# No mapping found for \[@timestamp\]

**URL:** <https://discuss.elastic.co/t/no-mapping-found-for-timestamp/141586>\
**Category:** Logstash\
**Created:** [July 25, 2018, 1:33pm UTC](https://discuss.elastic.co/t/no-mapping-found-for-timestamp/141586 "2018-07-25T13:33:20Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![gur79](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gur79/32/42896_2.png) [@gur79](https://discuss.elastic.co/u/gur79)\
**Post date:** [July 25, 2018, 1:33pm UTC](https://discuss.elastic.co/t/no-mapping-found-for-timestamp/141586/1 "2018-07-25T13:33:20Z")

</div>

I'm real sorry if I'm asking newbie question, i have been introduced to ELK sack last 2 weeks

here's my story, i have this internal network of 10 different servers and I'm collecting logs from all of them (using filebeat system module).  
i have this one server which is running logstash to collect all logs and elasticsearch plus kibana  
i decide to use X-pack for logging users in and having different users

here's how i'm debuggig it.

on logstash, the pipeline i'm using is the default one taken from official website for parsing filebeat system module

this one:  
[https://www.elastic.co/guide/en/logstash/6.3/logstash-config-for-filebeat-modules.html#parsing-system](https://www.elastic.co/guide/en/logstash/6.3/logstash-config-for-filebeat-modules.html#parsing-system)

then when i run logstash with  
**_bin/logstash -f pipeline.conf --path.settings /etc/logstash/_**  
i'm getting that [logstash.filters.elasticsearch] Failed to query elasticsearch for previous event.

here's the whole message:

[2018-07-25T14:14:45,948][WARN][logstash.filters.elasticsearch] Failed to query elasticsearch for previous event {:index=\>"", :query=\>"", :event=\>#LogStash::Event:0x4bbccba9, :error=\>#\<RuntimeError: Elasticsearch query error: [{"shard"=\>0, "index"=\>".kibana", "node"=\>"yw1ItHevQDON-5vGOsQj9Q", "reason"=\>{"type"=\>"query\_shard\_exception", "reason"=\>"No mapping found for [@timestamp] in order to sort on", "index\_uuid"=\>"5olmNGoaQJyvs6LP8L9ZUA", "index"=\>".kibana"}}, {"shard"=\>0, "index"=\>".ml-anomalies-shared", "node"=\>"yw1ItHevQDON-5vGOsQj9Q", "reason"=\>{"type"=\>"query\_shard\_exception", "reason"=\>"No mapping found for [@timestamp] in order to sort on", "index\_uuid"=\>"as9JnEjTTpqH5xCgOz8xTQ", "index"=\>".ml-anomalies-shared"}}, {"shard"=\>0, "index"=\>".ml-notifications", "node"=\>"yw1ItHevQDON-5vGOsQj9Q", "reason"=\>{"type"=\>"query\_shard\_exception", "reason"=\>"No mapping found for [@timestamp] in order to sort on", "index\_uuid"=\>"nE6\_0GetS9aV3xEScT9DUg", "index"=\>".ml-notifications"}}, {"shard"=\>0, "index"=\>".monitoring-alerts-6", "node"=\>"yw1ItHevQDON-5vGOsQj9Q", "reason"=\>{"type"=\>"query\_shard\_exception", "reason"=\>"No mapping found for [@timestamp] in order to sort on", "index\_uuid"=\>"KseNNb\_sTYSPn977ec\_5iA", "index"=\>".monitoring-alerts-6"}}, {"shard"=\>0, "index"=\>".monitoring-es-6-2018.07.25", "node"=\>"yw1ItHevQDON-5vGOsQj9Q", "reason"=\>{"type"=\>"query\_shard\_exception", "reason"=\>"No mapping found for [@timestamp] in order to sort on", "index\_uuid"=\>"CGDU9lywShq01Eo3irsE0g", "index"=\>".monitoring-es-6-2018.07.25"}}, {"shard"=\>0, "index"=\>".monitoring-kibana-6-2018.07.25", "node"=\>"yw1ItHevQDON-5vGOsQj9Q", "reason"=\>{"type"=\>"query\_shard\_exception", "reason"=\>"No mapping found for [@timestamp] in order to sort on", "index\_uuid"=\>"\_pAhA2y7T-OpmoOOAzSJ0Q", "index"=\>".monitoring-kibana-6-2018.07.25"}}, {"shard"=\>0, "index"=\>".security-6", "node"=\>"yw1ItHevQDON-5vGOsQj9Q", "reason"=\>{"type"=\>"query\_shard\_exception", "reason"=\>"No mapping found for [@timestamp] in order to sort on", "index\_uuid"=\>"3hysFJAUT\_KAcZrXnsx4dw", "index"=\>".security-6"}}, {"shard"=\>0, "index"=\>".triggered\_watches", "node"=\>"yw1ItHevQDON-5vGOsQj9Q", "reason"=\>{"type"=\>"query\_shard\_exception", "reason"=\>"No mapping found for [@timestamp] in order to sort on", "index\_uuid"=\>"Fiy\_fakLSmasnMWpcxsiKA", "index"=\>".triggered\_watches"}}, {"shard"=\>0, "index"=\>".watcher-history-7-2018.07.25", "node"=\>"yw1ItHevQDON-5vGOsQj9Q", "reason"=\>{"type"=\>"query\_shard\_exception", "reason"=\>"No mapping found for [@timestamp] in order to sort on", "index\_uuid"=\>"Xgac\_ryLRS2c1obJ8Wm9dg", "index"=\>".watcher-history-7-2018.07.25"}}, {"shard"=\>0, "index"=\>".watches", "node"=\>"yw1ItHevQDON-5vGOsQj9Q", "reason"=\>{"type"=\>"query\_shard\_exception", "reason"=\>"No mapping found for [@timestamp] in order to sort on", "index\_uuid"=\>"gD3IB1S-TfOWqUFw8r27KA", "index"=\>".watches"}}, {"shard"=\>0, "index"=\>"filebeat-2018.07.24", "node"=\>"yw1ItHevQDON-5vGOsQj9Q", "reason"=\>{"type"=\>"query\_shard\_exception", "reason"=\>"No mapping found for [@timestamp] in order to sort on", "index\_uuid"=\>"DQqCKrU7TYW9JuckfZZntw", "index"=\>"filebeat-2018.07.24"}}]\>}

