# Mixing up field types error: IP field is not getting added

**URL:** <https://discuss.elastic.co/t/mixing-up-field-types-error-ip-field-is-not-getting-added/55332>\
**Category:** Elasticsearch\
**Created:** [July 12, 2016, 4:17pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-error-ip-field-is-not-getting-added/55332 "2016-07-12T16:17:06Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![vishnubraj](https://avatars.discourse-cdn.com/v4/letter/v/bc79bd/32.png) [@vishnubraj](https://discuss.elastic.co/u/vishnubraj)\
**Post date:** [July 12, 2016, 4:17pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-error-ip-field-is-not-getting-added/55332/1 "2016-07-12T16:17:06Z")

</div>

i did a manual mapping in Elasticsearch. but i am getting the below error. Can you please help.

Failed action. {:status=\>400, :action=\>["index", {:\_id=\>nil, :_index=\>"netflow_", :\_type=\>"logs", :\_routing=\>nil}, #\<LogStash::Event:0x481034c7 @metadata\_accessors=#\<LogStash::Util::Accessors:0x7b26b09 @store={}, @lut={}\>, @cancelled=false, @data={"tag"=\>0, "as\_src"=\>0, "label"=\>"DFW1", "ip\_src"=\>"10.160.10.31", "packets"=\>1, "country\_ip\_dst"=\>"", "as\_dst"=\>0, "peer\_ip\_src"=\>"10.0.11.252", "bytes"=\>55, "iface\_out"=\>30, "iface\_in"=\>18, "ip\_dst"=\>"10.160.22.31", "mask\_src"=\>0, "mask\_dst"=\>0, "port\_src"=\>45005, "port\_dst"=\>15353, "stamp\_inserted"=\>"2016-07-12 15:48:00", "country\_ip\_src"=\>"", "ip\_proto"=\>"udp", "stamp\_updated"=\>"2016-07-12 15:51:10", "@version"=\>"1", "@timestamp"=\>"2016-07-12T15:54:37.015Z"}, @metadata={}, @accessors=#\<LogStash::Util::Accessors:0x6e830327 @store={"tag"=\>0, "as\_src"=\>0, "label"=\>"DFW1", "ip\_src"=\>"10.160.10.31", "packets"=\>1, "country\_ip\_dst"=\>"", "as\_dst"=\>0, "peer\_ip\_src"=\>"10.0.11.252", "bytes"=\>55, "iface\_out"=\>30, "iface\_in"=\>18, "ip\_dst"=\>"10.160.22.31", "mask\_src"=\>0, "mask\_dst"=\>0, "port\_src"=\>45005, "port\_dst"=\>15353, "stamp\_inserted"=\>"2016-07-12 15:48:00", "country\_ip\_src"=\>"", "ip\_proto"=\>"udp", "stamp\_updated"=\>"2016-07-12 15:51:10", "@version"=\>"1", "@timestamp"=\>"2016-07-12T15:54:37.015Z"}, @lut={"type"=\>[{"tag"=\>0, "as\_src"=\>0, "label"=\>"DFW1", "ip\_src"=\>"10.160.10.31", "packets"=\>1, "country\_ip\_dst"=\>"", "as\_dst"=\>0, "peer\_ip\_src"=\>"10.0.11.252", "bytes"=\>55, "iface\_out"=\>30, "iface\_in"=\>18, "ip\_dst"=\>"10.160.22.31", "mask\_src"=\>0, "mask\_dst"=\>0, "port\_src"=\>45005, "port\_dst"=\>15353, "stamp\_inserted"=\>"2016-07-12 15:48:00", "country\_ip\_src"=\>"", "ip\_proto"=\>"udp", "stamp\_updated"=\>"2016-07-12 15:51:10", "@version"=\>"1", "@timestamp"=\>"2016-07-12T15:54:37.015Z"}, "type"]}\>\>], :response=\>{"create"=\>{"_index"=\>"netflow_", "\_type"=\>"logs", "\_id"=\>"AVXf0TPx-AQHNLHZG1yY", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"=\>"Mixing up field types: class org.elasticsearch.index.mapper.core.LongFieldMapper$LongFieldType != class org.elasticsearch.index.mapper.ip.IpFieldMapper$IpFieldType on field ip\_src"}}}}, :level=\>:warn}

