Logstash reffdering to old index for the mapping

I am facing an issue with existing mapping. In few occations mapping type some times referring current settings and some times referring to old mapping due to that data is spilling over so the graphs are getting floating incorrectly. current version logstash 1.5.4.

Need some help on this.

Filed mapping is some thing like below.

current format in collector : var1, timestamp,var2,var3,var4,var5,var6

{
"_index": "Indx-yyyy.mm.dd",
"_type": "mytype",
"_id": "AWGaqLuLzHhJvAINZLbA",
"_score": null,
"_source": {
"message": [
"srv1,2018-02-15T13:10:03.274-0500,9,65046540,22697616,34,42348924"
],
"@version": "1",
"@timestamp": "2018-02-15T18:10:04.260Z",
"host": "XXXXXXXXXXX",
"path": "XXXXXXXXXXXXXXXXXXX.log",
"type": "mytype",
"server": "XXXXXXXXXXX",
"run_timestamp": "2018-02-15T13:10:03.274-0500",
"var2": 9,
"var3": 65046540,
"var4": 22697616,
"var6": 34,
"var5": 42348924
},
"sort": [
1518718204260,
1518718204260
]
}

Old format : var1,date,time, var2,var3,var4,var5
{
"_index": "Indx-yyyy.mm.dd",
"_type": "mytype",
"_id": "AWGaqoyIwVSQTYJf60Yu",
"_score": null,
"_source": {
"message": [
"srv1,2018-02-15T13:12:02.507-0500,9,65046540,22698824,34,42347716"
],
"@version": "1",
"@timestamp": "2018-02-15T18:12:03.314Z",
"host": "XXXXXXXXXXX",
"path": "XXXXXXXXXXXXXXXXXXX.log",
"type": "mytype",
"server": "XXXXXXXXXXX",
"date": "2018-02-15T13:12:02.507-0500",
"time": "9",
"var2": 65046540,
"var3": 22698824,
"var4": 34,
"var5": 42347716
},
"sort": [
1518718323314,
1518718323314
]
}

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.