# Unable to create index in Elastic search using API

**URL:** <https://discuss.elastic.co/t/unable-to-create-index-in-elastic-search-using-api/233446>\
**Category:** Elasticsearch\
**Created:** [May 20, 2020, 3:49am UTC](https://discuss.elastic.co/t/unable-to-create-index-in-elastic-search-using-api/233446 "2020-05-20T03:49:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rupini](https://avatars.discourse-cdn.com/v4/letter/r/58f4c7/32.png) [@rupini](https://discuss.elastic.co/u/rupini)\
**Post date:** [May 20, 2020, 3:49am UTC](https://discuss.elastic.co/t/unable-to-create-index-in-elastic-search-using-api/233446/1 "2020-05-20T03:49:40Z")

</div>

Hi, I am trying to create index in Elastic search using API in Kibana dev tools.

```auto
PUT /ipflow-logs
{
  "ipflow-logs" : {
    "mappings" : {
      "properties" : {
        "conn_state" : {
          "type" : "keyword"
        },
        "content_length" : {
          "type" : "long"
        },
        "content_type" : {
          "type" : "keyword"
        },
        "createdDate" : {
          "type" : "keyword"
        },
        "dst_ip" : {
          "type" : "ip"
        },
        "dst_port" : {
          "type" : "long"
        },
        "duration" : {
          "type" : "long"
        },
        "history" : {
          "type" : "keyword"
        },
        "local_orig" : {
          "type" : "keyword"
        },
        "missed_bytes" : {
          "type" : "long"
        },
        "orig_bytes" : {
          "type" : "long"
        },
        "orig_ip_bytes" : {
          "type" : "long"
        },
        "orig_pkts" : {
          "type" : "long"
        },
        "protocol" : {
          "type" : "keyword"
        },
        "resp_bytes" : {
          "type" : "long"
        },
        "resp_ip_bytes" : {
          "type" : "long"
        },
        "resp_pkts" : {
          "type" : "long"
        },
        "service" : {
          "type" : "keyword"
        },
        "src_ip" : {
          "type" : "ip"
        },
        "src_port" : {
          "type" : "long"
        },
        "timestamp" : {
          "type" : "date",
          "format" : "yyyy-MM-dd 'T' HH:mm:ss.SSS"
        },
        "uid" : {
          "type" : "keyword"
        }
      }
    }
  }
}

```

I am getting the following error

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "parse_exception",
        "reason": "unknown key [ipflow-logs] for create index"
      }
    ],
    "type": "parse_exception",
    "reason": "unknown key [ipflow-logs] for create index"
  },
  "status": 400
}

```

Any help is appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 20, 2020, 4:15am UTC](https://discuss.elastic.co/t/unable-to-create-index-in-elastic-search-using-api/233446/2 "2020-05-20T04:15:34Z")

</div>

Check out [https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html#create-mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html#create-mapping).

Basically you need to remove `ipflow-logs` at the URL or top json level.

---

<div class="post-metadata">

**Author:** ![rupini](https://avatars.discourse-cdn.com/v4/letter/r/58f4c7/32.png) [@rupini](https://discuss.elastic.co/u/rupini)\
**Post date:** [May 20, 2020, 4:39am UTC](https://discuss.elastic.co/t/unable-to-create-index-in-elastic-search-using-api/233446/3 "2020-05-20T04:39:53Z")

</div>

Thanks @warkolm for your reply. It worked to solve the issue.

After I created the index, am trying to use reindex API to copy documents from another index. I am getting the following error.

```auto
"failures": [
    {
      "index": "ipflow-logs",
      "type": "_doc",
      "id": "EwZxLHIBwqu9v3DPUWLu",
      "cause": {
        "type": "mapper_parsing_exception",
        "reason": "failed to parse field [timestamp] of type [date] in document with id 'EwZxLHIBwqu9v3DPUWLu'. Preview of field's value: '2012-03-16 20:30:00.060'",
        "caused_by": {
          "type": "illegal_argument_exception",
          "reason": "failed to parse date field [2012-03-16 20:30:00.060] with format [yyyy-MM-dd 'T' HH:mm:ss.SSS]",
          "caused_by": {
            "type": "date_time_parse_exception",
            "reason": "date_time_parse_exception: Text '2012-03-16 20:30:00.060' could not be parsed at index 11"
          }
        }
      },
      "status": 400

```

Is it possible to point out where I am going wrong?. Thanks

---

<div class="post-metadata">

**Author:** ![forloop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/forloop/32/9021_2.png) [@forloop](https://discuss.elastic.co/u/forloop)\
**Post date:** [May 21, 2020, 12:24am UTC](https://discuss.elastic.co/t/unable-to-create-index-in-elastic-search-using-api/233446/4 "2020-05-21T00:24:59Z")

</div>

> [@rupini](#):
>
> "failed to parse field [timestamp] of type [date] in document with id 'EwZxLHIBwqu9v3DPUWLu'. Preview of field's value: '2012-03-16 20:30:00.060'"

The format of the date ` '2012-03-16 20:30:00.060'` does not match the format that you have defined for `timestamp`, which is

> [@rupini](#):
>
> ```json
> "timestamp" : { "type" : "date", "format" : "yyyy-MM-dd 'T' HH:mm:ss.SSS" },
> 
> ```

The format should be `"yyyy-MM-dd HH:mm:ss.SSS"`, or you can [specify multiple formats](https://www.elastic.co/guide/en/elasticsearch/reference/current/date.html#multiple-date-formats) if you expect multiple formats, `"yyyy-MM-dd 'T' HH:mm:ss.SSS||yyyy-MM-dd HH:mm:ss.SSS"`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 18, 2020, 12:24am UTC](https://discuss.elastic.co/t/unable-to-create-index-in-elastic-search-using-api/233446/5 "2020-06-18T00:24:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
