# Rejecting mapping update to as the final mapping would have more than 1 type: \[log, doc\]

**URL:** <https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866>\
**Category:** Logstash\
**Created:** [December 14, 2017, 10:07pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866 "2017-12-14T22:07:49Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 14, 2017, 10:07pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/1 "2017-12-14T22:07:49Z")

</div>

I'm trying to use logstash 6.0.1 and I'm getting the following error from filebeats 6.0.1. I understand the error but not sure how to correct this issue.

Rejecting mapping update to [filebeat-6.0.1-postgres-2017.11.29] as the final mapping would have more than 1 type: [log, doc]

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 14, 2017, 11:00pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/2 "2017-12-14T23:00:39Z")

</div>

I am not specifying the document\_type anywhere.

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 15, 2017, 3:25pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/3 "2017-12-15T15:25:02Z")

</div>

Here are my settings .... what am i missing?

cat logstash.yml | grep -v "#"  
[node.name](http://node.name): p-gp2-es46-4.\*\*\*\*\*  
path.data: /data/logstash  
http.host: "p-gp2-es46-4.**_"  
path.logs: /var/log/logstash  
xpack.monitoring.enabled: true  
xpack.monitoring.elasticsearch.url: [http://p-gp2-es46-8](http://p-gp2-es46-8)._**:9200  
xpack.monitoring.elasticsearch.username: logstash\_system  
xpack.monitoring.elasticsearch.password: \*\*\*\*\*

cat pipelines.yml

- [pipeline.id](http://pipeline.id): beats\_pipeline  
path.config: "/etc/logstash/pipelines/syslog\_pipeline.conf"

cat pipelines/syslog\_pipeline.conf  
input {  
beats {  
client\_inactivity\_timeout =\> 120  
port =\> 5044  
}  
}

filter {  
}

output {  
if "sys\_log" in [tags] {  
if "\_grokparsefailure" in [tags] {  
file {  
path =\> "/var/log/logstash/\_grokparsefailure/grokparsefailure\_sys\_log.log"  
}  
}

```
elasticsearch {
  hosts => "d-gp2-es46-8. ***** :9200"
  manage_template => false
  index => "%{[@metadata][beat]}-%{[@metadata][version]}-sys-log-%{+YYYY.MM.dd}"
}

```

}  
}

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 15, 2017, 9:48pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/4 "2017-12-15T21:48:46Z")

</div>

I took logstash out and have filebeat connecting directly to elasticsearch and still receive the same error. Not sure where the problem lies .... either elasticsearch or filebeats.

2017-12-15T21:34:10Z WARN Can not index event (status=400): {"type":"illegal\_argument\_exception","reason":"Rejecting mapping update to [filebeat-6.0.1-2017.12.15] as the final mapping would have more than 1 type: [log, doc]"}

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 15, 2017, 9:58pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/5 "2017-12-15T21:58:05Z")

</div>

Also filebeats is passing doc for \_type so it must be elasticsearch that is some how inserting log in for \_type. Any ideas where?

[2017-12-15T21:53:31,894][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"filebeat-6.0.1-postgres-2017.11.29", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x1e6ed340], :response=\>{"index"=\>{"\_index"=\>"filebeat-6.0.1-postgres-2017.11.29", **"\_type"=\>"doc"** , "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Rejecting mapping update to [filebeat-6.0.1-postgres-2017.11.29] as the final mapping would have more than 1 type: [log, doc]"}}}}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 16, 2017, 4:19am UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/6 "2017-12-16T04:19:30Z")

</div>

Check if you have any old index template that might be specifying a different type and therefore causing a conflict.

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 17, 2017, 3:25pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/7 "2017-12-17T15:25:28Z")

</div>

I'm not seeing anything. Also this is a fresh install of 6.0.1 so there shouldn't be anything.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 17, 2017, 5:04pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/8 "2017-12-17T17:04:12Z")

</div>

Do you have an old version of Filebeat somewhere?

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 18, 2017, 3:45pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/9 "2017-12-18T15:45:35Z")

</div>

No, I installed 6.0.1 and only have 1 filebeat setup right now to hit ES 6.0.1.

[root@d-gp2-dbp7-1:~]# /usr/share/filebeat/bin/filebeat --version  
filebeat version 6.0.1 (amd64), libbeat 6.0.1

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 19, 2017, 3:31pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/10 "2017-12-19T15:31:05Z")

</div>

I went an installed a new server with a new filebeats install of 6.0.1 and it started to work. Not sure what the difference was but it is working now. So the issues seams to have been with the upgraded filebeats from 5.6.1 to 6.0.1.

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 20, 2017, 6:10pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/11 "2017-12-20T18:10:06Z")

</div>

created a backup file of the filebeat.yml ... tried to make some changes and failed again and then put back the filebeat.yml that did work and failing again. Not sure what is causing this.

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 20, 2017, 6:44pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/12 "2017-12-20T18:44:43Z")

</div>

What would cause it to work one day and the next no?

2017-12-20T18:43:55Z WARN Can not index event (status=400): {"type":"illegal\_argument\_exception","reason":"Rejecting mapping update to [filebeat-6.0.1-2017.12.20] as the final mapping would have more than 1 type: [log, doc]"}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 20, 2017, 6:58pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/13 "2017-12-20T18:58:10Z")

</div>

You should probably read [https://www.elastic.co/guide/en/elasticsearch/reference/master/removal-of-types.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/removal-of-types.html)

The document type used by beats in v6 is doc, I think at some point in v5 it was log (definitely for logstash). So if a v6 beat sends a document into your index the type for your index is set to doc, and anything trying to index a document of type log will get that error.

If the first document in the index is of type log then anything trying to index a document of type doc will get that error. So it sounds like you have two different things indexing documents (logstash and beats perhaps) which are using different types.

If one of the logs infrequently then the problem would go away each day as a new index is created. Then whoever indexes the first document of the day locks the type of the index.

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 20, 2017, 7:51pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/14 "2017-12-20T19:51:48Z")

</div>

I understand the error but just not sure where the "log" document\_type could be set. I'm able to go straight from filebeat to elasticsearch now. When going from filebeat -\> logstash -\> elasticsearch .... it still gives that error.

[2017-12-20T19:50:13,923][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"filebeat-6.0.1-postgres-2017.11.29", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x2ea6bbce], :response=\>{"index"=\>{"\_index"=\>"filebeat-6.0.1-postgres-2017.11.29", "\_type"=\>"doc", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Rejecting mapping update to [filebeat-6.0.1-postgres-2017.11.29] as the final mapping would have more than 1 type: [log, doc]"}}}}

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [December 20, 2017, 8:02pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/15 "2017-12-20T20:02:14Z")

</div>

Figured it out ... ended up being a few things ... i did have an index template that was referencing "log". Also logstash was off by one letter pointing to the wrong elasticsearch. Seems to be working now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2018, 8:02pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update-to-as-the-final-mapping-would-have-more-than-1-type-log-doc/111866/16 "2018-01-17T20:02:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
