# Types removal warning

**URL:** <https://discuss.elastic.co/t/types-removal-warning/233916>\
**Category:** Logstash\
**Created:** [May 22, 2020, 2:27pm UTC](https://discuss.elastic.co/t/types-removal-warning/233916 "2020-05-22T14:27:41Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![irishwill2008](https://avatars.discourse-cdn.com/v4/letter/i/eb9ed0/32.png) [@irishwill2008](https://discuss.elastic.co/u/irishwill2008)\
**Post date:** [May 22, 2020, 2:27pm UTC](https://discuss.elastic.co/t/types-removal-warning/233916/1 "2020-05-22T14:27:42Z")

</div>

Hey guys,

Inside "elasticsearch\_deprecation.log" i see the odd warning stating: `[types removal] Specifying types in bulk requests is deprecated.`.

I want to remove this, i am running my Elastic Stack on v7.7. I looked online but keep going down rabbitholes? I cant seem to find anything that simply states a command or something to resolve this.

Can someone shed some light on this?

Thanks.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 22, 2020, 3:33pm UTC](https://discuss.elastic.co/t/types-removal-warning/233916/2 "2020-05-22T15:33:18Z")

</div>

How are you indexing documents?

---

<div class="post-metadata">

**Author:** ![irishwill2008](https://avatars.discourse-cdn.com/v4/letter/i/eb9ed0/32.png) [@irishwill2008](https://discuss.elastic.co/u/irishwill2008)\
**Post date:** [May 22, 2020, 3:42pm UTC](https://discuss.elastic.co/t/types-removal-warning/233916/3 "2020-05-22T15:42:36Z")

</div>

Hey there,

Apologies for the noobie response, I hope the below might answer this as i dont exactly understand how to answer that question as i am still learning Elastic Stack.

I used Kibanas Index Patterns? So i have an index in the format: "filebeat-" So i setup a pattern to match "filebeat-\*".

Are you asking me to provide you with my logstash setup, filebeat setup or?

Whatever you need to assist me i will provide.

Again, apologies in advance!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 22, 2020, 4:58pm UTC](https://discuss.elastic.co/t/types-removal-warning/233916/4 "2020-05-22T16:58:59Z")

</div>

I was asking about the tools you are using to index data into elasticsearch. Is it logstash or filebeat?

Anyway, make sure you are using the latest version of those components.

---

<div class="post-metadata">

**Author:** ![irishwill2008](https://avatars.discourse-cdn.com/v4/letter/i/eb9ed0/32.png) [@irishwill2008](https://discuss.elastic.co/u/irishwill2008)\
**Post date:** [May 22, 2020, 5:13pm UTC](https://discuss.elastic.co/t/types-removal-warning/233916/5 "2020-05-22T17:13:41Z")

</div>

Hey Dadoonet,

I am using Filebeats to send the data to Logstash.

Logstash is on the latest version, filebeats is not actually.. Since i have many Agents.

I will update Filebeats now on the servers and report back.

Hopefully that resolves this 🙂

Thanks for the suggestion!

---

<div class="post-metadata">

**Author:** ![irishwill2008](https://avatars.discourse-cdn.com/v4/letter/i/eb9ed0/32.png) [@irishwill2008](https://discuss.elastic.co/u/irishwill2008)\
**Post date:** [May 22, 2020, 6:31pm UTC](https://discuss.elastic.co/t/types-removal-warning/233916/6 "2020-05-22T18:31:48Z")

</div>

Hey Dadoonet,

I just updated filebeats on all my servers.

I can confirm the entire Elastic Stack / Components are now all running on 7.7.0.

Unfortunately i can still see that error populating.

`[types removal] Specifying types in bulk requests is deprecated.`

Do i have to cleanse my current indices perhaps? Maybe its contaminated?

Thanks.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 22, 2020, 6:40pm UTC](https://discuss.elastic.co/t/types-removal-warning/233916/7 "2020-05-22T18:40:43Z")

</div>

What are you using logstash for?  
What is its configuration ?

