# Underscore preventing us from upgrading from 1.7.1 to 2.x

**URL:** https://discuss.elastic.co/t/underscore-preventing-us-from-upgrading-from-1-7-1-to-2-x/63634
**Category:** Logstash
**Created:** [October 21, 2016, 3:18pm UTC](https://discuss.elastic.co/t/underscore-preventing-us-from-upgrading-from-1-7-1-to-2-x/63634 "2016-10-21T15:18:36Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![genesis](https://avatars.discourse-cdn.com/v4/letter/g/96bed5/32.png) [@genesis](https://discuss.elastic.co/u/genesis)
#### Post date: [October 21, 2016, 3:18pm UTC](https://discuss.elastic.co/t/underscore-preventing-us-from-upgrading-from-1-7-1-to-2-x/63634/1 "2016-10-21T15:18:36Z")

</div>

I have been trying to resolve this issue which is preventing me from upgrading from 1.7.1 to 2.x due to this error:  
The \_uid, \_id, \_type, \_source, \_all, \_parent, \_field\_names, \_routing, \_index, \_size, \_timestamp, and \_ttl field names are reserved and can no longer be used in the document \_source., in type: logs.

At the ElasticOn NY couple of days ago, I worked with Chris Earle and he suggested to make these changes in logstash and re-indexed but those indices when ran through the migration tool still show the same errors.  
Please help

filter {  
ruby {  
init =\> "  
def remove\_dots hash  
new = Hash.new  
hash.each { |k,v|  
if v.is\_a? Hash  
v = remove\_dots(v)  
end  
new[k.gsub('.','\_')] = v  
if v.is\_a? Array  
v.each { |elem|  
if elem.is\_a? Hash  
elem = remove\_dots(elem)

```
                    end
                    key = k.gsub('.','_')
                    if key.starts_with?('_')
                      key = key[1..-1]
                    end
                    new[key] = elem
                } unless v.nil?
            end
        } unless hash.nil?
        return new
    end
"
code => "
    event.instance_variable_set(:@data,remove_dots(event.to_hash))
"

```

}  
mutate {

```
rename => { "_uid" => "uid" }
rename => { "_action" => "action" }
rename => { "_caps" => "caps" }
rename => { "_cldee" => "cldee" }
rename => { "_ga" => "ga" }
rename => { "_mbox" => "mbox" }
rename => { "_partner" => "partner" }
rename => { "_rand" => "rand" }
rename => { "_rdr" => "rdr" }
rename => { "_sm_au_" => "sm_au_" }
rename => { "_suid" => "suid" }
rename => { "_task" => "task" }

```

}  
}

output {  
elasticsearch {  
hosts =\> ["[xxxxxxxxxx.com](http://xxxxxxxxxx.com)" ]  
index =\> "%{[@metadata][\_index]}"  
document\_type =\> "%{[@metadata][\_type]}"  
document\_id =\> "%{[@metadata][\_id]}"  
}

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:33am UTC](https://discuss.elastic.co/t/underscore-preventing-us-from-upgrading-from-1-7-1-to-2-x/63634/2 "2017-07-06T04:33:15Z")

</div>


