# The final mapping would have more than 1 type

**URL:** <https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565>\
**Category:** Logstash\
**Created:** [March 5, 2018, 4:47pm UTC](https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565 "2018-03-05T16:47:11Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![jaas](https://avatars.discourse-cdn.com/v4/letter/j/a4c791/32.png) [@jaas](https://discuss.elastic.co/u/jaas)\
**Post date:** [March 5, 2018, 4:47pm UTC](https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565/1 "2018-03-05T16:47:11Z")

</div>

I write a template and want to load it manually, but failed.  
a message showed up :

```
{"error":
{"root_cause":[
{"type":"illegal_argument_exception","reason":"Rejecting mapping update to [OC22HHTNQxaFWq2g_XGKyA] as the final mapping would have more than 1 type: [t_df_dfxx, t_kd_grdfd]"}], 
"type":"illegal_argument_exception",
"reason":"Rejecting mapping update to [OC22HHTNQxaFWq2g_XGKyA] as the final mapping would have more than 1 type: [t_df_dfxx, t_kd_grdfd]"},"status":400}

 { 
"index_patterns": ["tes*"], 
"settings" : { 
"index" : { 
"number_of_shards" : 3, 
"number_of_replicas" : 2 
} 
}, 

"mappings" : { 
"t_df_dfxx" : { 
"properties" : { 
"ydaxj" : { "type" : "text" }, 
"nbddh" : { "type" : "text" }, 
"ajrds" : { "type" : "text" }, 

} 
}, 

"t_kd_grdfd" : { 
"properties" : { 
"kk" : { "type" : "text" }, 
"zjdd" : { "type" : "text" }, 
"yxjdf" : { "type" : "text" }, 

} 
} 
} 
} 

```

what I want to do is to mapping different log to different type like t\_kd\_grdfd and t\_df\_dfxx, would you mind tell me how to do the right thing?Thank you.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 6, 2018, 1:53am UTC](https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565/2 "2018-03-06T01:53:03Z")

</div>

Elasticsearch 6.x only supports a single type in new indices, as described [in this blog post](https://www.elastic.co/blog/removal-of-mapping-types-elasticsearch).

---

<div class="post-metadata">

**Author:** ![jaas](https://avatars.discourse-cdn.com/v4/letter/j/a4c791/32.png) [@jaas](https://discuss.elastic.co/u/jaas)\
**Post date:** [March 6, 2018, 2:04am UTC](https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565/3 "2018-03-06T02:04:27Z")

</div>

Thank you for your replay. I have different log format with different names. For example, a.log,b.log,c.log....a,b,c.. have some relationship, actually, there are exported from a database.I want to build only one index and mapping,if I can say this word, them to different types.

What should I do in logstash and filebeat?I am totally confused by the removal of mapping.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 6, 2018, 2:07am UTC](https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565/4 "2018-03-06T02:07:09Z")

</div>

Please provide examples to help us better understand the problem you are having. It is very hard to give any concrete advice based on the currently available information.

---

<div class="post-metadata">

**Author:** ![jaas](https://avatars.discourse-cdn.com/v4/letter/j/a4c791/32.png) [@jaas](https://discuss.elastic.co/u/jaas)\
**Post date:** [March 6, 2018, 2:44am UTC](https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565/5 "2018-03-06T02:44:06Z")

</div>

file names of my log(txt): 1\_A.txt, 1\_B.txt,1\_C.txt, 2\_A.txt, 2\_B.txt,2\_C.txt;  
A ,B, C has different format (type).Let's say ,A's format is name,account,address;B's format is account, balance; C's format is account,status.

I put all txt files under one directory and collect them with filebeat and logstash into elasticsearch.  
I will build a index named test, and put data(_.txt)into it.  
specifically, I want put all \_A.txt into type a\_type,\_B.txt into b\_type,_\_C.txt into c\_type.  
because I use filebeat and logstash, I need to load template manually,so I need write and load a template.

I have read the document and understand put two document into a index,but I use filebeat and logstash,I am confused.

what should I do to accomplish it?  
Thank you for your patient and help.

