# Keyword seem to have disappeared

**URL:** <https://discuss.elastic.co/t/keyword-seem-to-have-disappeared/283685>\
**Category:** Elasticsearch\
**Created:** [September 8, 2021, 2:55pm UTC](https://discuss.elastic.co/t/keyword-seem-to-have-disappeared/283685 "2021-09-08T14:55:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bibas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bibas/32/67732_2.png) [@Bibas](https://discuss.elastic.co/u/Bibas)\
**Post date:** [September 8, 2021, 2:55pm UTC](https://discuss.elastic.co/t/keyword-seem-to-have-disappeared/283685/1 "2021-09-08T14:55:14Z")

</div>

Hello

I have logs coming from my application, in those logs, there is a "coType" field that used to be a text that contains a keyword subfield.

For a reason that I ignore (I don't think I changed the conf file in months and I reloaded the index in case of an unapplied auto-mapping), the keyword field kind of disappeared but I still receive those logs, the juste now are only text with no subfield.

here's a screenshot of the mapping before and after :  
 ![Capture d’écran 2021-09-08 à 16.53.18](https://us1.discourse-cdn.com/elastic/original/3X/3/6/36adcf77b7dfd6274ae6f594adbbb4e38f15d7fa.png)  
 ![Capture d’écran 2021-09-08 à 16.53.29](https://us1.discourse-cdn.com/elastic/original/3X/8/f/8f08a172787a16e65ec237137b16b5cfaa2cd640.png)

so I was wondering :

- Do you have any idea of the reason why the keyword field could have disappeared ?
- How can I re-add it on my logs ?

Here is my guess for now :  
I'm kind of an ELK newbie so I don't know if it can be related but I have a logstash conf that only have a mutate filter to convert some fields to "string", maybe i should had the "coType" field to this filter ?

Thanks for your help !

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 13, 2021, 3:13pm UTC](https://discuss.elastic.co/t/keyword-seem-to-have-disappeared/283685/2 "2021-09-13T15:13:01Z")

</div>

Fields never disappear from an existing index.

This looks as if the index has been **recreated** with a different mapping.

You can add that field back using updating your mapping using multi fields. See [fields | Elasticsearch Guide [7.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/multi-fields.html)

**However** : You need to reindex all the existing documents once so that for all of the already indexed documents this field gets added and indexed. This can be done using the reindex API. See [Reindex API | Elasticsearch Guide [7.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/docs-reindex.html)

Hope this helps!

---

<div class="post-metadata">

**Author:** ![Bibas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bibas/32/67732_2.png) [@Bibas](https://discuss.elastic.co/u/Bibas)\
**Post date:** [September 14, 2021, 8:10am UTC](https://discuss.elastic.co/t/keyword-seem-to-have-disappeared/283685/3 "2021-09-14T08:10:21Z")

</div>

Thanks for your answer !

My field are recreated every month with their lifecycle policies, how can I prevent this re-creation with a different mapping to happen in the future ?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [September 14, 2021, 8:12am UTC](https://discuss.elastic.co/t/keyword-seem-to-have-disappeared/283685/4 "2021-09-14T08:12:52Z")

</div>

Make sure to use index templates [Index templates | Elasticsearch Guide [7.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/indices-templates.html)

---

<div class="post-metadata">

**Author:** ![Bibas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bibas/32/67732_2.png) [@Bibas](https://discuss.elastic.co/u/Bibas)\
**Post date:** [September 14, 2021, 8:35am UTC](https://discuss.elastic.co/t/keyword-seem-to-have-disappeared/283685/5 "2021-09-14T08:35:58Z")

</div>

Thank you for your time ! That helps a lot !

---

<div class="post-metadata">

**Author:** ![Bibas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bibas/32/67732_2.png) [@Bibas](https://discuss.elastic.co/u/Bibas)\
**Post date:** [September 14, 2021, 9:44am UTC](https://discuss.elastic.co/t/keyword-seem-to-have-disappeared/283685/6 "2021-09-14T09:44:04Z")

</div>

I'm sorry to ask for your help again, but I created a new index like `myIndex-77` by reindexing my `myIndex-1`, the new mapping correctly applied but now my logstash is not able to index data anymore, I suspect that he does not find the index he used to push data onto, do you have any idea on how to correct that ?

I tried to delete `myIndex-1` and then reindex `myIndex-77` into a new `myIndex-1` but it doesn't work

Here is the error I keep seeing on Logstash

```auto
logstash_1 | [2021-09-14T09:43:05,090][ERROR][logstash.outputs.elasticsearch][main] Encountered a retryable error. Will Retry with exponential backoff {:code=>400, :url=>"http://elasticsearch:9200/_bulk"}

```

There is also an error log on ES

 ![Capture d’écran 2021-09-14 à 12.02.25](https://us1.discourse-cdn.com/elastic/original/3X/b/e/beba9bbb7ba520d30b4f2e638ff2b6ba85619d84.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 12, 2021, 9:44am UTC](https://discuss.elastic.co/t/keyword-seem-to-have-disappeared/283685/7 "2021-10-12T09:44:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
