# Logstash add @version which is not in the original document

**URL:** <https://discuss.elastic.co/t/logstash-add-version-which-is-not-in-the-original-document/256144>\
**Category:** Logstash\
**Created:** [November 20, 2020, 3:38pm UTC](https://discuss.elastic.co/t/logstash-add-version-which-is-not-in-the-original-document/256144 "2020-11-20T15:38:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![amralieg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amralieg/32/49943_2.png) [@amralieg](https://discuss.elastic.co/u/amralieg)\
**Post date:** [November 20, 2020, 3:38pm UTC](https://discuss.elastic.co/t/logstash-add-version-which-is-not-in-the-original-document/256144/1 "2020-11-20T15:38:29Z")

</div>

Hi,  
I have this logstash config that moves data between 2 elasticsearch, when I run it I get this error, any idea how to solve this?

```auto
input {
    elasticsearch {
        hosts => ["<source>"]
        user => "**"
        password => "**"
        index => "idx-uk-category-0005"
        size => 1000
        scroll => "10m"
        codec => "json"
        docinfo => true
    }
}
# a note in this section indicates that filter can be selected
filter {
}
output {
    elasticsearch {
        hosts => ["<target>"]
        user => "**"
        password => "**"
        index => "idx-uk-category-0005"
    }
    stdout { codec => rubydebug { metadata => true } }
}

```

This is the error:

[main][07849e361f87e2bca773dc6ffd4bb555a7e9d671c249307fdab01f4cdcf6fb4e] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"idx-uk-category-0005", :routing=\>nil, :\_type=\>"\_doc"}, #LogStash::Event:0x62c197e2], :response=\>{"index"=\>{"\_index"=\>"idx-uk-category-0005", "\_type"=\>"\_doc", "\_id"=\>"4RtK5nUBh2BTJtDt2rUv", "status"=\>400, "error"=\>{"type"=\>"strict\_dynamic\_mapping\_exception", "reason"=\>"mapping set to strict, dynamic introduction of [@version] within [\_doc] is not allowed"}}}}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 20, 2020, 3:48pm UTC](https://discuss.elastic.co/t/logstash-add-version-which-is-not-in-the-original-document/256144/2 "2020-11-20T15:48:30Z")

</div>

Correct, logstash will [always add](https://github.com/elastic/logstash/blob/ca81a8f4a32457a7c100a4712c7c5a4c9b5c2faa/logstash-core/src/main/java/org/logstash/Event.java#L70) a @version field when it creates the event. You can remove it using

```
mutate { remove_field => ["@version"] }

```

in your filter section.

---

<div class="post-metadata">

**Author:** ![amralieg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amralieg/32/49943_2.png) [@amralieg](https://discuss.elastic.co/u/amralieg)\
**Post date:** [November 20, 2020, 4:07pm UTC](https://discuss.elastic.co/t/logstash-add-version-which-is-not-in-the-original-document/256144/3 "2020-11-20T16:07:53Z")

</div>

Thank you, this seems to solve the problem, also found another field added, so final filter should be

```auto
mutate { remove_field => ["@version", "@timestamp"] }

```

But I found another problem, logstash uses an auto generated \_id, not the original \_id in the source document, any idea how to force it to use the original \_id from the source document?

---

<div class="post-metadata">

**Author:** ![amralieg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amralieg/32/49943_2.png) [@amralieg](https://discuss.elastic.co/u/amralieg)\
**Post date:** [November 20, 2020, 4:23pm UTC](https://discuss.elastic.co/t/logstash-add-version-which-is-not-in-the-original-document/256144/4 "2020-11-20T16:23:04Z")

</div>

I figured out how to force to use the original document id, I add this in the output section  
`document_id => "%{[@metadata][_id]}"`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2020, 4:23pm UTC](https://discuss.elastic.co/t/logstash-add-version-which-is-not-in-the-original-document/256144/5 "2020-12-18T16:23:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
