# Python -\> ElasticSearch Data Stream.. i'm doing something wrong.. suggestions

**URL:** <https://discuss.elastic.co/t/python-elasticsearch-data-stream-im-doing-something-wrong-suggestions/330874>\
**Category:** Elasticsearch\
**Tags:** language-clients\
**Created:** [April 26, 2023, 6:34pm UTC](https://discuss.elastic.co/t/python-elasticsearch-data-stream-im-doing-something-wrong-suggestions/330874 "2023-04-26T18:34:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [April 26, 2023, 6:34pm UTC](https://discuss.elastic.co/t/python-elasticsearch-data-stream-im-doing-something-wrong-suggestions/330874/1 "2023-04-26T18:34:14Z")

</div>

i'm trying to write a pretty basic python script to bulk insert some ip blacklists into an elasticsearch data stream.

this is my code, its basic for now:

```auto
    def bulkESSubmit(self):
        try:
            count=1
            es = Elasticsearch(['http://<HOST>:9200'], http_auth=('<user>', '<password>'), timeout=100, max_retries=2, retry_on_timeout=True)
            actions = []
            indexName="firehol-bad-ips"

            for item in tqdm(self.BadIP_Dict):
                commonTags=self.buildCommonTags(self.BadIP_Dict[item])
                commonTags=list(set(commonTags))
                tempDict = {
                    '_index': indexName,
                    '_op_type': "create",
                    '_source': {
                        '@timestamp': datetime.now().replace(microsecond=0).isoformat(),
                        'createdAt': datetime.now().replace(microsecond=0).isoformat(),
                        'ipaddress': item,
                        'sources': list(set(self.BadIP_Dict[item])),
                        'tags' : list(set(commonTags)),
                    },
                }
                actions.append(tempDict)
                tempDict.clear()
                count += 1
            helpers.bulk(es, actions)

```

i've got the ILM set up, i've got the index template set up.. when i try to insert i get this error:  
"'reason': 'only write ops with an op\_type of create are allowed in data streams'"

i've looked for examples online.. i've found a few:

> [@Dec 17th, 2021: \[EN\] Getting Started with the Elasticsearch Python Client](https://discuss.elastic.co/t/dec-17th-2021-en-getting-started-with-the-elasticsearch-python-client/290535):
>
> Getting Started With The Elasticsearch Python Client An Introduction To Elasticsearch With Python Elastic provides its own client for most languages, including of course - Python! There are two official Elasticsearch clients for the Python language: [elasticsearch-dsl](https://elasticsearch-dsl.readthedocs.io/en/latest/): A very user-friendly Python client. It is written in Python, and is built on top of the Elasticsearch-py client, in order to abstract some of the lower-level functionality. [elasticsearch-py](https://elasticsearch-py.readthedocs.io/en/master/): This is a lower-level Elasticsea…

but nothing seems to work.. what am i missing?  
any suggestions would be greatly appreciated

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 27, 2023, 1:44am UTC](https://discuss.elastic.co/t/python-elasticsearch-data-stream-im-doing-something-wrong-suggestions/330874/2 "2023-04-27T01:44:42Z")

</div>

Do you get an error if you don't declare the `_op_type` (and let it default to `index`)?

---

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [April 27, 2023, 3:12am UTC](https://discuss.elastic.co/t/python-elasticsearch-data-stream-im-doing-something-wrong-suggestions/330874/3 "2023-04-27T03:12:32Z")

</div>

that doesnt work either.. I tried that too.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2023, 3:13am UTC](https://discuss.elastic.co/t/python-elasticsearch-data-stream-im-doing-something-wrong-suggestions/330874/4 "2023-05-25T03:13:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
