# Mapper\_parsing\_exception with template

**URL:** <https://discuss.elastic.co/t/mapper-parsing-exception-with-template/114534>\
**Category:** Elasticsearch\
**Created:** [January 8, 2018, 1:59pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-with-template/114534 "2018-01-08T13:59:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![florentmair](https://avatars.discourse-cdn.com/v4/letter/f/8e7dd6/32.png) [@florentmair](https://discuss.elastic.co/u/florentmair)\
**Post date:** [January 8, 2018, 1:59pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-with-template/114534/1 "2018-01-08T13:59:39Z")

</div>

Hello,

i am updated my cluster from 5.6.1 to 6.1.1 and i am not able to create new index if i use template

My template

```
PUT _template/tds_audit 
{
    "order": 0,
    "index_patterns": "logstash-tds_audit*",
    "settings": {
      "index.number_of_shards": "4"
    },
    "mappings": {
      "tds_audit": {
        "properties": {
          "operationResponseTime": {
            "type": "double"
          },
          "timeOnWorkQ": {
            "type": "double"
          },
          "rdbmLockWaitTime": {
            "type": "double"
          },
          "clientIOTime": {
            "type": "double"
          },
          "numberOfEntriesReturned": {
            "type": "long"
          },
          "client_ip": {
            "type": "ip"
        }
      }
    }
  }
}

```

now i trying to create an index  
`PUT logstash-tds_audit-200`

```
{
  "error": {
    "root_cause": [
      {
        "type": "mapper_parsing_exception",
        "reason": "[include_in_all] is not allowed for indices created on or after version 6.0.0 as [_all] is deprecated. As a replacement, you can use an [copy_to] on mapping fields to create your own catch all field."
      }
    ],
    "type": "mapper_parsing_exception",
    "reason": "Failed to parse mapping [_default_]: [include_in_all] is not allowed for indices created on or after version 6.0.0 as [_all] is deprecated. As a replacement, you can use an [copy_to] on mapping fields to create your own catch all field.",
    "caused_by": {
      "type": "mapper_parsing_exception",
      "reason": "[include_in_all] is not allowed for indices created on or after version 6.0.0 as [_all] is deprecated. As a replacement, you can use an [copy_to] on mapping fields to create your own catch all field."
    }
  },
  "status": 400
}

```

i don't undestand why the "_default_" mapping still exists

any ideas ?

Regards  
Florent

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [January 8, 2018, 2:02pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-with-template/114534/2 "2018-01-08T14:02:44Z")

</div>

Do you have other templates present in ES? What does `GET _template` yield?

---

<div class="post-metadata">

**Author:** ![florentmair](https://avatars.discourse-cdn.com/v4/letter/f/8e7dd6/32.png) [@florentmair](https://discuss.elastic.co/u/florentmair)\
**Post date:** [January 8, 2018, 2:32pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-with-template/114534/3 "2018-01-08T14:32:41Z")

</div>

yes i have many other template.  
What should i check ?

---

<div class="post-metadata">

**Author:** ![florentmair](https://avatars.discourse-cdn.com/v4/letter/f/8e7dd6/32.png) [@florentmair](https://discuss.elastic.co/u/florentmair)\
**Post date:** [January 8, 2018, 2:39pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-with-template/114534/4 "2018-01-08T14:39:05Z")

</div>

Arrgh i found an old template from logstash

```
  "logstash": {
    "order": 0,
    "version": 50001,
    "index_patterns": [
      "logstash-*"
    ],
    "settings": {
      "index": {
        "refresh_interval": "5s"
      }
    },
    "mappings": {
      "_default_": {
        "_all": {
          "enabled": true,
          "norms": false
        },
....

```

can i delete it or logstash should update this one ?

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [January 8, 2018, 2:39pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-with-template/114534/5 "2018-01-08T14:39:32Z")

</div>

Ok, then you definitely have one template whose pattern also matches `logstash-tds_audit-200` but whose definition is not 6.1.1 compatible

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [January 8, 2018, 2:40pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-with-template/114534/6 "2018-01-08T14:40:37Z")

</div>

You can delete it manually but you also need to figure out which logstash is managing it and make sure it updates it to something that is compatible with 6.1.1, i.e. make sure that Logstash does not recreate that old template

---

<div class="post-metadata">

**Author:** ![florentmair](https://avatars.discourse-cdn.com/v4/letter/f/8e7dd6/32.png) [@florentmair](https://discuss.elastic.co/u/florentmair)\
**Post date:** [January 8, 2018, 2:54pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-with-template/114534/7 "2018-01-08T14:54:43Z")

</div>

I confirm that we can delete the template "logstash" created by logstash 5.X, it seems thats in 6.X the template is called "logstash-index-template"

the problem is solved after removed this old template

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [January 8, 2018, 2:56pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-with-template/114534/8 "2018-01-08T14:56:24Z")

</div>

Cool, glad you figured it out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2018, 2:56pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-with-template/114534/9 "2018-02-05T14:56:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
