# Mixing up field types - can we force text to keyword?

**URL:** <https://discuss.elastic.co/t/mixing-up-field-types-can-we-force-text-to-keyword/171167>\
**Category:** Elasticsearch\
**Created:** [March 6, 2019, 5:40pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-can-we-force-text-to-keyword/171167 "2019-03-06T17:40:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![exocore123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exocore123/32/45130_2.png) [@exocore123](https://discuss.elastic.co/u/exocore123)\
**Post date:** [March 6, 2019, 5:40pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-can-we-force-text-to-keyword/171167/1 "2019-03-06T17:40:10Z")

</div>

`Could not index event to Elasticsearch. {:status=&gt;400, :action=&gt;["index", {:_id=&gt;"52801f35-d64d-4585-b698-5628baa8552d", :_index=&gt;"logstash-summary-2019.03.06", :_type=&gt;"doc", :_routing=&gt;nil}, #&lt;LogStash::Event:0x2f805b51&gt;], :response=&gt;{"index"=&gt;{"_index"=&gt;"logstash-summary-2019.03.06", "_type"=&gt;"doc", "_id"=&gt;"52801f35-d64d-4585-b698-5628baa8552d", "status"=&gt;400, "error"=&gt;{"type"=&gt;"mapper_parsing_exception", "reason"=&gt;"failed to parse", "caused_by"=&gt;{"type"=&gt;"illegal_state_exception", "reason"=&gt;"Mixing up field types: class org.elasticsearch.index.mapper.TextFieldMapper$TextFieldType != class org.elasticsearch.index.mapper.KeywordFieldMapper$KeywordFieldType on field orderID"}}}}}`

I am trying to fix this issue. I recently learned about the mapping files and changes between ES2 to ES5 and ES6. My original issue was that I had a field that was of type string, which caused incorrect query results in elasticsearch so in return, I had incorrect data. However, I've been trying to replace this field to be a `type;keyword` OR `type:string` with `index:not_analyzed`, but whenever I apply that change on the template. I keep getting that error. So the template applies for all indices with the matching template name correct? I am not sure why when I delete all my indices and delete my template on ES and redeploy a fresh version. I still get the error above. Is there some hidden thing I am forgetting to change? Could it be logstash causing this field to be Text?

```
{
	"template": "logstash-summary-*",
	"settings": {
		"index.refresh_interval": "5s"
	},
	"mappings": {
		"logs": {
			"_all": {
				"enabled": true,
				"omit_norms": true
			},
			"dynamic_templates": [
				{
					"message_field": {
						"match": "message",
						"match_mapping_type": "string",
						"mapping": {
							"type": "string",
							"index": "analyzed",
							"omit_norms": true
						}
					}
				},
				{
					"string_fields": {
						"match": "*",
						"match_mapping_type": "string",
						"mapping": {
							"type": "string",
							"index": "not_analyzed",
							"ignore_above": 256
						}
					}
				}
			],
			"properties": {
				"orderID": {
					"type": "string",
					"index": "not_analyzed"
				}
			}
		}
	}
}

```

This is my new template. Originally under orderID, I just have `type:string`, no index parameter. I get the same error when I change it to `type:keyword` (I understand ES5 and ES6 use `type:keyword` as a `type:string` with `index:not_analyzed`)

This is the template that I pull from the index

```
{
  "logstash-summary-2019.03.06": {
    "mappings": {
      "logs": {
        "_all": {
          "enabled": true,
          "norms": false
        },
        "dynamic_templates": [
          {
            "message_field": {
              "match": "message",
              "path_match": "message",
              "match_mapping_type": "string",
              "mapping": {
                "index": "analyzed",
                "norms": false,
                "omit_norms": true,
                "type": "string"
              }
            }
          },
          {
            "string_fields": {
              "match": "*",
              "match_mapping_type": "string",
              "mapping": {
                "fields": {
                  "keyword": {
                    "ignore_above": 256,
                    "type": "keyword"
                  }
                },
                "ignore_above": 256,
                "index": "not_analyzed",
                "norms": false,
                "type": "string"
              }
            }
          }
        ],
        "properties": {
          "@timestamp": {
            "type": "date",
            "include_in_all": false
          },
          "@version": {
            "type": "keyword",
            "include_in_all": false
          },
          "geoip": {
            "dynamic": "true",
            "properties": {
              "ip": {
                "type": "ip"
              },
              "latitude": {
                "type": "half_float"
              },
              "location": {
                "type": "geo_point"
              },
              "longitude": {
                "type": "half_float"
              }
            }
          },
          "orderID": {
            "type": "keyword"
          }
        }
      }
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![exocore123](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exocore123/32/45130_2.png) [@exocore123](https://discuss.elastic.co/u/exocore123)\
**Post date:** [March 11, 2019, 3:44pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-can-we-force-text-to-keyword/171167/2 "2019-03-11T15:44:48Z")

</div>

I found out that there was another template with a shorter prefix `logstash-*` which caused this template to be applied as well as my previous template. Had to delete that template for my correct template to be applied.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 8, 2019, 3:44pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-can-we-force-text-to-keyword/171167/3 "2019-04-08T15:44:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
