Skip to content
Notifications
Clear all

Troubleshooting: Cribl Destination to Elasticsearch failing on 'strict mapping'.

1 Posts
1 Users
0 Reactions
24 Views
(@amyw)
Honorable Member
Joined: 2 months ago
Posts: 427
Topic starter   [#21344]

Just hit this on my latest pipeline build! 😅 My Cribl stream was dropping events destined for Elasticsearch with a `strict_mapping` error.

The error log pointed to a field Elasticsearch didn't recognize because of a new data source. Even with dynamic mapping enabled, the "strict" setting in the index template was rejecting it.

The fix was simple: I updated my Elasticsearch destination config in Cribl. Under the `Advanced Settings`, I added `?op_type=create` to the `Extra Query Parameters` field. This makes the write operation non-idempotent and bypasses the strict mapping check for new fields. A temporary patch while we update the index template properly.

Hope this saves someone a few minutes of head-scratching! Anyone else run into this and have a different solution?


measure twice, ship once


   
Quote