# No handler for type \[string\] declared on field \[fieldname\]

**URL:** <https://discuss.elastic.co/t/no-handler-for-type-string-declared-on-field-fieldname/222693>\
**Category:** Elasticsearch\
**Created:** [March 9, 2020, 11:21am UTC](https://discuss.elastic.co/t/no-handler-for-type-string-declared-on-field-fieldname/222693 "2020-03-09T11:21:06Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chris\_Wilmott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chris_wilmott/32/47036_2.png) [@Chris\_Wilmott](https://discuss.elastic.co/u/Chris_Wilmott)\
**Post date:** [March 9, 2020, 11:21am UTC](https://discuss.elastic.co/t/no-handler-for-type-string-declared-on-field-fieldname/222693/1 "2020-03-09T11:21:06Z")

</div>

I know this question has been asked before but I can't seem to make this work.

I updated Kibana and ElasticSearch from 5.6.16 to 6.8.7, and after the upgrade everything continued to work. However, two days later at midnight all logging stopped and the following errors started to show up in the logs:

`[2020-03-09T10:35:09,326][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"logstash-prod-syslog-2020.11", :_type=>"syslog", :_routing=>nil}, LOGLINE, :response=>{"index"=>{"_index"=>"logstash-prod-syslog-2020.11", "_type"=>"syslog", "_id"=>nil, "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"Failed to parse mapping [_default_]: No handler for type [string] declared on field [@version]", "caused_by"=>{"type"=>"mapper_parsing_exception", "reason"=>"No handler for type [string] declared on field [@version]"}}}}}`

From looking over previous post I would assume the error is that the `@version` field was previously of type `sting` and now needs to be of type `text` or `keyword`. However, when looking at the templates (that have been in use since 5.6.16) the field is of type `keyword`:

```auto
 "@version": { "type": "keyword", "index": true },

```

In the templates I do have a few references to `string` such as this:

```auto
  "mappings" : {
    "_default_" : {
       "_all" : {"enabled" : false, "norms" : false},
       "dynamic_templates" : [ {
         "message_field" : {
           "match" : "message",
           "match_mapping_type" : "string",
           "mapping" : {
             "type" : "text", "index" : true, "norms" : false
           }
         }
       }, {
         "string_fields" : {
           "match" : "*",
           "match_mapping_type" : "string",
           "mapping" : {
             "type" : "text", "index" : true, "norms" : false,
               "fields" : {
                 "raw" : {"type": "keyword", "index" : true, "ignore_above" : 256}
               }

```

But ifI try and update these to `text` I get the following error:

```auto
"No field type matched on [text], possible values are [object, string, long, double, boolean, date, binary]"

```

I have also had a look at my index patterns (it is also worth noting that the index mention in the error message, `logstash-prod-syslog-2020.11`, is not present in Kibana) and I can see that `@version` is listed as a string:

`@version string`

The only other place I can see `@version` being listed as a sting is if I run the following GET in the elastic API:

```auto
/_template/logstash-prod

```

```auto
          "@version": {
            "index": "not_analyzed",
            "type": "string"

```

I have tried just doing a PUT and changing the type to `text` and I just get the error:

```auto
"reason": "unknown key [logstash-prod] in the template ",

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2020, 11:21am UTC](https://discuss.elastic.co/t/no-handler-for-type-string-declared-on-field-fieldname/222693/2 "2020-04-06T11:21:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
