# Can't create nested type in ElasticSearch from data out of Logstash

**URL:** <https://discuss.elastic.co/t/cant-create-nested-type-in-elasticsearch-from-data-out-of-logstash/89585>\
**Category:** Logstash\
**Created:** [June 15, 2017, 3:46pm UTC](https://discuss.elastic.co/t/cant-create-nested-type-in-elasticsearch-from-data-out-of-logstash/89585 "2017-06-15T15:46:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sesam](https://avatars.discourse-cdn.com/v4/letter/s/cab0a1/32.png) [@Sesam](https://discuss.elastic.co/u/Sesam)\
**Post date:** [June 15, 2017, 3:46pm UTC](https://discuss.elastic.co/t/cant-create-nested-type-in-elasticsearch-from-data-out-of-logstash/89585/1 "2017-06-15T15:46:11Z")

</div>

Hey guys,

im suffering with this Problem:

Using jdbc connected with SQL-Database.

**I want to achive this nested type in elasticsearch:**

```
   {
      "mappings": {
        "Units": {
          "properties": {
            "System": {
              "type": "nested",
              "properties": {
                "serialNumber": {
                  "type": "integer"
                },
                "name": {
                  "type": "string"
                }
              }
            }
          }
        }
      }
    }

```

**but if i try to do so via logstash i get this error:**

`[2017-06-15T17:42:33,556][WARN][logstash.outputs.elasticsearch] Failed action.{:status=>400, :action=>["index", {:_id=>nil, :_index=>"my_index", :_type=>"logs", :_routing=>nil}, 2017-06-15T15:42:33.334Z %{host} %{message}], :response=>{"index"=>{"_index"=>"my_index", "_type"=>"logs", "_id"=>"AVysa6BNpCeJ3dzt0jMB", "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"object mapping [System] can't be changed from nested to non-nested"}}}}`

**my configfile for Logstash is:**

```
input
{ 
	jdbc 
	{ 
	 //working fine
	} 
	
}
	filter{
		aggregate {
    task_id => "%{iddevice}"
    code => "
		 map['System'] ||={}
		map['System']['name'] = event.get('namesystem')
		map['System']['serialNumber'] = event.get('serialnumbersystem')
		map['System']['description'] = event.get('descriptionsystem')
		map['System']['typeid'] = event.get('systemtypeid')
		map['System']['SubSystem'] ||={}
		map['System']['SubSystem']['name'] = event.get('namesubsystem')
		map['System']['SubSystem']['description'] = event.get('descriptionsubsystem')
		map['System']['SubSystem']['serialNumber'] = event.get('serialnumbersubsystem')
		map['System']['SubSystem']['typeid'] = event.get('subsystemtypeid')
		map['System']['SubSystem']['Device']||={}
		map['System']['SubSystem']['Device']['name'] = event.get('namedevice')
		map['System']['SubSystem']['Device']['nameRaw'] = event.get('namedeviceraw')
		map['System']['SubSystem']['Device']['Values'] ||= []
		map['System']['SubSystem']['Device']['Values'] << { 'typeid' => event.get('devicetypeid'),
		'date' => event.get('datedevice'),
		'operatingTime' => event.get('operatingtimedevice')}
		  
    "
	push_previous_map_as_event => true
    timeout_tags => ['aggregated']
  }
  if "aggregated" not in [tags] {
    drop {}
  }
}
output
{
	stdout {
    		codec => rubydebug{
			metadata => false}
  	}
	elasticsearch {
		hosts => ["127.0.0.1"]
			index =>"my_index"
   	} 
}

```

If I dont use mappings for my Index the aggregated data is cleary not advertised as type of "nested".

Thanks for help.

---

<div class="post-metadata">

**Author:** ![Sesam](https://avatars.discourse-cdn.com/v4/letter/s/cab0a1/32.png) [@Sesam](https://discuss.elastic.co/u/Sesam)\
**Post date:** [June 15, 2017, 4:46pm UTC](https://discuss.elastic.co/t/cant-create-nested-type-in-elasticsearch-from-data-out-of-logstash/89585/2 "2017-06-15T16:46:04Z")

</div>

Helped myself out of this by changing "Units" to "logs" because logstash is creating an own mappingtype under the name "logs". Next question is how to find out of changing "logs" into something more meaningful. I think i can google that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2017, 4:46pm UTC](https://discuss.elastic.co/t/cant-create-nested-type-in-elasticsearch-from-data-out-of-logstash/89585/3 "2017-07-13T16:46:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
