# Need to change schema/metadata for existing index with lots of data

**URL:** <https://discuss.elastic.co/t/need-to-change-schema-metadata-for-existing-index-with-lots-of-data/12772>\
**Category:** Elasticsearch\
**Created:** [July 12, 2013, 3:27pm UTC](https://discuss.elastic.co/t/need-to-change-schema-metadata-for-existing-index-with-lots-of-data/12772 "2013-07-12T15:27:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Isaac\_Freeman](https://avatars.discourse-cdn.com/v4/letter/i/b487fb/32.png) [@Isaac\_Freeman](https://discuss.elastic.co/u/Isaac_Freeman)\
**Post date:** [July 12, 2013, 3:27pm UTC](https://discuss.elastic.co/t/need-to-change-schema-metadata-for-existing-index-with-lots-of-data/12772/1 "2013-07-12T15:27:11Z")

</div>

(x-posting from the graylog2 group since I think this is really more of an  
ES question...)

I have a Graylog2 0.10 instance running on Debian Squeeze (haven't upgraded  
to Wheezy yet) with Elasticsearch 0.20.4. For some reason one of my  
graylog2 indexes doesn't have the right datatype, index\_options or  
omit\_norms set for the index. Specifically, I'm interested in the  
histogram\_time field which I use to generate audit reports to prove that  
we're collecting logs for the past 90 days.

For example:

(I know the formatting isn't valid JSON, I just copied this out of the  
'head' plugin, which doesn't preserve commas for some reason...)

{

```
state: open
settings: {
    index.number_of_replicas: 0
    index.version.created: 200499
    index.number_of_shards: 4
}
mappings: {
    message: {
        properties: {
            _mode: {
                type: string
            }
            _xdelay: {
                type: string
            }
            ...
           * histogram_time: {
                type: string
            }*

```

...

vs

{

```
state: open
settings: {
    index.version.created: 200499
    index.number_of_replicas: 0
    index.number_of_shards: 4
}
mappings: {
    message: {
        _source: {
            compress: true
        }
        dynamic_templates: [
            {
                store_generic: {
                    mapping: {
                        index: not_analyzed
                    }
                    match: *
                }
            }
        ]
        _ttl: {
            enabled: true
        }
        properties: {
            _last_pfn: {
                index: not_analyzed
                omit_norms: true
                index_options: docs
                type: string
            }
            _xdelay: {
                index: not_analyzed
                omit_norms: true
                index_options: docs
                type: string
            }
           * histogram_time: {
                format: yyyy-MM-dd HH-mm-ss
                type: date
            }

```

...\*

The latter is what it should be, and that's what it is in every other  
index, but this one index just has "type: string"

I've tried a few methods of reindexing this data. I've created a new index  
called graylog2\_7\_re by copying the metadata from another index  
(graylog2\_6) and in the head plugin I can see that it has the correct  
metadata, but when I run the reindexing scripts, for some reason the  
metadata for the new index is changed to the wrong schema from the old  
broken index. I can't find a way to have it actually reindex with the  
correct metadata.

I've tried these two scripts:

> **[geronime/es-reindex](https://github.com/geronime/es-reindex)**
>
> es-reindex - Ruby script to copy ElasticSearch index (reindex).

  

> **[karussell/elasticsearch-reindex](https://github.com/karussell/elasticsearch-reindex)**
>
> elasticsearch-reindex - Simple re-indexing. To backup, apply index settings changes and more ElasticMagic

And both have the same result of overriding the metadata that I set when  
creating the new index.

Any ideas, advice or pointers would be greatly appreciated.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:26am UTC](https://discuss.elastic.co/t/need-to-change-schema-metadata-for-existing-index-with-lots-of-data/12772/2 "2017-07-06T02:26:44Z")

</div>