is there any way of correcting this "No Mapping found for @timestamp" on my indices (i have filebeat-\*,) and these system indices (.monitor, .watchers, .ml-anomalies, etc..)  
or am i doing it the wrong way??

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 28, 2018, 11:14am UTC](https://discuss.elastic.co/t/no-mapping-found-for-timestamp/141586/2 "2018-07-28T11:14:38Z")

</div>

What's in your pipeline.conf file?

---

<div class="post-metadata">

**Author:** ![gur79](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gur79/32/42896_2.png) [@gur79](https://discuss.elastic.co/u/gur79)\
**Post date:** [July 28, 2018, 11:30am UTC](https://discuss.elastic.co/t/no-mapping-found-for-timestamp/141586/3 "2018-07-28T11:30:41Z")

</div>

this one, i took it from elastic official website.. it's used to parse filebeat system module

input {  
elasticsearch {  
user =\> logstash\_internal  
password =\> x-pack-test-password  
}  
beats {  
port =\> 5044  
host =\> "0.0.0.0"  
}  
}  
filter {  
elasticsearch {  
user =\> logstash\_internal  
password =\> x-pack-test-password  
}

if [fileset][module] == "system" {  
if [fileset][name] == "auth" {  
grok {  
match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:[%{POSINT:[system][auth][pid]}])?: %{DATA:[system][auth][ssh][event]} %{DATA:[system][auth][ssh][method]} for (invalid user )?%{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]} port %{NUMBER:[system][auth][ssh][port]} ssh2(: %{GREEDYDATA:[system][auth][ssh][signature]})?",  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:[%{POSINT:[system][auth][pid]}])?: %{DATA:[system][auth][ssh][event]} user %{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]}",  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:[%{POSINT:[system][auth][pid]}])?: Did not receive identification string from %{IPORHOST:[system][auth][ssh][dropped\_ip]}",  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sudo(?:[%{POSINT:[system][auth][pid]}])?: \s\*%{DATA:[system][auth][user]} ☹ %{DATA:[system][auth][sudo][error]} ;)? TTY=%{DATA:[system][auth][sudo][tty]} ; PWD=%{DATA:[system][auth][sudo][pwd]} ; USER=%{DATA:[system][auth][sudo][user]} ; COMMAND=%{GREEDYDATA:[system][auth][sudo][command]}",  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} groupadd(?:[%{POSINT:[system][auth][pid]}])?: new group: name=%{DATA:system.auth.groupadd.name}, GID=%{NUMBER:system.auth.groupadd.gid}",  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} useradd(?:[%{POSINT:[system][auth][pid]}])?: new user: name=%{DATA:[system][auth][user][add][name]}, UID=%{NUMBER:[system][auth][user][add][uid]}, GID=%{NUMBER:[system][auth][user][add][gid]}, home=%{DATA:[system][auth][user][add][home]}, shell=%{DATA:[system][auth][user][add][shell]}$",  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} %{DATA:[system][auth][program]}(?:[%{POSINT:[system][auth][pid]}])?: %{GREEDYMULTILINE:[system][auth][message]}"] }  
pattern\_definitions =\> {  
"GREEDYMULTILINE"=\> "(.|\n)_"  
}  
remove\_field =\> "message"  
}  
date {  
match =\> ["[system][auth][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]  
}  
geoip {  
source =\> "[system][auth][ssh][ip]"  
target =\> "[system][auth][ssh][geoip]"  
}  
}  
else if [fileset][name] == "syslog" {  
grok {  
match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][syslog][timestamp]} %{SYSLOGHOST:[system][syslog][hostname]} %{DATA:[system][syslog][program]}(?:[%{POSINT:[system][syslog][pid]}])?: %{GREEDYMULTILINE:[system][syslog][message]}"] }  
pattern\_definitions =\> { "GREEDYMULTILINE" =\> "(.|\n)_" }  
remove\_field =\> "message"  
}  
date {  
match =\> ["[system][syslog][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]  
}  
}  
}  
}  
output {  
elasticsearch {  
user =\> logstash\_internal  
password =\> x-pack-test-password  
