I am facing an issue with existing mapping. In few occations mapping type some times referring current settings and some times referring to old mapping due to that data is spilling over so the graphs are getting floating incorrectly. current version logstash 1.5.4.
Need some help on this.
Filed mapping is some thing like below.
current format in collector : var1, timestamp,var2,var3,var4,var5,var6
{
"_index": "Indx-yyyy.mm.dd",
"_type": "mytype",
"_id": "AWGaqLuLzHhJvAINZLbA",
"_score": null,
"_source": {
"message": [
"srv1,2018-02-15T13:10:03.274-0500,9,65046540,22697616,34,42348924"
],
"@version": "1",
"@timestamp": "2018-02-15T18:10:04.260Z",
"host": "XXXXXXXXXXX",
"path": "XXXXXXXXXXXXXXXXXXX.log",
"type": "mytype",
"server": "XXXXXXXXXXX",
"run_timestamp": "2018-02-15T13:10:03.274-0500",
"var2": 9,
"var3": 65046540,
"var4": 22697616,
"var6": 34,
"var5": 42348924
},
"sort": [
1518718204260,
1518718204260
]
}
Old format : var1,date,time, var2,var3,var4,var5
{
"_index": "Indx-yyyy.mm.dd",
"_type": "mytype",
"_id": "AWGaqoyIwVSQTYJf60Yu",
"_score": null,
"_source": {
"message": [
"srv1,2018-02-15T13:12:02.507-0500,9,65046540,22698824,34,42347716"
],
"@version": "1",
"@timestamp": "2018-02-15T18:12:03.314Z",
"host": "XXXXXXXXXXX",
"path": "XXXXXXXXXXXXXXXXXXX.log",
"type": "mytype",
"server": "XXXXXXXXXXX",
"date": "2018-02-15T13:12:02.507-0500",
"time": "9",
"var2": 65046540,
"var3": 22698824,
"var4": 34,
"var5": 42347716
},
"sort": [
1518718323314,
1518718323314
]
}