Below is my template config:

curl -XGET localhost:9200/_template/\*?pretty  
{  
"my\_logs" : {  
"order" : 1,  
"template" : "netflow_\*",  
"settings" : {  
"index" : {  
"number\_of\_shards" : "1",  
"number\_of\_replicas" : "0"  
}  
},  
"mappings" : {  
"logs" : {  
"properties" : {  
"ip\_proto" : {  
"type" : "string"  
},  
"iface\_in" : {  
"type" : "long"  
},  
"iface\_out" : {  
"type" : "long"  
},  
"src\_host\_country" : {  
"type" : "geo\_point"  
},  
"peer\_ip\_src" : {  
"type" : "ip"  
},  
"ip\_src" : {  
"type" : "ip"  
},  
"port\_dst" : {  
"type" : "long"  
},  
"port\_src" : {  
"type" : "long"  
},  
"ip\_dst" : {  
"type" : "ip"  
},  
"as\_src" : {  
"type" : "long"  
},  
"@timestamp" : {  
"type" : "date"  
},  
"mask\_dst" : {  
"type" : "ip"  
},  
"mask\_src" : {  
"type" : "ip"  
},  
"dst\_host\_country" : {  
"type" : "geo\_point"  
},  
"as\_dst" : {  
"type" : "long"  
}  
}  
}  
},  
"aliases" : { }  
}  
}

---

<div class="post-metadata">

**Author:** ![vishnubraj](https://avatars.discourse-cdn.com/v4/letter/v/bc79bd/32.png) [@vishnubraj](https://discuss.elastic.co/u/vishnubraj)\
**Post date:** [July 13, 2016, 12:44pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-error-ip-field-is-not-getting-added/55332/2 "2016-07-13T12:44:43Z")

</div>

> [@vishnubraj](#):
>
> Mixing up field types

Can anyone help to fix this.

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [July 13, 2016, 3:08pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-error-ip-field-is-not-getting-added/55332/3 "2016-07-13T15:08:04Z")

</div>

Is the `ip_src` field mapped as a long on one of your types?

---

<div class="post-metadata">

**Author:** ![vishnubraj](https://avatars.discourse-cdn.com/v4/letter/v/bc79bd/32.png) [@vishnubraj](https://discuss.elastic.co/u/vishnubraj)\
**Post date:** [July 13, 2016, 3:50pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-error-ip-field-is-not-getting-added/55332/4 "2016-07-13T15:50:03Z")

</div>

No in template i mentioned it as type IP.. so the mapping should happen based on template right?  
sorry i am very new to elastic search

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [July 13, 2016, 4:01pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-error-ip-field-is-not-getting-added/55332/5 "2016-07-13T16:01:22Z")

</div>

Right, so I was wondering that maybe you are putting explicit mappings as well in the same index?

If not, can you provide us with a contained recreation of the issue that we can look into?

---

<div class="post-metadata">

**Author:** ![vishnubraj](https://avatars.discourse-cdn.com/v4/letter/v/bc79bd/32.png) [@vishnubraj](https://discuss.elastic.co/u/vishnubraj)\
**Post date:** [July 13, 2016, 6:05pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-error-ip-field-is-not-getting-added/55332/6 "2016-07-13T18:05:31Z")

</div>

No.. I am not putting any mapping in the index.  
The error is gone now.. but i am not able to change the type field of ip\_src and ip\_dst to ip. it takes the default value when the index get created.

Here is my logstash.conf

input {  
kafka {  
zk\_connect =\> "localhost:3181"  
topic\_id =\> "pmacct.acct"  
}  
}  
output {  
elasticsearch {  
hosts =\> "127.0.0.1"  
index =\> "logs\_%{+YYYY\_MM\_dd}"  
manage\_template =\> false  
}  
}

My template file:

