# \[WARN \]\[o.e.d.i.m.MapperService \] \[unmapped\_type:string\] should be replaced with \[unmapped\_type:keyword\]

**URL:** <https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948>\
**Category:** Elasticsearch\
**Created:** [March 24, 2017, 9:19pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948 "2017-03-24T21:19:59Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![klein\_stephane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/klein_stephane/32/11364_2.png) [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Post date:** [March 24, 2017, 9:19pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/1 "2017-03-24T21:19:59Z")

</div>

Hi,

how can I fix this ElasticSearch 5.2.2 Warning?

```
[WARN][o.e.d.i.m.MapperService] [unmapped_type:string] should be replaced with [unmapped_type:keyword]

```

This is my indices configuration: [https://gist.github.com/harobed/e92fb7d131cac523067c26458d842184](https://gist.github.com/harobed/e92fb7d131cac523067c26458d842184)

Best regards,  
Stéphane

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 24, 2017, 11:00pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/2 "2017-03-24T23:00:00Z")

</div>

Read the breaking changes doc. String type has been removed.

---

<div class="post-metadata">

**Author:** ![klein\_stephane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/klein_stephane/32/11364_2.png) [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Post date:** [March 25, 2017, 8:42am UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/3 "2017-03-25T08:42:43Z")

</div>

> [@dadoonet](#):
>
> Read the breaking changes doc. String type has been removed.

I use Logstash 5.2.2 and Kibana 5.2.2 on empty ES. This two tools are not compatible with ES 5.2.2 ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 25, 2017, 4:39pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/4 "2017-03-25T16:39:44Z")

</div>

They are but you probably upgraded or already have an old template?

---

<div class="post-metadata">

**Author:** ![klein\_stephane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/klein_stephane/32/11364_2.png) [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Post date:** [March 27, 2017, 7:18pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/5 "2017-03-27T19:18:33Z")

</div>

> [@dadoonet](#):
>
> They are but you probably upgraded or already have an old template?

No, my data are empty.

---

<div class="post-metadata">

**Author:** ![klein\_stephane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/klein_stephane/32/11364_2.png) [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Post date:** [March 27, 2017, 7:36pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/6 "2017-03-27T19:36:47Z")

</div>

ES display that warning for `logstash` indice:

```auto
elasticsearch_1 | [2017-03-27T19:25:37,644][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [title]
elasticsearch_1 | [2017-03-27T19:25:37,649][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [timeFieldName]
elasticsearch_1 | [2017-03-27T19:25:37,655][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [intervalName]
elasticsearch_1 | [2017-03-27T19:25:37,658][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [fields]
elasticsearch_1 | [2017-03-27T19:25:37,661][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [sourceFilters]
elasticsearch_1 | [2017-03-27T19:25:37,662][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [fieldFormatMap]
elasticsearch_1 | [2017-03-27T19:25:37,673][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [title]
elasticsearch_1 | [2017-03-27T19:25:37,675][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [timeFieldName]
elasticsearch_1 | [2017-03-27T19:25:37,676][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [intervalName]
elasticsearch_1 | [2017-03-27T19:25:37,678][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [fields]
elasticsearch_1 | [2017-03-27T19:25:37,685][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [sourceFilters]
elasticsearch_1 | [2017-03-27T19:25:37,686][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [fieldFormatMap]

```

and for `.kibana` indice:

```auto
elasticsearch_1 | [2017-03-27T19:34:47,709][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [title]
elasticsearch_1 | [2017-03-27T19:34:47,714][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [description]
elasticsearch_1 | [2017-03-27T19:34:47,714][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [columns]
elasticsearch_1 | [2017-03-27T19:34:47,714][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [sort]
elasticsearch_1 | [2017-03-27T19:34:47,715][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [searchSourceJSON]
elasticsearch_1 | [2017-03-27T19:34:47,716][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [title]
elasticsearch_1 | [2017-03-27T19:34:47,720][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [description]
elasticsearch_1 | [2017-03-27T19:34:47,720][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [columns]
elasticsearch_1 | [2017-03-27T19:34:47,721][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [sort]
elasticsearch_1 | [2017-03-27T19:34:47,721][WARN][o.e.d.i.m.StringFieldMapper$TypeParser] The [string] field is deprecated, please use [text] or [keyword] instead on [searchSourceJSON]

```

---

<div class="post-metadata">

**Author:** ![klein\_stephane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/klein_stephane/32/11364_2.png) [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Post date:** [March 27, 2017, 7:38pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/7 "2017-03-27T19:38:47Z")

</div>

It can be that?

```auto
curl "http://localhost:9200/logstash-2017.03.27/?pretty=1"
{
  "logstash-2017.03.27" : {
    "aliases" : { },
    "mappings" : {
      "_default_" : {
        "_all" : {
          "enabled" : true,
          "norms" : false
        },
        "dynamic_templates" : [
          {
            "message_field" : {
              "path_match" : "message",
              "match_mapping_type" : "string",
              "mapping" : {
                "norms" : false,
                "type" : "text"
              }
            }
          },
          {
            "string_fields" : {
              "match" : "*",
              "match_mapping_type" : "string",
              "mapping" : {
                "fields" : {
                  "keyword" : {
                    "type" : "keyword"
                  }
                },
                "norms" : false,
                "type" : "text"
              }
            }
          }
        ],
...

```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 27, 2017, 8:04pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/8 "2017-03-27T20:04:20Z")

</div>

But this template is correct.

Can you run a get cluster state query?

---

<div class="post-metadata">

**Author:** ![klein\_stephane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/klein_stephane/32/11364_2.png) [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Post date:** [March 28, 2017, 8:21am UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/9 "2017-03-28T08:21:34Z")

</div>

> [@dadoonet](#):
>
> Can you run a get cluster state query?