---

<div class="post-metadata">

**Author:** ![jaas](https://avatars.discourse-cdn.com/v4/letter/j/a4c791/32.png) [@jaas](https://discuss.elastic.co/u/jaas)\
**Post date:** [March 6, 2018, 2:55am UTC](https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565/6 "2018-03-06T02:55:54Z")

</div>

```
{
 "mappings": {
 "a_type": {
  "properties": {
    "name": { "type": "text" },
    "account": { "type": "keyword" },
    "address": { "type": "keyword" }
  }
},
"b_type": {
  "properties": {
    "account": { "type": "text" },
    "balance": { "type": "keyword" },
    
  }
,
"c_type": {
  "properties": {
    "account": { "type": "text" },
    "status": { "type": "keyword" },
    
  }
}
}

```

I write above code as my template to index test.but failed with wrong message "the final mapping would have more than 1 type." How does logstash know \*\_A.txt into a\_type?  
So confused about the removal of mappings

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 6, 2018, 1:30pm UTC](https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565/7 "2018-03-06T13:30:17Z")

</div>

The mapping contains more than 1 type, which is not allowed. Can you please give concrete examples of documents of the different types and explain why you feel you need to use type instead of e.g. just adding a custom field to each document that indicates the 'type' (which you can then filter on)?

---

<div class="post-metadata">

**Author:** ![jaas](https://avatars.discourse-cdn.com/v4/letter/j/a4c791/32.png) [@jaas](https://discuss.elastic.co/u/jaas)\
**Post date:** [March 6, 2018, 6:52pm UTC](https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565/8 "2018-03-06T18:52:16Z")

</div>

Thank you for you kindness.I am a beginner of Elasticsearch. My scenario is simple.  
I have 26 kinds of txt files from 30 different organizations.Let's say 1\_A.txt,2\_A.txt,....30\_A.txt;1\_B.txt,2\_B.txt,....1\_Z.txt,2\_Z.txt....30\_Z.txt.  
The line in these files above delimiter by ^A. for example, Smith^A56425887^A199.00^AFermont,CA^A^A20180101  
What I want to do is harvest these 26\*30 txt files with filbeat and ship them to Logstash  
, using a simple filter mutate {split =\>["message","^A"]} split every line into filed,eventually store them in Elasticsearch under a single index, let's say test.  
I want to analysis these data, most are transaction data, and visualize them by kibana or do some machine learning or statistics using x-pack.

I use 'type' initially due to it is easy to understand that a index similar to a database and a type similar to a table. Furthermore, when I read the documents of filebeat and logstash,I found that if filebeat do not directly connect to Elasticsearch, I need to load the template manually,which means I need 26 types in my template, for example, type A, type B,....type Z.

when I test my template containing only 1 type, I can using filebeat to collect certain txt files, let's say \*\_A.txt,and simply filtered by logstash, the data are sent to Elasticsearch.Of course, I load the A's template manually ahead.

When I add one more type into my template, error occurs.Like you said, the mapping do not allowed containing more than 1 type.And I learn from the documents of Elasticsearch that the mapping will be completely removed in version 7.0.

Is there any good solution to my simple applications?

Your post mentioned that just adding a custom field to each document that indicates the 'type'.I think it is a way to solve my problem. But I am a new to filebeat, logstash and Elasticsearch,would you mind show me some example,especially the configuration files on filter.It will be great help if you tell me what knowledge I need to learn.

Thank you for your time.It is very pleasure to learn from you.

---

<div class="post-metadata">

**Author:** ![jaas](https://avatars.discourse-cdn.com/v4/letter/j/a4c791/32.png) [@jaas](https://discuss.elastic.co/u/jaas)\
**Post date:** [March 6, 2018, 7:05pm UTC](https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565/9 "2018-03-06T19:05:53Z")

</div>

the examples of documents of the different types like this  
1\_A.TXT contains. Smith^A56425887^A199.00^AFermont,CA^A1^A20180101  
format name^Aaccount^Abalance^Aaddress^Aorganization\_id^Adate  
Smith,56425887,199.00,Fermont,CA,1,20180101 will be my document  
if I deal with them like database, I can search them from type A and A has a field name, so I know how to analyze .  
2\_A.TXT contains documents like : Bay^A32425887^A878.00^ASan,LA^A2^A20180101

I know this method not benefit from Elasticsearch. Would you please tell me how to tackle this ?

1\_Z.TXT contains documents like : 1232322^A343.00^A12^Acredit card^A20180202^A1

---

<div class="post-metadata">

**Author:** ![jaas](https://avatars.discourse-cdn.com/v4/letter/j/a4c791/32.png) [@jaas](https://discuss.elastic.co/u/jaas)\
**Post date:** [March 7, 2018, 12:31am UTC](https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565/10 "2018-03-07T00:31:18Z")

</div>

If I add a custom field to each document that indicates the 'type'(actually, I want to know how to accomplish this), how about my filed name? It will influence my way to access data when I analysis.Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2018, 12:31am UTC](https://discuss.elastic.co/t/the-final-mapping-would-have-more-than-1-type/122565/11 "2018-04-04T00:31:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
