# Logstash "Rejected mapping update", not sure how to rectify the situation

**URL:** <https://discuss.elastic.co/t/logstash-rejected-mapping-update-not-sure-how-to-rectify-the-situation/280269>\
**Category:** Logstash\
**Created:** [August 3, 2021, 3:49am UTC](https://discuss.elastic.co/t/logstash-rejected-mapping-update-not-sure-how-to-rectify-the-situation/280269 "2021-08-03T03:49:23Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![CameronCenic](https://avatars.discourse-cdn.com/v4/letter/c/df788c/32.png) [@CameronCenic](https://discuss.elastic.co/u/CameronCenic)\
**Post date:** [August 3, 2021, 3:49am UTC](https://discuss.elastic.co/t/logstash-rejected-mapping-update-not-sure-how-to-rectify-the-situation/280269/1 "2021-08-03T03:49:23Z")

</div>

I am seeing an error:

> Rejecting mapping update to [logstash-INDEXNAME-2021.08.03] as the final mapping would have more than 1 type: [\_doc, doc]

I suspect this is due to me switching my template from using doc to using \_doc, but I deleted the index in question and recreated it to no effect. Furthermore I have a test system with an index template that uses \_doc that is not having the same issue. So I do not understand why it is happening in the one system but not the other, and how I can rectify the error.

---

<div class="post-metadata">

**Author:** ![CameronCenic](https://avatars.discourse-cdn.com/v4/letter/c/df788c/32.png) [@CameronCenic](https://discuss.elastic.co/u/CameronCenic)\
**Post date:** [August 3, 2021, 4:03am UTC](https://discuss.elastic.co/t/logstash-rejected-mapping-update-not-sure-how-to-rectify-the-situation/280269/2 "2021-08-03T04:03:31Z")

</div>

I guess I should be using document\_type in the ES output, or "doc" in the template?

> <https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/868>
>
> I asked this previously \[on the forum\](https://discuss.elastic.co/t/elasticsear…ch-doc-type-deprecation-doc-vs-doc/139799) but it didn't seem to draw any attention.
> 
> The \[advice in the doctype deprecation notes\](https://www.elastic.co/guide/en/elasticsearch/reference/current/removal-of-types.html#\_schedule\_for\_removal\_of\_mapping\_types) is to use a document type of \`\_doc\` in 6.x to prepare for type removal. However the Logstash Elasticsearch \[output plugin defaults\](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-document\_type) to \`doc\`.
> 
> At this point we should be able to omit the \`document\_type\` parameter (\*which flags a deprecation warning!\*) and not require that configuration change between 6.x and 7.x.

But that does not explain why it works on my test system without issue...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 3, 2021, 4:04am UTC](https://discuss.elastic.co/t/logstash-rejected-mapping-update-not-sure-how-to-rectify-the-situation/280269/3 "2021-08-03T04:04:54Z")

</div>

> [@CameronCenic](#):
>
> I suspect this is due to me switching my template from using doc to using \_doc

Yep most likely.

What does your Logstash pipeline config look like?

---

<div class="post-metadata">

**Author:** ![CameronCenic](https://avatars.discourse-cdn.com/v4/letter/c/df788c/32.png) [@CameronCenic](https://discuss.elastic.co/u/CameronCenic)\
**Post date:** [August 3, 2021, 4:17am UTC](https://discuss.elastic.co/t/logstash-rejected-mapping-update-not-sure-how-to-rectify-the-situation/280269/4 "2021-08-03T04:17:49Z")

</div>

Neither the input nor output are specifying the type. For some reason the index template is not applying in my test environment, but is in my production environment.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 3, 2021, 4:20am UTC](https://discuss.elastic.co/t/logstash-rejected-mapping-update-not-sure-how-to-rectify-the-situation/280269/5 "2021-08-03T04:20:25Z")

</div>

Have you tried removing the type from the template definition?

---

<div class="post-metadata">

**Author:** ![CameronCenic](https://avatars.discourse-cdn.com/v4/letter/c/df788c/32.png) [@CameronCenic](https://discuss.elastic.co/u/CameronCenic)\
**Post date:** [August 3, 2021, 4:22am UTC](https://discuss.elastic.co/t/logstash-rejected-mapping-update-not-sure-how-to-rectify-the-situation/280269/6 "2021-08-03T04:22:36Z")

</div>

That is basically what I did, I created the template with include\_type\_name=false. The only fix I can see is to use include\_type\_name=true and specify the type as "doc". This is Logstash/Elastic 6.8 btw.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2021, 4:23am UTC](https://discuss.elastic.co/t/logstash-rejected-mapping-update-not-sure-how-to-rectify-the-situation/280269/7 "2021-08-31T04:23:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
