# Mapping definition for \[message\] has unsupported parameters: \[ignore\_above : 1024\]

**URL:** <https://discuss.elastic.co/t/mapping-definition-for-message-has-unsupported-parameters-ignore-above-1024/154455>\
**Category:** Elasticsearch\
**Created:** [October 29, 2018, 2:20pm UTC](https://discuss.elastic.co/t/mapping-definition-for-message-has-unsupported-parameters-ignore-above-1024/154455 "2018-10-29T14:20:18Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kieren\_Johnstone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kieren_johnstone/32/26311_2.png) [@Kieren\_Johnstone](https://discuss.elastic.co/u/Kieren_Johnstone)\
**Post date:** [October 29, 2018, 2:20pm UTC](https://discuss.elastic.co/t/mapping-definition-for-message-has-unsupported-parameters-ignore-above-1024/154455/1 "2018-10-29T14:20:18Z")

</div>

It's a new week, and seemingly randomly, this week's log index is failing to be created.

Logged from filebeat is:

{"type":"mapper\_parsing\_exception","reason":"Failed to parse mapping [doc]: Mapping definition for [message] has unsupported parameters: [ignore\_above : 1024]","caused\_by":{"type":"mapper\_parsing\_exception","reason":"Mapping definition for [message] has unsupported parameters: [ignore\_above : 1024]"}}

I've checked and have 3 (identical-looking) index templates, as has been the case for a few months without issue. The filebeat version is a little out of date (6.3.2), but has been working fine up to this point.

The "message" property seems to potentially be covered in the template in two ways:

Dynamic template mapping:

```
        "strings_as_keyword": {
          "mapping": {
            "ignore_above": 1024,
            "type": "keyword"
          },
          "match_mapping_type": "string"
        }

```

General field mapping:

```
              "message": {
                "type": "text",
                "norms": false
              },

```

I'm just using the "raw JSON" mode for sending the contents of text files with one JSON document per row to ES, so it's not an app-specific type of document.

All I can think is that the general field mapping is only overriding the "type" and "norms" prop or something? The dynamic template may be a red herring, I don't know...

But how can I diagnose and fix this issue? A few 100ks of events are queuing up 🙂

Any help appreciated..

Edit: the response to GET /\_template: [https://gist.github.com/kierenj/a91df51630b1d06798a105e7a66eb5dd](https://gist.github.com/kierenj/a91df51630b1d06798a105e7a66eb5dd) . Index name is filebeat-rr-logs-6.3.2-2018.44 (or would be, if it would create)

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 29, 2018, 3:49pm UTC](https://discuss.elastic.co/t/mapping-definition-for-message-has-unsupported-parameters-ignore-above-1024/154455/2 "2018-10-29T15:49:32Z")

</div>

Hi @Kieren_Johnstone,

I am not sure about what can be the issue, but by now I see that the index templates you have installed don't include the version:

```auto
  "filebeat-rr-logs": {
    "order": 1,
    "index_patterns": [
      "filebeat-rr-logs-*"
    ],
  ...
  "filebeat-rr": {
    "order": 1,
    "index_patterns": [
      "filebeat-rr-*"
    ],

```

This can make different versions to store events in the same index, what can lead to unexpected mapping issues.

Is this intended? How did you install your index templates?

---

<div class="post-metadata">

**Author:** ![Kieren\_Johnstone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kieren_johnstone/32/26311_2.png) [@Kieren\_Johnstone](https://discuss.elastic.co/u/Kieren_Johnstone)\
**Post date:** [October 29, 2018, 8:47pm UTC](https://discuss.elastic.co/t/mapping-definition-for-message-has-unsupported-parameters-ignore-above-1024/154455/3 "2018-10-29T20:47:00Z")

</div>

I installed the filebeat templates manually, probably a few times with slightly different settings. I read that the version field was ignored and only for external template management systems? arent multiple index templates ehich match the pattern just combined? They all look the same to me so wouldnt that have no effect?

---

<div class="post-metadata">

**Author:** ![Kieren\_Johnstone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kieren_johnstone/32/26311_2.png) [@Kieren\_Johnstone](https://discuss.elastic.co/u/Kieren_Johnstone)\
**Post date:** [October 30, 2018, 8:07am UTC](https://discuss.elastic.co/t/mapping-definition-for-message-has-unsupported-parameters-ignore-above-1024/154455/4 "2018-10-30T08:07:51Z")

</div>

Would appreciate any help at all, I'm fairly desperate and our production logging server is backing up very quickly indeed.

---

<div class="post-metadata">

**Author:** ![Kieren\_Johnstone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kieren_johnstone/32/26311_2.png) [@Kieren\_Johnstone](https://discuss.elastic.co/u/Kieren_Johnstone)\
**Post date:** [October 31, 2018, 3:13pm UTC](https://discuss.elastic.co/t/mapping-definition-for-message-has-unsupported-parameters-ignore-above-1024/154455/5 "2018-10-31T15:13:48Z")

</div>

Can anyone help at all? Or tell me where I can find help?

(The elastic paid support plan's basic cluster costing requirement is $15.5k commitment, or consultancy starts at £3,600 with a minimum of 4 days. I'm at your mercy!)

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [October 31, 2018, 4:19pm UTC](https://discuss.elastic.co/t/mapping-definition-for-message-has-unsupported-parameters-ignore-above-1024/154455/6 "2018-10-31T16:19:49Z")

</div>

I think this can be more an issue with Elasticsearch than with Beats, I am going to move this topic to the ES category.

Btw, what is the ES version you are using?

---

<div class="post-metadata">

**Author:** ![Kieren\_Johnstone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kieren_johnstone/32/26311_2.png) [@Kieren\_Johnstone](https://discuss.elastic.co/u/Kieren_Johnstone)\
**Post date:** [November 1, 2018, 9:06am UTC](https://discuss.elastic.co/t/mapping-definition-for-message-has-unsupported-parameters-ignore-above-1024/154455/7 "2018-11-01T09:06:31Z")

</div>

Thanks 🙂 My ES version is 6.4.2.

I carefully deleted two of the duplicate index templates and the issue seems to be resolved.

(No idea how it worked for the previous 43 weeks..)

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [November 1, 2018, 10:46am UTC](https://discuss.elastic.co/t/mapping-definition-for-message-has-unsupported-parameters-ignore-above-1024/154455/8 "2018-11-01T10:46:10Z")

</div>

I'm glad to read that you found a workaround.  
In any case consider to add the filebeat version to the index patterns, specially if you use different versions at the same time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2018, 10:46am UTC](https://discuss.elastic.co/t/mapping-definition-for-message-has-unsupported-parameters-ignore-above-1024/154455/9 "2018-11-29T10:46:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