This [gist:5c196be791eace13e343409907e780a6 · GitHub](https://gist.github.com/harobed/5c196be791eace13e343409907e780a6) ?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 28, 2017, 2:24pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/10 "2017-03-28T14:24:15Z")

</div>

Weird. I can't explain what you are seeing here.

BTW how do you know that the messages you saw are related to `logstash` or `kibana` indices?

Any chance you have old kibana instance which is trying to connect to your Elasticsearch cluster? Same for logstash?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 28, 2017, 2:26pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/11 "2017-03-28T14:26:28Z")

</div>

I checked what Logstash 5.2.2 is sending to elasticsearch and it looks correct to me: [https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/5.2.x/lib/logstash/outputs/elasticsearch/elasticsearch-template-es5x.json](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/5.2.x/lib/logstash/outputs/elasticsearch/elasticsearch-template-es5x.json)

---

<div class="post-metadata">

**Author:** ![klein\_stephane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/klein_stephane/32/11364_2.png) [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Post date:** [March 28, 2017, 2:38pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/12 "2017-03-28T14:38:15Z")

</div>

> [@dadoonet](#):
>
> Any chance you have old kibana instance which is trying to connect to your Elasticsearch cluster? Same for logstash?

I did:

```auto
$ rm es-data -rf

```

before restart my ES Docker. Then I think ES is empty 🙂

---

<div class="post-metadata">

**Author:** ![klein\_stephane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/klein_stephane/32/11364_2.png) [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Post date:** [March 28, 2017, 2:39pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/13 "2017-03-28T14:39:27Z")

</div>

> [@dadoonet](#):
>
> BTW how do you know that the messages you saw are related to logstash or kibana indices?

I don't have other indices when I query `_cat/indices`.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 28, 2017, 3:05pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/14 "2017-03-28T15:05:17Z")

</div>

Sure. But it does not mean that another old process is not trying to connect to this instance.

Let me sum up the situation so I understand the full picture.

You have one elasticsearch instance, running on docker, which is totally empty as you remove data dir before starting.  
You start it. Then `GET _cat/indices` is totally empty?

Then you start Kibana 5.2.2 instance and it prints in your logs the message you pasted before. Is that right?

Then you start a Logstash 5.2.2 instance and it also prints similar log line. Still right?

Are Kibana and Logstash totally fresh new downloads from our website? Or did you upgrade them somehow?

---

<div class="post-metadata">

**Author:** ![klein\_stephane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/klein_stephane/32/11364_2.png) [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Post date:** [March 30, 2017, 6:02pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/15 "2017-03-30T18:02:07Z")

</div>

> [@dadoonet](#):
>
> You start it. Then GET \_cat/indices is totally empty?

```auto
$ rm es-data/ -rf
$ docker-compose up -d elasticsearch
Creating elk_elasticsearch_1
curl http://127.0.0.1:9200/_cluster/health?pretty=1
{
  "cluster_name" : "santa-maria-log",
  "status" : "green",
  "timed_out" : false,
  "number_of_nodes" : 1,
  "number_of_data_nodes" : 1,
  "active_primary_shards" : 0,
  "active_shards" : 0,
  "relocating_shards" : 0,
  "initializing_shards" : 0,
  "unassigned_shards" : 0,
  "delayed_unassigned_shards" : 0,
  "number_of_pending_tasks" : 0,
  "number_of_in_flight_fetch" : 0,
  "task_max_waiting_in_queue_millis" : 0,
  "active_shards_percent_as_number" : 100.0
}
$ curl http://127.0.0.1:9200/_cat/indices

```

I have no indice.

Log before start kibana : [after\_kibana · GitHub](https://gist.github.com/harobed/5e05941354d0f491c33eea526ecb6851#file-before_kibana)

Now I start kibana and I see warning message if I open Kibana in my browser : [after\_kibana · GitHub](https://gist.github.com/harobed/5e05941354d0f491c33eea526ecb6851#file-before_kibana)

docker-compose.yaml file: [after\_kibana · GitHub](https://gist.github.com/harobed/5e05941354d0f491c33eea526ecb6851#file-docker-compose-yml)

```auto

```

---

<div class="post-metadata">

**Author:** ![klein\_stephane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/klein_stephane/32/11364_2.png) [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Post date:** [April 1, 2017, 3:02pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/16 "2017-04-01T15:02:32Z")

</div>

Same error with "official" images:

```auto
docker.elastic.co/elasticsearch/elasticsearch:5.3.0
docker.elastic.co/kibana/kibana:5.2.2

```

---

<div class="post-metadata">

**Author:** ![klein\_stephane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/klein_stephane/32/11364_2.png) [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Post date:** [April 2, 2017, 1:11pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/17 "2017-04-02T13:11:48Z")

</div>

You can test with this repository: [https://github.com/harobed/elk\_warning](https://github.com/harobed/elk_warning)

---

<div class="post-metadata">

**Author:** ![klein\_stephane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/klein_stephane/32/11364_2.png) [@klein\_stephane](https://discuss.elastic.co/u/klein_stephane)\
**Post date:** [April 2, 2017, 1:14pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/18 "2017-04-02T13:14:29Z")

</div>

I have created this issue: [https://github.com/elastic/kibana/issues/10993](https://github.com/elastic/kibana/issues/10993)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2017, 1:14pm UTC](https://discuss.elastic.co/t/warn-o-e-d-i-m-mapperservice-unmapped-type-string-should-be-replaced-with-unmapped-type-keyword/79948/19 "2017-04-30T13:14:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
