When trying to add a timeline via add_timeline.py I am getting the following exception:
Traceback (most recent call last):
File "/var/www/timesketch/utils/add_timeline.py", line 113, in
sys.exit(main())
File "/var/www/timesketch/utils/add_timeline.py", line 92, in main
elasticsearch.put_mapping(args.index, 'plaso_event', mapping)
File "/usr/local/lib/python2.7/dist-packages/pyelasticsearch/client.py", line 96, in decorate
return func(_args, query_params=query_params, *_kwargs)
File "/usr/local/lib/python2.7/dist-packages/pyelasticsearch/client.py", line 659, in put_mapping
query_params=query_params)
File "/usr/local/lib/python2.7/dist-packages/pyelasticsearch/client.py", line 254, in send_request
self._raise_exception(resp, prepped_response)
File "/usr/local/lib/python2.7/dist-packages/pyelasticsearch/client.py", line 269, in _raise_exception
raise error_class(response.status_code, error_message)
pyelasticsearch.exceptions.ElasticHttpError: (400, u'MergeMappingException[Merge failed with failures {[Cannot update path in _timestamp value. Value is datetime path in merged mapping is missing]}]')
I recently upgraded our ES instance from 1.2 to 1.4 not sure if that is a culprit or not. Previous additions to timesketch worked fine prior to the ES upgrade. Any suggestions?