# Index.mapping.ignore\_malformed for all new indices

**URL:** https://discuss.elastic.co/t/index-mapping-ignore-malformed-for-all-new-indices/83026
**Category:** Elasticsearch
**Created:** [April 20, 2017, 9:57am UTC](https://discuss.elastic.co/t/index-mapping-ignore-malformed-for-all-new-indices/83026 "2017-04-20T09:57:07Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)
#### Post date: [April 20, 2017, 9:57am UTC](https://discuss.elastic.co/t/index-mapping-ignore-malformed-for-all-new-indices/83026/1 "2017-04-20T09:57:07Z")

</div>

Hello all,

I have struggled with this for a few days now trying all the documentation and this forum without much luck...

I'm using Elastic Stack for a classic centralised logging use case. ES 5.2.2. Logstash is creating daily indices.

I have logs coming from many sources and I can't really control the format of each field so I'm running into field data type conflicts which by Elasticsearch defaults is handled by [rejecting the whole document](https://www.elastic.co/guide/en/elasticsearch/reference/current/ignore-malformed.html#ignore-malformed).

I have tried to use the the [PUT mapping API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html) to set **"ignore\_malformed": true** for the fields that are causing issues but I keep getting _unsupported parameters ignore\_malformed_ errors.

What I can do is set **index.mapping.ignore\_malformed** for new indices. That would be fine but I don't really want to do that manually for every index.

Question: Is there a way to set **index.mapping.ignore\_malformed** as a default for all new indices?

Any answers and/or comments are appreciated 🙂

Cheers,  
AB

---

<div class="post-metadata">

### Author: ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)
#### Post date: [April 20, 2017, 10:11am UTC](https://discuss.elastic.co/t/index-mapping-ignore-malformed-for-all-new-indices/83026/2 "2017-04-20T10:11:25Z")

</div>

Seems like even if I create an index with **"index.mapping.ignore\_malformed": true** I'm still seeing the same issue 😕

GET logstash-2017.04.20.09/\_settings  
{  
"logstash-2017.04.20.09": {  
"settings": {  
"index": {  
"mapping": {  
"ignore\_malformed": "true"  
},  
"refresh\_interval": "5s",  
"number\_of\_shards": "5",  
"provided\_name": "logstash-2017.04.20.09",  
"creation\_date": "1492680822373",  
"number\_of\_replicas": "1",  
"uuid": "OjYYhYYUQbykVnwq7y5CUQ",  
"version": {  
"created": "5020299"  
}  
}  
}  
}  
}

In my Elasticsearch logs I see this  
[2017-04-20T09:54:52,605][DEBUG][o.e.a.b.TransportShardBulkAction] [es-03] [logstash-2017.04.20.09][4] failed to execute bulk item (index) index {log in JSON format}  
java.lang.IllegalArgumentException: [severity] is defined as an object in mapping [my-logs] but this name is already used for a field in other types

Any ideas?

Cheers,  
AB

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 18, 2017, 10:22am UTC](https://discuss.elastic.co/t/index-mapping-ignore-malformed-for-all-new-indices/83026/3 "2017-05-18T10:22:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
