":[{"timestamp":{"order":"desc"}}],"collapse":{"field":"cluster_uuid"}}}]
org.elasticsearch.transport.RemoteTransportException: [ausflgicuesmon1_2dcmon][10.182.182.34:9301][indices:data/read/search[phase/query]]
Caused by: java.lang.IllegalArgumentException: unknown type for collapse field `cluster_uuid`, only keywords and numbers are accepted
        at org.elasticsearch.search.collapse.CollapseBuilder.build(CollapseBuilder.java:209) ~[elasticsearch-7.6.1.jar:7.6.1]
        at org.elasticsearch.search.SearchService.parseSource(SearchService.java:919) ~[elasticsearch-7.6.1.jar:7.6.1]
        at org.elasticsearch.search.SearchService.createContext(SearchService.java:591) ~[elasticsearch-7.6.1.jar:7.6.1]

```

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [March 23, 2020, 4:20am UTC](https://discuss.elastic.co/t/illegal-argument-exception-unknown-type-for-collapse-field-cluster-uuid-only-keywords-and-numbers-are-accepted-check-the-elasticsearch-monitoring-cluster-network-connection-or-the-load-level-of-the-nodes/224575/2 "2020-03-23T04:20:10Z")

</div>

> [@gururjrk](#):
>
> unknown type for collapse field `cluster_uuid`

What version of the stack are you using ? It looks like a mapping issue on the ES side.

Let's make sure you're indexing the right version of monitoring documents.

What do you see when you run:

```auto
GET _cat/indices/.monitoring-es-*

```

Try running this:

```auto
GET .monitoring-es-*/_mapping

```

The `cluster_uuid` mapping needs to be a keyword, and I'm guessing it's not for your setup:

```auto
        "cluster_uuid" : {
          "type" : "keyword"
        },

```

Is it safe to assume that all the existing monitoring data can be deleted without issue? Or do we need to preserve any of it? I'm asking because my recommendation moving forward will be to remove all `.monitoring-es-*` indices as a way to fix this.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![gururjrk](https://avatars.discourse-cdn.com/v4/letter/g/43a26b/32.png) [@gururjrk](https://discuss.elastic.co/u/gururjrk)\
**Post date:** [March 23, 2020, 7:08pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-unknown-type-for-collapse-field-cluster-uuid-only-keywords-and-numbers-are-accepted-check-the-elasticsearch-monitoring-cluster-network-connection-or-the-load-level-of-the-nodes/224575/3 "2020-03-23T19:08:06Z")

</div>

> [@rashmi](#):
>
> \_cat/indices/.monitoring-es-\*

Hi Rashmi,

I am on latest version 7.6.1. Both the Production and Monitoring cluster are in same version 7.6.1

GET \_cat/indices/.monitoring-es-\*

green open .monitoring-es-7-mb-2020.03.23 1U3X7HffQYSsLnmwuvOgWA 1 1 108221 0 311.1mb 155.1mb  
green open .monitoring-es-7-mb-2020.03.22 7d9ihmoHSDugbKwP09S6-Q 1 1 24977 0 70.1mb 34.9mb

GET .monitoring-es-\*/\_mapping

"cluster\_stats": {  
"properties": {  
"cluster\_uuid": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [March 23, 2020, 7:11pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-unknown-type-for-collapse-field-cluster-uuid-only-keywords-and-numbers-are-accepted-check-the-elasticsearch-monitoring-cluster-network-connection-or-the-load-level-of-the-nodes/224575/4 "2020-03-23T19:11:01Z")

</div>

@shaunak - can I seek ur inputs here?

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [March 23, 2020, 8:14pm UTC](https://discuss.elastic.co/t/illegal-argument-exception-unknown-type-for-collapse-field-cluster-uuid-only-keywords-and-numbers-are-accepted-check-the-elasticsearch-monitoring-cluster-network-connection-or-the-load-level-of-the-nodes/224575/5 "2020-03-23T20:14:34Z")

</div>

The mappings look wrong. Could you post the output of `GET _cat/templates/*monitoring* ?v`, run against your Monitoring ES cluster, please?

---

<div class="post-metadata">

**Author:** ![gururjrk](https://avatars.discourse-cdn.com/v4/letter/g/43a26b/32.png) [@gururjrk](https://discuss.elastic.co/u/gururjrk)\
**Post date:** [March 24, 2020, 5:46am UTC](https://discuss.elastic.co/t/illegal-argument-exception-unknown-type-for-collapse-field-cluster-uuid-only-keywords-and-numbers-are-accepted-check-the-elasticsearch-monitoring-cluster-network-connection-or-the-load-level-of-the-nodes/224575/6 "2020-03-24T05:46:29Z")

</div>

Hi Shaunak,

GET \_cat/templates?v

name index\_patterns order version  
metricbeat-7.6.1 [metricbeat-7.6.1-_] 1  
.management-beats [.management-beats] 0 70000  
.triggered\_watches [.triggered\_watches_] 2147483647  
.watches [.watches\*] 2147483647  
.watch-history-10 [.watcher-history-10\*] 2147483647  
.ml-anomalies- [.ml-anomalies-_] 0 7060199  
ilm-history [ilm-history-1_] 2147483647  
.ml-meta [.ml-meta] 0 7060199  
.ml-inference-000001 [.ml-inference-000001] 0 7060199  
.transform-internal-004 [.transform-internal-004] 0 7060199  
.ml-notifications-000001 [.ml-notifications-000001] 0 7060199  
.slm-history [.slm-history-1\*] 2147483647  
.transform-notifications-000002 [.transform-notifications-_] 0 7060199  
.ml-state [.ml-state_] 0 7060199  
.ml-config [.ml-config] 0 7060199  
.logstash-management [.logstash] 0

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2020, 5:46am UTC](https://discuss.elastic.co/t/illegal-argument-exception-unknown-type-for-collapse-field-cluster-uuid-only-keywords-and-numbers-are-accepted-check-the-elasticsearch-monitoring-cluster-network-connection-or-the-load-level-of-the-nodes/224575/7 "2020-04-21T05:46:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
