# Migration from ES 6.8 to 7.17 : Issues with negative date epoch timestamp

**URL:** <https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259>\
**Category:** Elasticsearch\
**Created:** [June 5, 2023, 8:49pm UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259 "2023-06-05T20:49:15Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abhilashsr2008](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhilashsr2008/32/144143_2.png) [@Abhilashsr2008](https://discuss.elastic.co/u/Abhilashsr2008)\
**Post date:** [June 5, 2023, 8:49pm UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259/1 "2023-06-05T20:49:15Z")

</div>

Hi Guys  
We are migrating our applications from 6.8 ES cluster to 7.17.10 ES cluster . The one thing which we identified is that the negative values are not supported for date type fields( "format": "epoch\_millis") . Is there any way to make it support in 7.17.10 ? because we see this PR to support this [support negative epoch\_millis timestamps by rkophs · Pull Request #80208 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/pull/80208) which looks like fixed in ES 8.XX versions . Can someone guide me how we can resolve this issue . we can't change the data type of this field . Also is there any way in ES to lets say disable template validation specific to one field . Please suggest which is the better way to handle this issue ?

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 6, 2023, 9:14am UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259/2 "2023-06-06T09:14:37Z")

</div>

Hi @Abhilashsr2008,

Digging through the [issue you cite](https://github.com/elastic/elasticsearch/pull/80208) and the related documentation issue it looks like negative timestamps are supported as of version 8.2.0. Is there a reason you are not able to upgrade?

The other option I can think of is using the [`ignore_malformed` attribute](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/ignore-malformed.html) on your field until you can upgrade.

---

<div class="post-metadata">

**Author:** ![Abhilashsr2008](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhilashsr2008/32/144143_2.png) [@Abhilashsr2008](https://discuss.elastic.co/u/Abhilashsr2008)\
**Post date:** [June 6, 2023, 7:51pm UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259/3 "2023-06-06T19:51:40Z")

</div>

Thanks @carly.richmond for the comments . Yes we are planning for 8.XX upgrade soon but few other apps still need support from ES 8.XX which we are waiting to complete . Once thats done the idea is to move to latest Elastic search . This is an intermediate solution we are looking for. Also lets say we have a index in ES 6.8 where the date field has negative values and when we do the rolling upgrade to 7.17 , the old index will have some problem right since the old index had negative values and new ES 7.17 doesn't support it . or is it like the existing data in ES 6.8 will not have any issue during rolling upgrade and new data insertion to ES 7.17 with negative values for date fields will have a problem

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 7, 2023, 9:48am UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259/4 "2023-06-07T09:48:55Z")

</div>

Yes you will have a validation problem on the field with the negative values. For a temporary workaround I would have a look at `ignore_malformed` as listed above.

---

<div class="post-metadata">

**Author:** ![Abhilashsr2008](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhilashsr2008/32/144143_2.png) [@Abhilashsr2008](https://discuss.elastic.co/u/Abhilashsr2008)\
**Post date:** [June 7, 2023, 4:27pm UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259/5 "2023-06-07T16:27:55Z")

</div>

yes thanks @carly.richmond . So what am thinking , may be before the rolling upgrade , i will add `ignore_malformed` property to the current index template in 6.8 ES and then do the rolling upgrade to 7.17 ES. is this approach good ? so in that way during rolling upgrade i shouldn't get any issues . what do you think

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 8, 2023, 9:07am UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259/6 "2023-06-08T09:07:30Z")

</div>

I would check the data is being indexing in version 6.8 with the `ignore_malformed` for the fields in question as you expect and also take a snapshot first. But yes you can do a rolling upgrade between 6.8 and 7.17.10. There's details for rolling upgrades in the below sections of the documentation:

1. [Upgrade Elasticsearch](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/setup-upgrade.html)
2. [Rolling upgrades](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/rolling-upgrades.html)

---

<div class="post-metadata">

**Author:** ![Abhilashsr2008](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abhilashsr2008/32/144143_2.png) [@Abhilashsr2008](https://discuss.elastic.co/u/Abhilashsr2008)\
**Post date:** [June 9, 2023, 6:45am UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259/8 "2023-06-09T06:45:26Z")

</div>

@carly.richmond have did some digging and find out that when we set ignore\_malformed for the date i was able to insert negative values to my new index . But the problem comes when i make a query with that specific field . Elastic search throws exception saying that i wont be able to access this field . Is it because , when we set ignore\_malformed field , ES removed this field from its indexing which caused later query failures ? can you please confirm whether my understanding is correct . Attaching the query failure

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/9/292eae71e0d13fa661802f01c509780fb4c09cfa.png)

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 21, 2023, 10:19am UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259/9 "2023-06-21T10:19:06Z")

</div>

Hi @Abhilashsr2008,

That understanding does sound correct to me. If you're needing to query these fields I strongly recommend you upgrade to get the fix, where you won't need `ignore_malformed`.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2023, 10:19am UTC](https://discuss.elastic.co/t/migration-from-es-6-8-to-7-17-issues-with-negative-date-epoch-timestamp/335259/10 "2023-07-19T10:19:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