hosts =\> localhost  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 28, 2018, 3:01pm UTC](https://discuss.elastic.co/t/no-mapping-found-for-timestamp/141586/4 "2018-07-28T15:01:33Z")

</div>

That's not the configuration you linked to earlier. Where does the elasticsearch **filter** come from? You've probably made a copy/paste mistake.

---

<div class="post-metadata">

**Author:** ![gur79](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gur79/32/42896_2.png) [@gur79](https://discuss.elastic.co/u/gur79)\
**Post date:** [July 28, 2018, 3:41pm UTC](https://discuss.elastic.co/t/no-mapping-found-for-timestamp/141586/5 "2018-07-28T15:41:27Z")

</div>

actually it's the same except that i added elasticsearch **username** and **password** part.

here's the real copy of my pipeline in /etc/logstash/conf.d/ directory

input {  
beats {  
port =\> 5044  
host =\> "0.0.0.0"  
}  
elasticsearch {  
user =\> username  
password =\> "pass"  
}  
}  
filter {  
elasticsearch {  
user =\> username  
password =\> "pass"  
}  
if [fileset][module] == "system" {  
if [fileset][name] == "auth" {  
grok {  
match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:[%{POSINT:[system][auth][pid]}])?: %{DATA:[system][auth][ssh][event]} %{DATA:[system][auth][ssh][method]} for (invalid user )?%{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]} port %{NUMBER:[system][auth][ssh][port]} ssh2(: %{GREEDYDATA:[system][auth][ssh][signature]})?",  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:[%{POSINT:[system][auth][pid]}])?: %{DATA:[system][auth][ssh][event]} user %{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]}",  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:[%{POSINT:[system][auth][pid]}])?: Did not receive identification string from %{IPORHOST:[system][auth][ssh][dropped\_ip]}",  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sudo(?:[%{POSINT:[system][auth][pid]}])?: \s\*%{DATA:[system][auth][user]} ☹ %{DATA:[system][auth][sudo][error]} ;)? TTY=%{DATA:[system][auth][sudo][tty]} ; PWD=%{DATA:[system][auth][sudo][pwd]} ; USER=%{DATA:[system][auth][sudo][user]} ; COMMAND=%{GREEDYDATA:[system][auth][sudo][command]}",  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} groupadd(?:[%{POSINT:[system][auth][pid]}])?: new group: name=%{DATA:system.auth.groupadd.name}, GID=%{NUMBER:system.auth.groupadd.gid}",  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} useradd(?:[%{POSINT:[system][auth][pid]}])?: new user: name=%{DATA:[system][auth][user][add][name]}, UID=%{NUMBER:[system][auth][user][add][uid]}, GID=%{NUMBER:[system][auth][user][add][gid]}, home=%{DATA:[system][auth][user][add][home]}, shell=%{DATA:[system][auth][user][add][shell]}$",  
"%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} %{DATA:[system][auth][program]}(?:[%{POSINT:[system][auth][pid]}])?: %{GREEDYMULTILINE:[system][auth][message]}"] }  
pattern\_definitions =\> {  
"GREEDYMULTILINE"=\> "(.|\n)_"  
}  
remove\_field =\> "message"  
}  
date {  
match =\> ["[system][auth][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]  
}  
geoip {  
source =\> "[system][auth][ssh][ip]"  
target =\> "[system][auth][ssh][geoip]"  
}  
}  
else if [fileset][name] == "syslog" {  
grok {  
match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][syslog][timestamp]} %{SYSLOGHOST:[system][syslog][hostname]} %{DATA:[system][syslog][program]}(?:[%{POSINT:[system][syslog][pid]}])?: %{GREEDYMULTILINE:[system][syslog][message]}"] }  
pattern\_definitions =\> { "GREEDYMULTILINE" =\> "(.|\n)_" }  
remove\_field =\> "message"  
}  
date {  
match =\> ["[system][syslog][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]  
}  
}  
}  
}  
output {  
elasticsearch {  
user =\> username  
password =\> "pass"  
hosts =\> localhost  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 28, 2018, 7:01pm UTC](https://discuss.elastic.co/t/no-mapping-found-for-timestamp/141586/6 "2018-07-28T19:01:45Z")