curl -XGET localhost:9200/_template/\*?pretty  
{  
"logs" : {  
"order" : 0,  
"template" : "logs_\*",  
"settings" : {  
"index" : {  
"number\_of\_shards" : "1",  
"number\_of\_replicas" : "0",  
"mappings" : {  
"logs" : {  
"properties" : {  
"@version" : {  
"type" : "integer",  
"index" : "analyzed"  
},  
"netflow" : {  
"type" : "object",  
"dynamic" : "strict",  
"properties" : {  
"iface\_in" : {  
"type" : "long"  
},  
"ip\_proto" : {  
"type" : "string"  
},  
"iface\_out" : {  
"type" : "long"  
},  
"ip\_src" : {  
"type" : "ip"  
},  
"peer\_ip\_src" : {  
"type" : "ip"  
},  
"port\_dst" : {  
"type" : "long"  
},  
"port\_src" : {  
"type" : "long"  
},  
"label" : {  
"type" : "string"  
},  
"ip\_dst" : {  
"type" : "ip"  
},  
"packets" : {  
"type" : "long"  
},  
"as\_src" : {  
"type" : "long"  
},  
"stamp\_updated" : {  
"type" : "date"  
},  
"stamp\_inserted" : {  
"type" : "date"  
},  
"bytes" : {  
"bytes" : "long"  
},  
"country\_ip\_src" : {  
"type" : "geo\_point"  
},  
"mask\_dst" : {  
"type" : "long"  
},  
"country\_ip\_dst" : {  
"type" : "geo\_point"  
},  
"mask\_src" : {  
"type" : "long"  
},  
"tag" : {  
"type" : "number"  
},  
"as\_dst" : {  
"type" : "long"  
}  
}  
},  
"@timestamp" : {  
"type" : "date",  
"index" : "analyzed"  
}  
}  
}  
}  
}  
},  
"mappings" : { },  
"aliases" : { }  
}  
}

Elasticsearch log:

[2016-07-13 17:57:02,249][INFO][cluster.metadata] [Barnacle] [logs\_2016\_07\_13] creating index, cause [auto(bulk api)], templates [logs], shards [1]/[0], mappings [logs]  
[2016-07-13 17:57:02,263][INFO][cluster.routing.allocation] [Barnacle] Cluster health status changed from [RED] to [YELLOW] (reason: [shards started [[logs\_2016\_07\_13][0]] ...]).  
[2016-07-13 17:57:02,269][INFO][cluster.metadata] [Barnacle] [logs\_2016\_07\_13] update\_mapping [logs]

---

<div class="post-metadata">

**Author:** ![vishnubraj](https://avatars.discourse-cdn.com/v4/letter/v/bc79bd/32.png) [@vishnubraj](https://discuss.elastic.co/u/vishnubraj)\
**Post date:** [July 13, 2016, 6:05pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-error-ip-field-is-not-getting-added/55332/7 "2016-07-13T18:05:43Z")

</div>

This is the mapping file which got created automatically.

curl -XGET localhost:9200/logs\_2016\_07\_13/\_mappings/?pretty=true  
{  
"logs\_2016\_07\_13" : {  
"mappings" : {  
"logs" : {  
"properties" : {  
"@timestamp" : {  
"type" : "date",  
"format" : "strict\_date\_optional\_time||epoch\_millis"  
},  
"@version" : {  
"type" : "string"  
},  
"as\_dst" : {  
"type" : "long"  
},  
"as\_src" : {  
"type" : "long"  
},  
"bytes" : {  
"type" : "long"  
},  
"country\_ip\_dst" : {  
"type" : "string"  
},  
"country\_ip\_src" : {  
"type" : "string"  
},  
"iface\_in" : {  
"type" : "long"  
},  
"iface\_out" : {  
"type" : "long"  
},  
"ip\_dst" : {  
"type" : "string"  
},  
"ip\_proto" : {  
"type" : "string"  
},  
"ip\_src" : {  
"type" : "string"  
},  
"label" : {  
"type" : "string"  
},  
"mask\_dst" : {  
"type" : "long"  
},  
"mask\_src" : {  
"type" : "long"  
},  
"packets" : {  
"type" : "long"  
},  
"peer\_ip\_src" : {  
"type" : "string"  
},  
"port\_dst" : {  
"type" : "long"  
},  
"port\_src" : {  
"type" : "long"  
},  
"stamp\_inserted" : {  
"type" : "string"  
},  
"stamp\_updated" : {  
"type" : "string"  
},  
"tag" : {  
"type" : "long"  
}  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![jpountz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpountz/32/45836_2.png) [@jpountz](https://discuss.elastic.co/u/jpountz)\
**Post date:** [July 18, 2016, 9:01am UTC](https://discuss.elastic.co/t/mixing-up-field-types-error-ip-field-is-not-getting-added/55332/8 "2016-07-18T09:01:16Z")

</div>

The template is not applied because it looks for index names that start with `netflow_` (`"template" : "netflow_*"`) while this index name is `logs_2016_07_13`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:34pm UTC](https://discuss.elastic.co/t/mixing-up-field-types-error-ip-field-is-not-getting-added/55332/9 "2017-07-05T22:34:48Z")

</div>


