# Logstash Could not index event to Elasticsearch The \[default\] mapping cannot be updated on index

**URL:** <https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch-the-default-mapping-cannot-be-updated-on-index/177315>\
**Category:** Logstash\
**Created:** [April 17, 2019, 2:29pm UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch-the-default-mapping-cannot-be-updated-on-index/177315 "2019-04-17T14:29:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Moshe\_Nadler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moshe_nadler/32/27536_2.png) [@Moshe\_Nadler](https://discuss.elastic.co/u/Moshe_Nadler)\
**Post date:** [April 17, 2019, 2:29pm UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch-the-default-mapping-cannot-be-updated-on-index/177315/1 "2019-04-17T14:29:10Z")

</div>

After an upgrade to elastic stack 7 Logstash cannot send logs to elasticsearch any more. We see the following error:

[2019-04-17T14:25:31,292][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-aws-alb-logs-2019.04.17", :\_type=\>"\_doc", :routing=\>nil}, #LogStash::Event:0x47817ce4], :response=\>{"index"=\>{"\_index"=\>"logstash-aws-alb-logs-2019.04.17", "\_type"=\>"\_doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"The [default] mapping cannot be updated on index [logstash-aws-alb-logs-2019.04.17]: defaults mappings are not useful anymore now that indices can have at most one type."}}}}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 17, 2019, 3:03pm UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch-the-default-mapping-cannot-be-updated-on-index/177315/2 "2019-04-17T15:03:51Z")

</div>

Are you using a template for your elasticsearch output? If so, what does it look like?

---

<div class="post-metadata">

**Author:** ![Moshe\_Nadler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moshe_nadler/32/27536_2.png) [@Moshe\_Nadler](https://discuss.elastic.co/u/Moshe_Nadler)\
**Post date:** [April 17, 2019, 3:04pm UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch-the-default-mapping-cannot-be-updated-on-index/177315/3 "2019-04-17T15:04:50Z")

</div>

No template.

---

<div class="post-metadata">

**Author:** ![Moshe\_Nadler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moshe_nadler/32/27536_2.png) [@Moshe\_Nadler](https://discuss.elastic.co/u/Moshe_Nadler)\
**Post date:** [April 17, 2019, 3:37pm UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch-the-default-mapping-cannot-be-updated-on-index/177315/4 "2019-04-17T15:37:52Z")

</div>

Needed to delete the old logstash template in elsticsearch and restart one of the logstash pods. This recreated the template of the logstash 7.0.0 version and now it works.

---

<div class="post-metadata">

**Author:** ![erb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erb/32/45420_2.png) [@erb](https://discuss.elastic.co/u/erb)\
**Post date:** [May 3, 2019, 9:50am UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch-the-default-mapping-cannot-be-updated-on-index/177315/5 "2019-05-03T09:50:09Z")

</div>

Can you explain how you deleted the old logstash template in es ?  
Thanks.

---

<div class="post-metadata">

**Author:** ![erb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erb/32/45420_2.png) [@erb](https://discuss.elastic.co/u/erb)\
**Post date:** [May 3, 2019, 10:53am UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch-the-default-mapping-cannot-be-updated-on-index/177315/6 "2019-05-03T10:53:00Z")

</div>

Forget my previous question : everything is in the documentation here:  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html)

I had to do:

```
curl -XDELETE http://localhost:9200/_template/logstash

```

And all is OK now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2019, 10:53am UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch-the-default-mapping-cannot-be-updated-on-index/177315/7 "2019-05-31T10:53:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
