# What to be used instead of "type"

**URL:** <https://discuss.elastic.co/t/what-to-be-used-instead-of-type/204930>\
**Category:** Logstash\
**Created:** [October 23, 2019, 5:54pm UTC](https://discuss.elastic.co/t/what-to-be-used-instead-of-type/204930 "2019-10-23T17:54:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Senthil\_ak](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Post date:** [October 23, 2019, 5:54pm UTC](https://discuss.elastic.co/t/what-to-be-used-instead-of-type/204930/1 "2019-10-23T17:54:36Z")

</div>

Hi Team,  
I'm using type for separating the logs category, but in the logs file I am getting error (warning) message like below.

`[2019-10-22T14:48:01,104][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the`type`event field won't be used to determine the document _type {:es_version=>7}`

The document of logstash says to use the type for apache and other things.

[\_processing\_apache\_logs](https://www.elastic.co/guide/en/logstash/current/config-examples.html#_processing_apache_logs)

Below is the config snippet.

```
grep 'replace => { "type"' /etc/logstash/conf.d/logstash.conf
  mutate { replace => { "type" => "nginx_access" }}
  mutate { replace => { "type" => "apache_access" }}
  mutate { replace => { "type" => "sm_access" } }
  mutate { replace => { "type" => "smps_logs" }}
  mutate { replace => { "type" => "apigee_logs" }}

```

Let me know the correct way to categorize the logs.

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 23, 2019, 6:02pm UTC](https://discuss.elastic.co/t/what-to-be-used-instead-of-type/204930/2 "2019-10-23T18:02:17Z")

</div>

> [@Senthil\_ak](#):
>
> I'm using type for separating the logs category

If you are using it to separate the logstash processing you can continue to do so. If you want to suppress the warning then just rename it docType or something else.

If you want to use type to separate the documents in elasticsearch into different mapping types then you will not be able to do that in the future, because mapping types are [going away](https://www.elastic.co/guide/en/elasticsearch/reference/master/removal-of-types.html).

---

<div class="post-metadata">

**Author:** ![Senthil\_ak](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Post date:** [October 23, 2019, 6:08pm UTC](https://discuss.elastic.co/t/what-to-be-used-instead-of-type/204930/3 "2019-10-23T18:08:22Z")

</div>

I am just using this as to search in Kibana easily as each has different grok pattern in my logstash config. So i guess i put something like docType or use Tags ?  
Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 23, 2019, 6:22pm UTC](https://discuss.elastic.co/t/what-to-be-used-instead-of-type/204930/4 "2019-10-23T18:22:32Z")

</div>

> [@Senthil\_ak](#):
>
> So i guess i put something like docType or use Tags ?

Both good options.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2019, 6:22pm UTC](https://discuss.elastic.co/t/what-to-be-used-instead-of-type/204930/5 "2019-11-20T18:22:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