---

<div class="post-metadata">

**Author:** ![irishwill2008](https://avatars.discourse-cdn.com/v4/letter/i/eb9ed0/32.png) [@irishwill2008](https://discuss.elastic.co/u/irishwill2008)\
**Post date:** [May 22, 2020, 7:31pm UTC](https://discuss.elastic.co/t/types-removal-warning/233916/8 "2020-05-22T19:31:23Z")

</div>

Hey,

I have logstash installed as a windows service, i have it run a param: "-f C:\Logstash\logstash.conf" for example, inside logstash.conf is:

```auto
input {
  beats {
    port => 5044
  }
}
filter {
  if [fields][log_type] == "check1" {
    grok {
	  match => {
	    "message" => [
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{WORD:level} - %{DATA:[fields][sourceontext]} %{GREEDYDATA:unparsed} : (?<message>.*?(?=[a-zA-Z.]*Exception:))%{GREEDYDATA:exception}",
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{WORD:level} - %{DATA:[fields][sourceontext]} %{GREEDYDATA:unparsed} : %{GREEDYDATA:message}"
	    ]
	  }	
	  overwrite => ["message"]
    } 
  }
  else if [fields][log_type] == "check2" {
    grok {
	  match => {
	    "message" => [
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{WORD:level} : %{GREEDYDATA:message}",
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{WORD:level} %{DATA:[fields][sourceontext]} : %{GREEDYDATA:message}",
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{WORD:level} %{DATA:[fields][sourceontext]} : (?<message>.*?(?=[a-zA-Z.]*Exception:))%{GREEDYDATA:exception}",
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{WORD:level} %{DATA:[fields][sourceontext]} %{GREEDYDATA:unparsed} : %{GREEDYDATA:message}"
	    ]
	  }	
	  overwrite => ["message"]
    } 
  }
  else if [fields][log_type] == "check3" {
    grok {
	  match => {
	    "message" => [
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{WORD:sessionid} %{IP:ip} %{WORD:level} %{DATA:[fields][sourceontext]} : %{GREEDYDATA:message}",
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{WORD:sessionid} %{WORD:ip} %{WORD:level} %{DATA:[fields][sourceontext]} %{GREEDYDATA:unparsed} : (?<message>.*?(?=[a-zA-Z.]*Exception:))%{GREEDYDATA:exception}",
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{WORD:sessionid} %{WORD:ip} %{WORD:level} %{DATA:[fields][sourceontext]} %{GREEDYDATA:unparsed} : %{GREEDYDATA:message}"
	    ]
	  }	
	  overwrite => ["message"]
    } 
  }
  else if [fields][log_type] == "check4" {
    grok {
	  match => {
	    "message" => [
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{DATA:fieldid} %{WORD:level} %{DATA:loggingclass} %{DATA:[fields][sourceontext]} : %{GREEDYDATA:message}",
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{DATA:fieldid} %{WORD:level} %{DATA:[fields][sourceontext]} : %{GREEDYDATA:message}"
	    ]
	  }	
	  overwrite => ["message"]
    } 
  }
  else {
    grok {
	  match => {
	    "message" => [
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{WORD:level} - %{DATA:[fields][sourceontext]} \[%{DATA:[fields][requestid]}\] %{GREEDYDATA:unparsed} : (?<message>.*?(?=[a-zA-Z.]*Exception:))%{GREEDYDATA:exception}",
		  "(?m)%{TIMESTAMP_ISO8601:timestamp} \[%{NUMBER:[fields][threadid]}\] %{WORD:level} - %{DATA:[fields][sourceontext]} \[%{DATA:[fields][requestid]}\] %{GREEDYDATA:unparsed} : %{GREEDYDATA:message}"
	    ]
	  }	
	  overwrite => ["message"]
    } 
  }
  date {
    match => ["timestamp", "ISO8601"]
	remove_field => ["timestamp"]
  }
  json {
	skip_on_invalid_json => true
	source => "unparsed"
	target => "[fields][scope]"
  }
  mutate {
    remove_field => ["unparsed"]
  }
  if "beats_input_codec_plain_applied" in [tags] {
	mutate {
		remove_tag => ["beats_input_codec_plain_applied"]
	}
  }
}
output {
  elasticsearch {
    hosts => ["https://ElasticSearch:9200"]
	ssl => true
	cacert => "file.pem"
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
    user => "${ES_USERNAME}"
    password => "${ES_PASSWORD}"
  }
}

```

I have logs populating in a certain way so my checks are for different log types.

Thanks.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 22, 2020, 7:58pm UTC](https://discuss.elastic.co/t/types-removal-warning/233916/9 "2020-05-22T19:58:54Z")

</div>

I moved the question to #logstash as it looks like logstash is sending the type field in bulk requests which should be removed I believe.

[https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-document\_type](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-document_type)

I guess it's there for compatibility reason. May be experts can comment.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 22, 2020, 9:14pm UTC](https://discuss.elastic.co/t/types-removal-warning/233916/10 "2020-05-22T21:14:51Z")

</div>

@irishwill2008 that is a [known](https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/915) issue. Hopefully it is fixable now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2020, 9:14pm UTC](https://discuss.elastic.co/t/types-removal-warning/233916/11 "2020-06-19T21:14:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
