# WARN elasticsearch/client.go:520 Cannot index event publisher.Event

**URL:** <https://discuss.elastic.co/t/warn-elasticsearch-client-go-520-cannot-index-event-publisher-event/155683>\
**Category:** APM\
**Created:** [November 7, 2018, 8:25am UTC](https://discuss.elastic.co/t/warn-elasticsearch-client-go-520-cannot-index-event-publisher-event/155683 "2018-11-07T08:25:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gp4004](https://avatars.discourse-cdn.com/v4/letter/g/ea666f/32.png) [@gp4004](https://discuss.elastic.co/u/gp4004)\
**Post date:** [November 7, 2018, 8:25am UTC](https://discuss.elastic.co/t/warn-elasticsearch-client-go-520-cannot-index-event-publisher-event/155683/1 "2018-11-07T08:25:07Z")

</div>

Hi,

I have the following issue since in the APM logs 2 days :

> 2018-11-06T09:34:13.816Z WARN elasticsearch/client.go:520 Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0x35495b80, ext:63677093648, loc:(\*time.Location)(nil)}, Meta:common.MapStr(nil), Fields:common.MapStr{"processor":common.MapStr{"name":"transaction", "event":"transaction"}, "transaction":common.MapStr{"result":"success", "sampled":true, "id":"986e2613-6bbe-493b-931e-560a729b08ac", "name":"GET static file", "duration":common.MapStr{"us":1718}, "type":"request"}, "context":common.MapStr{"service":common.MapStr{"name":"XXXXXX", "agent":common.MapStr{"name":"nodejs", "version":"1.12.0"}, "language":common.MapStr{"name":"javascript"}, "runtime":common.MapStr{"name":"node", "version":"v8.11.2"}, "framework":common.MapStr{"name":"express", "version":"4.13.4"}},  
> .  
> .  
> .  
> .  
> (status=400): {"type":"mapper\_parsing\_exception","reason":"Failed to parse mapping [doc]: Mapping definition for [host] has unsupported parameters: [properties : {os={properties={family={ignore\_above=1024, type=keyword}, version={ignore\_above=1024, type=keyword}, platform={ignore\_above=1024, type=keyword}}}, ip={type=ip}, name={ignore\_above=1024, type=keyword}, id={ignore\_above=1024, type=keyword}, mac={ignore\_above=1024, type=keyword}, architecture={ignore\_above=1024, type=keyword}}]","caused\_by":{"type":"mapper\_parsing\_exception","reason":"Mapping definition for [host] has unsupported parameters: [properties : {os={properties={family={ignore\_above=1024, type=keyword}, version={ignore\_above=1024, type=keyword}, platform={ignore\_above=1024, type=keyword}}}, ip={type=ip}, name={ignore\_above=1024, type=keyword}, id={ignore\_above=1024, type=keyword}, mac={ignore\_above=1024, type=keyword}, architecture={ignore\_above=1024, type=keyword}}]"}}

There is no corresponding message in Elastic logs.

Note that Elastic doesn't create the new indice at 00:00 whereas it was created before 2018-11-06

> [2018-11-04T00:00:02,805][INFO][o.e.c.m.MetaDataCreateIndexService] [\_knGLBb] [apm-6.4.2-2018.11.04] creating index, cause [auto(bulk api)], templates [apm-6.4.2], shards [5]/[1], mappings [doc]  
> [2018-11-05T00:00:15,114][INFO][o.e.c.m.MetaDataCreateIndexService] [\_knGLBb] [apm-6.4.2-2018.11.05] creating index, cause [auto(bulk api)], templates [apm-6.4.2], shards [5]/[1], mappings [doc]

I'm running APM / Elastic / Kibana 6.4.2 in 3 docker containers on the same node  
Free diskspace is around 38% (10GB available)

the following post didn't help :

> [@Cannot index event publisher.Event (elasticsearch/client.go:502)](https://discuss.elastic.co/t/cannot-index-event-publisher-event-elasticsearch-client-go-502/127502):
>
> I set up APM in my Nodejs Express app. It starts fine, creates a new index in elasticsearch. When API return errors it only logs first few errors in elasticsearch (3,4 or 7 sometimes, its random) and then on starts throwing following error: 2018-04-10T19:22:28.516+0500 DEBUG [elasticsearch] elasticsearch/client.go:303 PublishEvents: 2 events have been published to elasticsearch in 88.166183ms. 2018-04-10T19:22:28.516+0500 WARN elasticsearch/client.go:502 Cannot index event publisher.Event{Co…

---

<div class="post-metadata">

**Author:** ![gp4004](https://avatars.discourse-cdn.com/v4/letter/g/ea666f/32.png) [@gp4004](https://discuss.elastic.co/u/gp4004)\
**Post date:** [November 8, 2018, 8:37am UTC](https://discuss.elastic.co/t/warn-elasticsearch-client-go-520-cannot-index-event-publisher-event/155683/2 "2018-11-08T08:37:50Z")

</div>

OK, the culprit was a logstash template messing up Elastic.  
After dropping that template, elastic immediately created the apm index.

---

<div class="post-metadata">

**Author:** ![simitt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simitt/32/106406_2.png) [@simitt](https://discuss.elastic.co/u/simitt)\
**Post date:** [November 21, 2018, 10:05am UTC](https://discuss.elastic.co/t/warn-elasticsearch-client-go-520-cannot-index-event-publisher-event/155683/3 "2018-11-21T10:05:44Z")

</div>


