# Rejecting mapping update

**URL:** <https://discuss.elastic.co/t/rejecting-mapping-update/150556>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 1, 2018, 11:02am UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556 "2018-10-01T11:02:55Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![rohan89](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan89/32/36044_2.png) [@rohan89](https://discuss.elastic.co/u/rohan89)\
**Post date:** [October 1, 2018, 11:02am UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/1 "2018-10-01T11:02:55Z")

</div>

Hi,

I have upgraded my elasticsearch to 6.3.2. After an upgrade i am trying to reindex my data. But i am getting below error.

> ```
> "cause": {
> "type": "illegal_argument_exception",
> "reason": "Rejecting mapping update to [logstash-YYYY.DD.MM-reindexed] as the final mapping would have more than 1 type: [kube-logs, logs]"
> },
> 
> ```

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 1, 2018, 11:13am UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/2 "2018-10-01T11:13:01Z")

</div>

What is your Filebeat version?

---

<div class="post-metadata">

**Author:** ![rohan89](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan89/32/36044_2.png) [@rohan89](https://discuss.elastic.co/u/rohan89)\
**Post date:** [October 1, 2018, 11:13am UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/3 "2018-10-01T11:13:22Z")

</div>

Below is my Filebeat Configuration

> filebeat.config.inputs:  
> enabled: true  
> path: "/etc/filebeat-additional/"  
> filebeat.inputs:
> 
> - type: log  
> paths: "/var/log/containers/\*.log"  
> tags: ["kube-logs","syslog"]  
> symlinks: true  
> json.message\_key: log  
> json.keys\_under\_root: true  
> json.add\_error\_key: true  
> multiline.pattern: '^\s'  
> multiline.match: after  
> output.logstash:  
> hosts: ["${LOGSTASH\_HOSTS:'logstash:5043'}"]  
> timeout: 15  
> logging:  
> level: ${LOG\_LEVEL:warning}  
> processors:
> - drop\_fields:  
> fields: ["host"]

---

<div class="post-metadata">

**Author:** ![rohan89](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan89/32/36044_2.png) [@rohan89](https://discuss.elastic.co/u/rohan89)\
**Post date:** [October 1, 2018, 11:13am UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/4 "2018-10-01T11:13:42Z")

</div>

My filebeat version is 6.3.2

---

<div class="post-metadata">

**Author:** ![rohan89](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan89/32/36044_2.png) [@rohan89](https://discuss.elastic.co/u/rohan89)\
**Post date:** [October 1, 2018, 11:18am UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/5 "2018-10-01T11:18:47Z")

</div>

I am using below command for reindexing

> POST /\_reindex  
> {
> 
> "source": {
> 
> ```
> "index": "logstash-YYYY.MM.DD"
> 
> ```
> 
> },
> 
> "dest": {
> 
> ```
> "index": "logstash-YYYY.MM.DD-reindexed"
> 
> ```
> 
> }
> 
> }

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 1, 2018, 11:24am UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/6 "2018-10-01T11:24:34Z")

</div>

What were the versions of Elasticsearch and Filebeat before you updated?

---

<div class="post-metadata">

**Author:** ![rohan89](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan89/32/36044_2.png) [@rohan89](https://discuss.elastic.co/u/rohan89)\
**Post date:** [October 1, 2018, 11:55am UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/7 "2018-10-01T11:55:03Z")

</div>

Before updating the version were 5.2.2

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [October 1, 2018, 3:48pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/8 "2018-10-01T15:48:55Z")

</div>

You have two types: kube-logs and logs. You need to create separate indices for each type.

---

<div class="post-metadata">

**Author:** ![rohan89](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan89/32/36044_2.png) [@rohan89](https://discuss.elastic.co/u/rohan89)\
**Post date:** [October 1, 2018, 5:35pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/9 "2018-10-01T17:35:13Z")

</div>

Hi @kvch

My filebeat version is sending only one type. After upgrade I have restored the indexes. please could let me how to separate two indices?

