# Mappings messed up...help?

**URL:** <https://discuss.elastic.co/t/mappings-messed-up-help/20925>\
**Category:** Elasticsearch\
**Created:** [November 25, 2014, 12:07am UTC](https://discuss.elastic.co/t/mappings-messed-up-help/20925 "2014-11-25T00:07:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jack\_Judge](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_judge/32/85499_2.png) [@Jack\_Judge](https://discuss.elastic.co/u/Jack_Judge)\
**Post date:** [November 25, 2014, 12:07am UTC](https://discuss.elastic.co/t/mappings-messed-up-help/20925/1 "2014-11-25T00:07:01Z")

</div>

Hi Folks,  
Blundering around with an ELK stack I've managed to break it, yay me!  
I was trying to disable the \_all field as (I believe) it basically  
duplicates all the data I'm already storing, so after way too much googling  
I came up with this,

curl -XPUT [http://localhost:9200/\_template/logstash\_per\_index](http://localhost:9200/_template/logstash_per_index) -d '{  
"template" : "logstash\*",  
"settings" : {  
"number\_of\_shards" : 2,  
"index.cache.field.type" : "soft",  
"index.refresh\_interval" : "5s",  
"index.store.compress.stored" : true,  
"index.query.default\_field" : "@message"  
},  
"mappings" : {  
"_default_" : {  
"\_all" : {"enabled" : false},  
"properties" : {  
"@fields" : {  
"type" : "object",  
"dynamic": true,  
"path": "full",  
"properties" : {  
"clientip" : { "type": "ip"}  
}  
},  
"@message": { "type": "string", "index": "analyzed" },  
"@source": { "type": "string", "index": "analyzed" },  
"@source\_host": { "type": "string", "index": "analyzed" },  
"@source\_path": { "type": "string", "index": "analyzed" },  
"@tags": { "type": "string", "index": "analyzed" },  
"@timestamp": { "type": "date", "index": "analyzed" },  
"@type": { "type": "string", "index": "analyzed" }  
}  
}  
}  
}  
'  
And now kibana isn't showing anything from the time the mapping was  
applied, older data is fine. I can see documents and data going into the  
stack via Bigdesk and Head but I can't visualise them with kibana. Can  
anyone help ? What did I do wrong ?  
At the moment I'd settle for reapplying the default out-of-the-box mappings  
if I could find them anywhere, or if I knew how to do it ☹

JJ

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/cad60329-5d03-42a9-8842-fd378d4ea66b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/cad60329-5d03-42a9-8842-fd378d4ea66b%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 25, 2014, 1:32am UTC](https://discuss.elastic.co/t/mappings-messed-up-help/20925/2 "2014-11-25T01:32:11Z")

</div>

You need to set index.query.default\_field, see

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

On 25 November 2014 at 11:07, Jack Judge [jackjudge01@gmail.com](mailto:jackjudge01@gmail.com) wrote:

> Hi Folks,  
> Blundering around with an ELK stack I've managed to break it, yay me!  
> I was trying to disable the \_all field as (I believe) it basically  
> duplicates all the data I'm already storing, so after way too much googling  
> I came up with this,
> 
> curl -XPUT [http://localhost:9200/\_template/logstash\_per\_index](http://localhost:9200/_template/logstash_per_index) -d '{  
> "template" : "logstash\*",  
> "settings" : {  
> "number\_of\_shards" : 2,  
> "index.cache.field.type" : "soft",  
> "index.refresh\_interval" : "5s",  
> "index.store.compress.stored" : true,  
> "index.query.default\_field" : "@message"  
> },  
> "mappings" : {  
> "_default_" : {  
> "\_all" : {"enabled" : false},  
> "properties" : {  
> "@fields" : {  
> "type" : "object",  
> "dynamic": true,  
> "path": "full",  
> "properties" : {  
> "clientip" : { "type": "ip"}  
> }  
> },  
> "@message": { "type": "string", "index": "analyzed" },  
> "@source": { "type": "string", "index": "analyzed" },  
> "@source\_host": { "type": "string", "index": "analyzed" },  
> "@source\_path": { "type": "string", "index": "analyzed" },  
> "@tags": { "type": "string", "index": "analyzed" },  
> "@timestamp": { "type": "date", "index": "analyzed" },  
> "@type": { "type": "string", "index": "analyzed" }  
> }  
> }  
> }  
> }  
> '  
> And now kibana isn't showing anything from the time the mapping was  
> applied, older data is fine. I can see documents and data going into the  
> stack via Bigdesk and Head but I can't visualise them with kibana. Can  
> anyone help ? What did I do wrong ?  
> At the moment I'd settle for reapplying the default out-of-the-box  
> mappings if I could find them anywhere, or if I knew how to do it ☹
> 
> JJ
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/cad60329-5d03-42a9-8842-fd378d4ea66b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/cad60329-5d03-42a9-8842-fd378d4ea66b%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/cad60329-5d03-42a9-8842-fd378d4ea66b%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/cad60329-5d03-42a9-8842-fd378d4ea66b%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAF3ZnZk0oJ%3D7WXpO4euVYpK5St7\_XZ-DWnyeDBF%2BJbfy5PcHKQ%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAF3ZnZk0oJ%3D7WXpO4euVYpK5St7_XZ-DWnyeDBF%2BJbfy5PcHKQ%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:47am UTC](https://discuss.elastic.co/t/mappings-messed-up-help/20925/3 "2017-07-06T00:47:54Z")

</div>


