# Logstash map id always detected as long, even it string

**URL:** <https://discuss.elastic.co/t/logstash-map-id-always-detected-as-long-even-it-string/245843>\
**Category:** Logstash\
**Created:** [August 21, 2020, 2:35am UTC](https://discuss.elastic.co/t/logstash-map-id-always-detected-as-long-even-it-string/245843 "2020-08-21T02:35:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bayucandra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bayucandra/32/81294_2.png) [@bayucandra](https://discuss.elastic.co/u/bayucandra)\
**Post date:** [August 21, 2020, 2:35am UTC](https://discuss.elastic.co/t/logstash-map-id-always-detected-as-long-even-it-string/245843/1 "2020-08-21T02:35:10Z")

</div>

Hi,

Based on logs below, I assume that my logstsh always consider any record with field named "id" as a "long", even it "string".

```
[WARN][logstash.outputs.elasticsearch][main][f4110a8e1e28ebbac18f43191bfa4dea9a1b050d31aef7bd8b0e3e6aa490afbd] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"13.229.9.94-webmin-webmin-api-2020.08", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x4f3a5c0>], :response=>{"index"=>{"_index"=>"13.229.9.94-webmin-webmin-api-2020.08", "_type"=>"_doc", "_id"=>"Uze0DnQBbUX_aj8AhqWE", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [log_record.response.content_json.data.rows.id] of type [long] in document with id 'Uze0DnQBbUX_aj8AhqWE'. Preview of field's value: '5f0579cb793f846f26418f44'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"For input string: \"5f0579cb793f846f26418f44\""}}}}}

```

Any solution regarding those case? Please help me regarding this matter. Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [August 21, 2020, 7:59am UTC](https://discuss.elastic.co/t/logstash-map-id-always-detected-as-long-even-it-string/245843/2 "2020-08-21T07:59:51Z")

</div>

Hi there,

guess this is caused by the fact that you originally ingested some documents in a ES index with a long-alike `log_record.response.content_json.data.rows.id` field without applying to that field a specific mapping in ES to cast it to be a string. Now you're ingesting another document with `5f0579cb793f846f26418f44` as value of that `log_record.response.content_json.data.rows.id` which obviously is not a long. Therefore it returns an error saying you cannot cast `5f0579cb793f846f26418f44` to a long.

Since you cannot change the mapping of a field of an already filled index, what you can do depends on whether you can delete that index or not.

If it's a test index and you can delete it you erase the index, apply a template to the index ( **before** ingesting any document) specifying you want `log_record.response.content_json.data.rows.id` to be ingested as a string and then you start ingesting the docs.

If you cannot delete the index because you don't want to lose any data, you can

- create a temporary index specifying the mapping for that field
- [reindex](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html) the docs from the old index to this new temporary one making sure that field is now set as string
- delete the old index with the wrong mapping
- apply the right mapping to the right index (the original one which you just erased)
- reindex back the old docs from the temporary index to the original index making sure that field has the right mapping
- delete the temporary index

---

<div class="post-metadata">

**Author:** ![bayucandra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bayucandra/32/81294_2.png) [@bayucandra](https://discuss.elastic.co/u/bayucandra)\
**Post date:** [August 21, 2020, 5:21pm UTC](https://discuss.elastic.co/t/logstash-map-id-always-detected-as-long-even-it-string/245843/3 "2020-08-21T17:21:57Z")

</div>

Hi, thanks for the detail answer. Will try to do reindex.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2020, 5:22pm UTC](https://discuss.elastic.co/t/logstash-map-id-always-detected-as-long-even-it-string/245843/4 "2020-09-18T17:22:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