Regards

---

<div class="post-metadata">

**Author:** ![rohan89](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan89/32/36044_2.png) [@rohan89](https://discuss.elastic.co/u/rohan89)\
**Post date:** [October 2, 2018, 4:07pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/10 "2018-10-02T16:07:49Z")

</div>

Can anyone help me on the same for reindexing

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [October 2, 2018, 4:43pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/11 "2018-10-02T16:43:16Z")

</div>

So right now you have a 5.x index that contains two different types, and you want to reindex every type into a different new index.

I understand that the way of achieving this is to use the `type` filtering in the reindex API as explained here: [Reindex API | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-reindex.html)

Something like:

```auto
POST _reindex
{
  "source": {
    "index": "logstash-YYYY.MM.DD",
    "type": "logs",
  },
  "dest": {
    "index": "logstash-YYYY.MM.DD-logs-reindexed"
  }
}

```

and

```auto
POST _reindex
{
  "source": {
    "index": "logstash-YYYY.MM.DD",
    "type": "kube-logs",
  },
  "dest": {
    "index": "logstash-YYYY.MM.DD-kube-logs-reindexed"
  }
}

```

You can also map all your documents to the same index, by removing the type information, as explained here:

> [@Dec 15th, 2017: \[EN\]\[Elasticsearch\] Going from multiple types to one type with the Reindex API](https://discuss.elastic.co/t/dec-15th-2017-en-elasticsearch-going-from-multiple-types-to-one-type-with-the-reindex-api/111315):
>
> Every document in Elasticsearch has a type. It has long been the recommendation of Elastic to use only one document type per index, but with the release of version 6.0 this has become more than just advice. For new indices, Elasticsearch now only accepts one document type per index, as a first step to [the complete removal of document types in future versions of Elasticsearch](https://www.elastic.co/blog/removal-of-mapping-types-elasticsearch). The fact that Elasticsearch now only accepts a single type per index makes this a good time to think about how you would…

Otherwise, you will get more authoritative answers in #elasticsearch

---

<div class="post-metadata">

**Author:** ![siddaram\_kj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/siddaram_kj/32/46048_2.png) [@siddaram\_kj](https://discuss.elastic.co/u/siddaram_kj)\
**Post date:** [October 5, 2018, 10:10am UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/12 "2018-10-05T10:10:05Z")

</div>

From elastic search 6 in each index we can have only one type.so create two index in new index.

---

<div class="post-metadata">

**Author:** ![rohan89](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan89/32/36044_2.png) [@rohan89](https://discuss.elastic.co/u/rohan89)\
**Post date:** [October 5, 2018, 5:15pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/13 "2018-10-05T17:15:12Z")

</div>

I guess the below link has helped me a ton.

> [@adrisr](#):
>
> You can also map all your documents to the same index, by removing the type information, as explained here:

I tried creating the index with different type as it was mapped in my index. But was ending up in confusions.  
But below reindex api helped me to have single t type.

POST \_reindex  
{  
"source": {  
"index": "old"  
},  
"dest": {  
"index": "new"  
},  
"script": {  
"source": """  
ctx.\_source.type = ctx.\_type;  
ctx.\_type = 'doc';  
""",  
"lang": "painless"  
}  
}

Thanks a ton again

---

<div class="post-metadata">

**Author:** ![rohan89](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rohan89/32/36044_2.png) [@rohan89](https://discuss.elastic.co/u/rohan89)\
**Post date:** [October 5, 2018, 5:17pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/14 "2018-10-05T17:17:42Z")

</div>

True. But data of same date with multiple created confusion.

> [@siddaram\_kj](#):
>
> From Elasticsearch 6 in each index we can have only one type.so create two index in new index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 2, 2018, 5:18pm UTC](https://discuss.elastic.co/t/rejecting-mapping-update/150556/15 "2018-11-02T17:18:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