</div>

> actually it's the same except that i added elasticsearch username and password part.

No! The original doesn't have an elasticsearch **filter** , only an elasticsearch **output**. Compare what comes right after `filter {` in your file vs. in the example in the documentation. Over and out.

---

<div class="post-metadata">

**Author:** ![gur79](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gur79/32/42896_2.png) [@gur79](https://discuss.elastic.co/u/gur79)\
**Post date:** [July 30, 2018, 8:53am UTC](https://discuss.elastic.co/t/no-mapping-found-for-timestamp/141586/7 "2018-07-30T08:53:26Z")

</div>

i looked up everything, copied it again, now i'm getting this new error of **_"could not index event to elasticsearch"_**  
here it is:

[2018-07-30T09:28:23,795][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"filebeat-6.3.1-2018.07.30", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x175f7d4b], :response=\>{"index"=\>{"\_index"=\>"filebeat-6.3.1-2018.07.30", "\_type"=\>"doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"Failed to parse mapping [doc]: Mapping definition for [error] has unsupported parameters: [properties : {code={type=long}, message={norms=false, type=text}, type={ignore\_above=1024, type=keyword}}]", "caused\_by"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"Mapping definition for [error] has unsupported parameters: [properties : {code={type=long}, message={norms=false, type=text}, type={ignore\_above=1024, type=keyword}}]"}}}}}

and when i try to get mapping for filbeat-\* with **curl -X GET -u elastic "localhost:9200/filebeat-\*/\_mapping/\_doc"**

i'm getting this error of missing type..

{"error":{"root\_cause":[{"type":"type\_missing\_exception","reason":"type[[\_doc]] missing","index\_uuid":"_na_","index":"\_all"}],"type":"type\_missing\_exception","reason":"type[[\_doc]] missing","index\_uuid":"_na_","index":"\_all"},"status":404}

are there any reason this is happening, or any suggestion.  
thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 30, 2018, 8:26pm UTC](https://discuss.elastic.co/t/no-mapping-found-for-timestamp/141586/8 "2018-07-30T20:26:09Z")

</div>

The name of the type is "doc", not "\_doc".

---

<div class="post-metadata">

**Author:** ![gur79](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gur79/32/42896_2.png) [@gur79](https://discuss.elastic.co/u/gur79)\
**Post date:** [July 31, 2018, 8:12am UTC](https://discuss.elastic.co/t/no-mapping-found-for-timestamp/141586/9 "2018-07-31T08:12:39Z")

</div>

i finally got it 😅 the main reason was that last time i updated my filebeat, i didn't bother to delete the old templates, and load there new ones.

and this thread below help me.

> [@Filebeat v6 and elasticsearch v6](https://discuss.elastic.co/t/filebeat-v6-and-elasticsearch-v6/107925/6):
>
> Hi, Just had the same issue, you need to update the template for filebeat & es6. You have the new mapping file in /etc/filebeat/filebeat.template-es6.json I deleted the previous one and load the new one but there may be a better option if you need to keep your data. curl -XDELETE http://localhost:9200/\_template/filebeat curl -XPUT -H 'Content-Type: application/json' http://localhost:9200/\_template/filebeat -d@filebeat.template-es6x.json See [https://www.elastic.co/guide/en/beats/filebeat/cur…](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-template.html)

Thanks a lot for your time.. you've been helpful

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2018, 8:12am UTC](https://discuss.elastic.co/t/no-mapping-found-for-timestamp/141586/10 "2018-08-28T08:12:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
