# Cannot index event when using output pipeline definition

**URL:** <https://discuss.elastic.co/t/cannot-index-event-when-using-output-pipeline-definition/260822>\
**Category:** Beats\
**Tags:** filebeat, ingest-pipeline\
**Created:** [January 12, 2021, 11:03am UTC](https://discuss.elastic.co/t/cannot-index-event-when-using-output-pipeline-definition/260822 "2021-01-12T11:03:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![subsonnic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/subsonnic/32/77845_2.png) [@subsonnic](https://discuss.elastic.co/u/subsonnic)\
**Post date:** [January 12, 2021, 11:03am UTC](https://discuss.elastic.co/t/cannot-index-event-when-using-output-pipeline-definition/260822/1 "2021-01-12T11:03:09Z")

</div>

Hi,

I am using filebeat/elasticsearch/kibana 7.10.0.  
My filebeat runs on Kubernetes.

When I activate my ingest pipeline in my filebeat output config it runs into errors on client side. But if I test one event in my pipeline definition in kibana it is processed as expected.

```
output.elasticsearch:
  hosts: ['${ELASTICSEARCH_HOST:elasticsearch}:${ELASTICSEARCH_PORT:9200}']
  username: ${FILEBEAT_USERNAME}
  password: ${FILEBEAT_PASSWORD}
  pipelines:
    - pipeline: gloo
      when.equals:
        kubernetes.namespace: gloo

```

The Error:

> Cannot index event publisher.Event{...}..."caused\_by":{"type":"illegal\_state\_exception","reason":"Can't get text on a START\_OBJECT at 1:874"}

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [January 12, 2021, 6:35pm UTC](https://discuss.elastic.co/t/cannot-index-event-when-using-output-pipeline-definition/260822/2 "2021-01-12T18:35:56Z")

</div>

Hey @subsonnic, welcome to discuss 🙂

If the pipeline works, but the event cannot be indexed, there may be a problem with the mapping. The pipeline may be trying to store some value in a field with an incompatible datatype. For example it could be that the event includes an object in a field that is expected to be a string.

Do the error show the specific field producing this failure?

---

<div class="post-metadata">

**Author:** ![subsonnic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/subsonnic/32/77845_2.png) [@subsonnic](https://discuss.elastic.co/u/subsonnic)\
**Post date:** [January 13, 2021, 3:57am UTC](https://discuss.elastic.co/t/cannot-index-event-when-using-output-pipeline-definition/260822/3 "2021-01-13T03:57:46Z")

</div>

Not directly. But what I try to do is to replace the message field by the structured fields. Maybe that is the problem and I cannot do it because its not a seperate index for only gloo and there are other event logs which are not processed and store the message value as it is (filebeat, string) so I cannot change the maping type for it.

```
[
  {
    "json": {
      "field": "message",
      "if": "ctx.kubernetes.namespace == \"gloo\""
    }
  }
]

```

I changed it to

```
{
  "json": {
    "field": "message",
    "target_field": "gloo",
    "if": "ctx.kubernetes.namespace==\"gloo\""
  }
}

```

After the change I see another error

> {"type":"illegal\_argument\_exception","reason":"com.fasterxml.jackson.core.JsonParseException: Unexpected character ('.' (code 46)): Expected space separating root-level values...}

But the try run still works

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [January 13, 2021, 10:10am UTC](https://discuss.elastic.co/t/cannot-index-event-when-using-output-pipeline-definition/260822/4 "2021-01-13T10:10:45Z")

</div>

> [@subsonnic](#):
>
> {"type":"illegal\_argument\_exception","reason":"com.fasterxml.jackson.core.JsonParseException: Unexpected character ('.' (code 46)): Expected space separating root-level values...}

This seems to indicate that there is something that doesn't parse as JSON.

Is it possible that some of the lines of your gloo service are not JSON? Or that filebeat is splitting some of its JSON in multiple lines?

Do you have an example of document that works in the pipeline simulator, but doesn't seem to work when sent by filebeat?

You can also try to do this json parsing in the filebeat side, using the [`decode_json` processor](https://www.elastic.co/guide/en/beats/filebeat/7.10/decode-json-fields.html).

---

<div class="post-metadata">

**Author:** ![subsonnic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/subsonnic/32/77845_2.png) [@subsonnic](https://discuss.elastic.co/u/subsonnic)\
**Post date:** [January 14, 2021, 2:25am UTC](https://discuss.elastic.co/t/cannot-index-event-when-using-output-pipeline-definition/260822/5 "2021-01-14T02:25:51Z")

</div>

Ah thanks. It was really possible. Now its working for just a subset of pods inside the namespace. There are sometimes events logged by an 3rd party pod not maintained by gloo itself. I will build more seperated and more specified pipelines.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2021, 4:25am UTC](https://discuss.elastic.co/t/cannot-index-event-when-using-output-pipeline-definition/260822/6 "2021-02-11T04:25:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
