# Updating mapping

**URL:** <https://discuss.elastic.co/t/updating-mapping/46900>\
**Category:** Elasticsearch\
**Created:** [April 10, 2016, 3:37pm UTC](https://discuss.elastic.co/t/updating-mapping/46900 "2016-04-10T15:37:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![kamaradski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kamaradski/32/9029_2.png) [@kamaradski](https://discuss.elastic.co/u/kamaradski)\
**Post date:** [April 10, 2016, 3:37pm UTC](https://discuss.elastic.co/t/updating-mapping/46900/1 "2016-04-10T15:37:06Z")

</div>

I'm sorry for yet another noob asking about this, but this topic is confusing me and i didn't find a good solution yet ☹

I have been logging my public FTP server for a while now without problems, but recently added some nginx data to the same index (logstash-\*).

Since I first tested in a separate database without any problems, i now added all data to the live index.

**Problem:**  
There is a conflict with one of the fields. 'field:bytes' is stored as 'type:long' and in some cases as 'type:integer'

**Expected result:**  
'type:integer' for all fields.

I guess i can do this with a PUT command, but i cannot seem to fully understand the right thing, and now i am scared of messing up my existing data. Could someone help me in the right direction ?

> curl -X GET '[http://localhost:9200/logstash\*/\_mapping/nginx/field/bytes?pretty=true](http://localhost:9200/logstash*/_mapping/nginx/field/bytes?pretty=true)'  
> **result:**  
> "logstash-2015.10.30" : {  
> "mappings" : {  
> "nginx" : {  
> "bytes" : {  
> "full\_name" : "bytes",  
> "mapping" : {  
> "bytes" : {  
> "type" : "long"  
> }  
> }  
> }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [April 10, 2016, 6:47pm UTC](https://discuss.elastic.co/t/updating-mapping/46900/2 "2016-04-10T18:47:18Z")

</div>

I guess you are using ES 2.x. Since ES 2.0, you cannot have the same field name with different mappings across different types in the same index. In you case, the mapping type of `bytes` field in your FTP type is different from in nginx type.

So, you can either put nginx data into a different index or add a prefix to you `bytes` field, e.g., `nginx-bytes`. You won't be able to change to mapping type of existing data in your index.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 10, 2016, 7:49pm UTC](https://discuss.elastic.co/t/updating-mapping/46900/3 "2016-04-10T19:49:20Z")

</div>

You need to add a template of that mapping, so that any new indices created use the same mapping with the field set. Then split your logs into different indices, mixing types like you have causes problems like you have.

---

<div class="post-metadata">

**Author:** ![kamaradski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kamaradski/32/9029_2.png) [@kamaradski](https://discuss.elastic.co/u/kamaradski)\
**Post date:** [April 10, 2016, 10:36pm UTC](https://discuss.elastic.co/t/updating-mapping/46900/4 "2016-04-10T22:36:58Z")

</div>

Thanks for the replies guy's.

Yeah this explains why it worked in the test-setup but not in live.

However when i had separate indices i had problems with geo-ip showing up as type:double, as i use geo-ip both on the ftp and on the nginx. preventing it from working correctly.

- I would prefer separate indices for performance reasons, but what to do with the geo-ip ?
- Could i somehow delete all type:nginx data out of my current index ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 10, 2016, 10:50pm UTC](https://discuss.elastic.co/t/updating-mapping/46900/5 "2016-04-10T22:50:41Z")

</div>

Like I said, you need to adapt the existing template for the new index.  
Otherwise, just call one index `logstash-nginx-` and one `logstash-ftp-` then the same template will aply to both.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:00pm UTC](https://discuss.elastic.co/t/updating-mapping/46900/6 "2017-07-05T23:00:52Z")

</div>


