# LOgstash 6.2 Template Mapping not able to write to index

**URL:** <https://discuss.elastic.co/t/logstash-6-2-template-mapping-not-able-to-write-to-index/123764>\
**Category:** Logstash\
**Created:** [March 13, 2018, 3:31pm UTC](https://discuss.elastic.co/t/logstash-6-2-template-mapping-not-able-to-write-to-index/123764 "2018-03-13T15:31:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sri535](https://avatars.discourse-cdn.com/v4/letter/s/779978/32.png) [@sri535](https://discuss.elastic.co/u/sri535)\
**Post date:** [March 13, 2018, 3:31pm UTC](https://discuss.elastic.co/t/logstash-6-2-template-mapping-not-able-to-write-to-index/123764/1 "2018-03-13T15:31:15Z")

</div>

HI  
i am using 6.2 and i made changes to my template file as required but i am getting below error in logstash.

> Blockquote  
> indent preformatted text by 4 spaces  
> [2018-03-13T06:55:55,748][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"foltsdb-2018.03.13", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x199f431e], :response=\>{"index"=\>{"\_index"=\>"foltsdb-2018.03.13", "\_type"=\>"doc", "\_id"=\>"KdWlH2IB9vIHqwZ6YyrH", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Could not convert [message.index] to boolean", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Failed to parse value [not\_analyzed] as only [true] or [false] are allowed."}}}}}}  
> indent preformatted text by 4 spaces

---

<div class="post-metadata">

**Author:** ![sri535](https://avatars.discourse-cdn.com/v4/letter/s/779978/32.png) [@sri535](https://discuss.elastic.co/u/sri535)\
**Post date:** [March 13, 2018, 3:32pm UTC](https://discuss.elastic.co/t/logstash-6-2-template-mapping-not-able-to-write-to-index/123764/2 "2018-03-13T15:32:44Z")

</div>

```
indent preformatted text by 4 spaces

```

here my logstash template:  
indent preformatted text by 4 spaces  
{  
"template" : "foltsdb-\*",  
"settings" : {  
"index.refresh\_interval" : "10s"  
},  
"mappings" : {  
"\_doc": {

```
   "dynamic_templates" : [
      {
        "message_field" : {
          "path_match" : "message",
          "mapping" : {
           "type" : "keyword", "omit_norms" : true
       },
          "match_mapping_type" : "string"
        }
      },
      
	  {
	    "integers": {
        "match_mapping_type": "long",
        "mapping": {
          "type": "integer"
        }
      }
    },
	  
	  {
        "string_fields" : {
          "mapping" : {
            "type" : "text", "index" : "analyzed", "norms": false,
            "fields" : {
              "keyword" : {"type": "keyword", "index" : "not_analyzed", "ignore_above" : 1024}
            }
          },
          "match_mapping_type" : "string",
          "match" : "*"
        }
      }
    ],
  
   
   "properties" : {

```

"@timestamp" : { "format" : "dateOptionalTime","type" : "date" },  
"@version":{ "type": "keyword" },  
"host": { "type": "keyword" },  
"path": { "type": "keyword" },  
"Application": { "type": "keyword" },  
"TransactionName": { "type": "keyword" },  
"StartTime": { "type": "date", "format" : "dateOptionalTime" },  
"Status": { "type": "text" },  
"ResponseCode": { "type": "keyword" },  
"ResponseTime": { "type": "integer" },  
"Latency": { "type": "integer" },  
"Throughput": { "type": "integer" },  
"TestId": { "type": "keyword" }

```
   }
}

```

}  
}  
indent preformatted text by 4 spaces

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2018, 3:32pm UTC](https://discuss.elastic.co/t/logstash-6-2-template-mapping-not-able-to-write-to-index/123764/3 "2018-04-10T15:32:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
