# Problem with writing to created index

**URL:** <https://discuss.elastic.co/t/problem-with-writing-to-created-index/115092>\
**Category:** Logstash\
**Created:** [January 11, 2018, 1:12pm UTC](https://discuss.elastic.co/t/problem-with-writing-to-created-index/115092 "2018-01-11T13:12:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![antimion](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@antimion](https://discuss.elastic.co/u/antimion)\
**Post date:** [January 11, 2018, 1:12pm UTC](https://discuss.elastic.co/t/problem-with-writing-to-created-index/115092/1 "2018-01-11T13:12:54Z")

</div>

Hello i have used lates ES with latest logstash, and i have this kind of problem.  
When i try to write my logs to ES i receive this error. i have old ES5, and don't have any problem with configuration files. This is fully new ES cluster.

`Jan 11 13:08:00 ny-mon4.picsart.loc logstash[23140]: [2018-01-11T13:08:00,746][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"nginx_error-2018.01", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x5b778c7c>], :response=>{"index"=>{"_index"=>"nginx_error-2018.01", "_type"=>"doc", "_id"=>"JIZV5WABwf1E9dYkmdHQ", "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"mapper [timestamp] of different type, current_type [date], merged_type [text]"}}}}`

This is template which i used on cluster  
PUT /\_template/template\_1  
{  
"index\_patterns" : ["\*"],  
"order" : 0,  
"settings" : {  
"index.refresh\_interval" : "30s",  
"number\_of\_shards" : "10",  
"number\_of\_replicas" : "0",  
"index.store.type": "mmapfs"  
}  
}

---

<div class="post-metadata">

**Author:** ![murlin99](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@murlin99](https://discuss.elastic.co/u/murlin99)\
**Post date:** [January 11, 2018, 6:39pm UTC](https://discuss.elastic.co/t/problem-with-writing-to-created-index/115092/2 "2018-01-11T18:39:45Z")

</div>

This looks like a symptom of reindexing data from the previous cluster into the new cluster and hitting some breaking changes.

This document should help with mapping in the current version.  
[https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html)

Is this the whole template?

Do you have a custom logstash filter for this data?

What version of Elasticsearch is the new cluster running?

Did you re index any templates or data into the new cluster?

---

<div class="post-metadata">

**Author:** ![antimion](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@antimion](https://discuss.elastic.co/u/antimion)\
**Post date:** [January 12, 2018, 7:29am UTC](https://discuss.elastic.co/t/problem-with-writing-to-created-index/115092/3 "2018-01-12T07:29:51Z")

</div>

Hi, yes, that is whole template, i use ES 6.1.1 and i don't have any specific filter for logstash. I will try reinstall cluster maybe something goes wrong during installation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2018, 7:29am UTC](https://discuss.elastic.co/t/problem-with-writing-to-created-index/115092/4 "2018-02-09T07:29:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
