# Tons of warning message "no index mapper found for field" in the log (one every seconds)

**URL:** <https://discuss.elastic.co/t/tons-of-warning-message-no-index-mapper-found-for-field-in-the-log-one-every-seconds/41310>\
**Category:** Elasticsearch\
**Created:** [February 9, 2016, 7:02pm UTC](https://discuss.elastic.co/t/tons-of-warning-message-no-index-mapper-found-for-field-in-the-log-one-every-seconds/41310 "2016-02-09T19:02:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![s0mb00n](https://avatars.discourse-cdn.com/v4/letter/s/7c8e57/32.png) [@s0mb00n](https://discuss.elastic.co/u/s0mb00n)\
**Post date:** [February 9, 2016, 7:02pm UTC](https://discuss.elastic.co/t/tons-of-warning-message-no-index-mapper-found-for-field-in-the-log-one-every-seconds/41310/1 "2016-02-09T19:02:01Z")

</div>

After upgrading to Elasticsearch 2.1.1 from 1.5 version, the following warning message started to fill up elasticsearch log:

````auto
Feb 9 18:25:17 logstash elasticsearch[30011]: [2016-02-09 18:25:17,523][WARN][index.codec] [Man-Beast] [logstash-2016.02.09] no index mapper found for field: [api_version.raw] returning default postings format
Feb 9 18:25:17 logstash elasticsearch[30011]: [2016-02-09 18:25:17,523][WARN][index.codec] [Man-Beast] [logstash-2016.02.09] no index mapper found for field: [client_addr] returning default postings format
Feb 9 18:25:17 logstash elasticsearch[30011]: [2016-02-09 18:25:17,523][WARN][index.codec] [Man-Beast] [logstash-2016.02.09] no index mapper found for field: [client_addr.raw] returning default postings format
Feb 9 18:25:17 logstash elasticsearch[30011]: [2016-02-09 18:25:17,523][WARN][index.codec] [Man-Beast] [logstash-2016.02.09] no index mapper found for field: [forwarded_for] returning default postings format
Feb 9 18:25:17 logstash elasticsearch[30011]: [2016-02-09 18:25:17,523][WARN][index.codec] [Man-Beast] [logstash-2016.02.09] no index mapper found for field: [forwarded_for.raw] returning default postings format
Feb 9 18:25:17 logstash elasticsearch[30011]: [2016-02-09 18:25:17,523][WARN][index.codec] [Man-Beast] [logstash-2016.02.09] no index mapper found for field: [proto] returning default postings format
Feb 9 18:25:17 logstash elasticsearch[30011]: [2016-02-09 18:25:17,523][WARN][index.codec] [Man-Beast] [logstash-2016.02.09] no index mapper found for field: [proto.raw] returning default postings format```

These warning messages are being pumped into the log almost every seconds and they are always on the same fields (`api_version`, `api_version.raw`, `client_addr`, `client_addr.raw`, `forwarded_for`, `forwarded_for.raw`, `proto`, and `proto.raw`).

I think these warning messages also affect the performance of the cluster as I noticed that the server is somewhat slower after the upgrade. 

Any suggestion on how to fix this issue would be greatly appreciated?
````

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [February 9, 2016, 10:44pm UTC](https://discuss.elastic.co/t/tons-of-warning-message-no-index-mapper-found-for-field-in-the-log-one-every-seconds/41310/2 "2016-02-09T22:44:24Z")

</div>

Did you follow the migration plugin advice?

> **[Elasticsearch 2.x upgrade](https://www.elastic.co/blog/key-point-to-be-aware-of-when-upgrading-from-elasticsearch-1-to-2)**
>
> Considerations when upgrading to Elasticsearch 2.x

It seems that you have incompatible fields in your old mapping.

---

<div class="post-metadata">

**Author:** ![s0mb00n](https://avatars.discourse-cdn.com/v4/letter/s/7c8e57/32.png) [@s0mb00n](https://discuss.elastic.co/u/s0mb00n)\
**Post date:** [February 10, 2016, 1:31am UTC](https://discuss.elastic.co/t/tons-of-warning-message-no-index-mapper-found-for-field-in-the-log-one-every-seconds/41310/3 "2016-02-10T01:31:18Z")

</div>

thank you for your help @jprante. I actually did follow the upgrade instruction and re-index my cluster so that all the fields that have the same name are of the same type. After that (and a few config changes), we were able to upgrade to 2.1.1 and our cluster was up for about a week or so before we started to see these warning messages.

Please note that the fields that the warning message are complaining about are not the one that the migration plugin identify to be re-indexed. In fact, we don't even have any field in our document with the `.raw` string in the name. I'm guessing that this is something that was being added by logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:17pm UTC](https://discuss.elastic.co/t/tons-of-warning-message-no-index-mapper-found-for-field-in-the-log-one-every-seconds/41310/4 "2017-07-05T23:17:45Z")

</div>


