# Need help - Cisco syslog events matching in GROK debugger but not showing up in

**URL:** https://discuss.elastic.co/t/need-help-cisco-syslog-events-matching-in-grok-debugger-but-not-showing-up-in/280116
**Category:** Logstash
**Created:** [July 31, 2021, 7:42am UTC](https://discuss.elastic.co/t/need-help-cisco-syslog-events-matching-in-grok-debugger-but-not-showing-up-in/280116 "2021-07-31T07:42:36Z")
**Posts on this page:** 1
**Showing post:** 6

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [August 1, 2021, 6:13pm UTC](https://discuss.elastic.co/t/need-help-cisco-syslog-events-matching-in-grok-debugger-but-not-showing-up-in/280116/6 "2021-08-01T18:13:30Z")

</div>

> [@Cdnvballer](#):
>
> `document_type => "%{[@metadata][type]}"`

Why are you setting document\_type? That option is deprecated and will be removed, I would guess in 8.0. If this is not the same on every document then documents will get rejected.

I would expect you to be getting the warning and exceptions [posted here](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-doc-syslog/238326).

---

_[View the full topic](https://discuss.elastic.co/t/need-help-cisco-syslog-events-matching-in-grok-debugger-but-not-showing-up-in/280116)._
