# Blank message field

**URL:** <https://discuss.elastic.co/t/blank-message-field/244441>\
**Category:** Logstash\
**Created:** [August 10, 2020, 4:37pm UTC](https://discuss.elastic.co/t/blank-message-field/244441 "2020-08-10T16:37:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![matheus.santoro](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@matheus.santoro](https://discuss.elastic.co/u/matheus.santoro)\
**Post date:** [August 10, 2020, 4:37pm UTC](https://discuss.elastic.co/t/blank-message-field/244441/1 "2020-08-10T16:37:17Z")

</div>

Trying to create a simple, non-filtered pipeline, but Kibana shows the message field as blank  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e5d6f3a8088136fa251b907f982c2b85ebaeb143.png)

Pipeline conf is

```auto
input {
  tcp {
    port => 9600
    codec => json
    mode => server
  }
}
output {
  elasticsearch {
    hosts => ["localhost:9200"]
    index => "myindex"
  }
}

```

When starting Logstash the following message is displayed

```auto
[WARN] 2020-08-10 16:33:02.698 [[main]>worker0] elasticsearch - Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"myindex", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0xbba272>], :response=>{"index"=>{"_index"=>"myindex", "_type"=>"_doc", "_id"=>"oJs32XMBjyfMsZpZ2EjQ", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [message] tried to parse field [message] as object, but found a concrete value"}}}}

```

Other fields are being mapped, but I would like to see the full message as wel...

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 10, 2020, 5:20pm UTC](https://discuss.elastic.co/t/blank-message-field/244441/2 "2020-08-10T17:20:21Z")

</div>

Does [this](https://discuss.elastic.co/t/logstash-xml-input-configuration-for-multiple-documents/243119/2) help?

---

<div class="post-metadata">

**Author:** ![matheus.santoro](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@matheus.santoro](https://discuss.elastic.co/u/matheus.santoro)\
**Post date:** [August 10, 2020, 6:40pm UTC](https://discuss.elastic.co/t/blank-message-field/244441/3 "2020-08-10T18:40:32Z")

</div>

This is the mapping of the _message_ field:

```auto
      },
        "message" : {
          "properties" : {
            "someField" : {
              "type" : "text",
              "fields" : {
                "keyword" : {
                  "type" : "keyword",
                  "ignore_above" : 256
                }
              }
            }
          }
        },

```

Tried to change/add this mapping with

```auto
{
  "properties": {
    "message": {
      "type": "object"
    }
  }
}

```

My point is - I am missing some information on the fields ES is detecting, so I would like to see the full message. Am I in the right direction?

Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 10, 2020, 7:21pm UTC](https://discuss.elastic.co/t/blank-message-field/244441/4 "2020-08-10T19:21:19Z")

</div>

If I am reading that correctly then elasticsearch expects the field

```
[message][someField]

```

to exist. That makes [message] an object, not a string. You could try

```
if ![message][someField] { mutate { rename => { "message" => "originalMessage" } } }
```

---

<div class="post-metadata">

**Author:** ![matheus.santoro](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@matheus.santoro](https://discuss.elastic.co/u/matheus.santoro)\
**Post date:** [August 10, 2020, 9:12pm UTC](https://discuss.elastic.co/t/blank-message-field/244441/5 "2020-08-10T21:12:20Z")

</div>

Thanks @Badger after applying the filter you suggested, the messages are being displayed on the doc.

However, every line of this _message_ generates a new doc, instead of showing the full message in the same doc. Is there any way we can group these lines into a single message?

\*\* Edit: These docs share a common field, i.e. execution.execid - Is there a way to aggregate all messages into the same doc, based on this ID?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 10, 2020, 9:17pm UTC](https://discuss.elastic.co/t/blank-message-field/244441/6 "2020-08-10T21:17:23Z")

</div>

I have no idea why that could be happening, so no suggestions on how to fix it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2020, 9:17pm UTC](https://discuss.elastic.co/t/blank-message-field/244441/7 "2020-09-07T21:17:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
