# Recover from mapping explosion

**URL:** <https://discuss.elastic.co/t/recover-from-mapping-explosion/90425>\
**Category:** Kibana\
**Created:** [June 22, 2017, 10:01am UTC](https://discuss.elastic.co/t/recover-from-mapping-explosion/90425 "2017-06-22T10:01:49Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ziv\_Farjun](https://avatars.discourse-cdn.com/v4/letter/z/e480ec/32.png) [@Ziv\_Farjun](https://discuss.elastic.co/u/Ziv_Farjun)\
**Post date:** [June 22, 2017, 10:01am UTC](https://discuss.elastic.co/t/recover-from-mapping-explosion/90425/1 "2017-06-22T10:01:49Z")

</div>

In my system (Kibana 5.1.1) I have 1 event that creating mapping explosion by creating a field that looks something like `foo<hashCode>` and we had lots of `fooXXXX`, soon after we reach `index.mapping.total_fields.limit`.  
I change the event to stop doing that by changing it to an array so it would look like `foo [hashcode1, hashcode1...]`. but now my system is clutter with those junk `foo<hashcode>`.

Trying to recover I run from dev tool UI `_delete_by_query` with a query that matches the problematic event.  
The response looks valid (see below) but the number of fields didn't decrease - why is that? and how can I delete and reset the fields count

```
{
  "took": 211,
  "timed_out": false,
  "total": 117,
  "deleted": 117,
  "batches": 1,
  "version_conflicts": 0,
  "noops": 0,
  "retries": {
    "bulk": 0,
    "search": 0
  },
  "throttled_millis": 0,
  "requests_per_second": -1,
  "throttled_until_millis": 0,
  "failures": []
}

```

I check the number of fields from UI -\> Management and also indexing new events give `Limit of total fields` error

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 22, 2017, 10:30am UTC](https://discuss.elastic.co/t/recover-from-mapping-explosion/90425/2 "2017-06-22T10:30:25Z")

</div>

You will need to put things into a new index, it won't change the existing one.

---

<div class="post-metadata">

**Author:** ![Ziv\_Farjun](https://avatars.discourse-cdn.com/v4/letter/z/e480ec/32.png) [@Ziv\_Farjun](https://discuss.elastic.co/u/Ziv_Farjun)\
**Post date:** [June 22, 2017, 11:08am UTC](https://discuss.elastic.co/t/recover-from-mapping-explosion/90425/3 "2017-06-22T11:08:15Z")

</div>

Thanks for your replay  
since this is still in dev I can do that but I rather check if there is other non-distractive mitigation or work around.

For example: dropping the index and then re-play all events (after removing the problematic event) or use the Source Filters while replay

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 22, 2017, 11:09am UTC](https://discuss.elastic.co/t/recover-from-mapping-explosion/90425/4 "2017-06-22T11:09:01Z")

</div>

> [@Ziv\_Farjun](#):
>
> For example: dropping the index and then re-play all events (after removing the problematic event)

That's pretty much the same thing as I suggested 😉  
It would be the best option.

---

<div class="post-metadata">

**Author:** ![Ziv\_Farjun](https://avatars.discourse-cdn.com/v4/letter/z/e480ec/32.png) [@Ziv\_Farjun](https://discuss.elastic.co/u/Ziv_Farjun)\
**Post date:** [June 22, 2017, 11:10am UTC](https://discuss.elastic.co/t/recover-from-mapping-explosion/90425/5 "2017-06-22T11:10:47Z")

</div>

Thanks again for the fast response.

Since I'm new to Kibana, creating new index will replay all events ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 22, 2017, 11:31pm UTC](https://discuss.elastic.co/t/recover-from-mapping-explosion/90425/6 "2017-06-22T23:31:40Z")

</div>

No you need to do that yourself.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2017, 11:31pm UTC](https://discuss.elastic.co/t/recover-from-mapping-explosion/90425/7 "2017-07-20T23:31:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
