# Can't merge a non object mapping ... with an object mapping ...but mapping still do not exists

**URL:** <https://discuss.elastic.co/t/cant-merge-a-non-object-mapping-with-an-object-mapping-but-mapping-still-do-not-exists/170446>\
**Category:** Logstash\
**Created:** [March 1, 2019, 7:06am UTC](https://discuss.elastic.co/t/cant-merge-a-non-object-mapping-with-an-object-mapping-but-mapping-still-do-not-exists/170446 "2019-03-01T07:06:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [March 1, 2019, 7:06am UTC](https://discuss.elastic.co/t/cant-merge-a-non-object-mapping-with-an-object-mapping-but-mapping-still-do-not-exists/170446/1 "2019-03-01T07:06:22Z")

</div>

Hi all,  
When parsing an XML, I have an error

"Can't merge a non object mapping [poc.ports.port.script.elem] with an object mapping [poc.ports.port.script.elem]"

Searching in the forum I found that the error appears when the document does not match the mapping in ES, but in my case mapping still do not exists.

How this is possible?  
Thank you!  
Regards  
Ana

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 1, 2019, 9:13am UTC](https://discuss.elastic.co/t/cant-merge-a-non-object-mapping-with-an-object-mapping-but-mapping-still-do-not-exists/170446/2 "2019-03-01T09:13:46Z")

</div>

If you have both occurrences in the same document you will get a mapping error when Elasticsearch tries to create mappings for it. What does the document look like?

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [March 1, 2019, 10:57am UTC](https://discuss.elastic.co/t/cant-merge-a-non-object-mapping-with-an-object-mapping-but-mapping-still-do-not-exists/170446/3 "2019-03-01T10:57:45Z")

</div>

Hi Christian,  
My document is a (simplified version) of an NMAP xml output.  
The problem is when try to parse the second script element in port 443, but I don't know how to solve it.

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/3/037ed6ea799ac83b204a1af88093da8132ebf9d6.png)

Thanks a lot!  
Regards  
Ana

LS Conf (Filter)

```
filter {

                xml { source => "message"
                        target => poc
                        xpath => ["host/address/@addr", ip]
                        xpath => ["host/status/@state", state]
                        xpath => ["host/status/@reason", reason]

                }

                if [message] =~ /^<host starttime/ {
                        split {
                                field => "[poc][ports][0][port]"
                        }
                }

                if [message] =~ /^<task/ {
                        drop { }
                }

}

```

Document

```
<host starttime="1551225720" endtime="1551226381"><status state="up" reason="syn-ack" reason_ttl="0"/>
<address addr="x.y95.165" addrtype="ipv4"/>
<hostnames>
<hostname name="static-x-y-95-165.domain" type="PTR"/>
</hostnames>
<ports><extraports state="filtered" count="65528">
<extrareasons reason="no-responses" count="65528"/>
</extraports>
<port protocol="tcp" portid="25"><state state="open" reason="syn-ack" reason_ttl="0"/><service name="smtp" product="Postfix smtpd" hostname=" FW_ENTERPRISE" method="probed" conf="10"><cpe>cpe:/a:postfix:postfix</cpe></service><script id="smtp-commands" output="FW_ENTERPRISE, SIZE, VRFY, ETRN, ENHANCEDSTATUSCODES, 8BITMIME, DSN, "/></port>
<port protocol="tcp" portid="80"><state state="open" reason="syn-ack" reason_ttl="0"/><service name="http" product="Check Point NGX Firewall-1" method="probed" conf="10"><cpe>cpe:/a:checkpoint:firewall-1</cpe></service></port>
<port protocol="tcp" portid="264"><state state="open" reason="syn-ack" reason_ttl="0"/><service name="fw1-topology" product="Check Point FireWall-1 Topology" devicetype="firewall" method="probed" conf="10"><cpe>cpe:/a:checkpoint:firewall-1</cpe></service></port>
<port protocol="tcp" portid="443"><state state="open" reason="syn-ack" reason_ttl="0"/><service name="http" product="Connectra Check Point Web Security httpd" devicetype="security-misc" tunnel="ssl" method="probed" conf="10"><cpe>cpe:/a:checkpoint:connectra</cpe></service>
<script id="http-methods" output="&#xa; Supported Methods: GET HEAD POST OPTIONS">
<table key="Supported Methods">
<elem>GET</elem>
<elem>HEAD</elem>
<elem>POST</elem>
<elem>OPTIONS</elem>
</table>
</script>
<script id="ssl-date" output="2019-02-27T00:12:30+00:00; -1s from scanner time.">
<elem key="date">2019-02-27T00:12:30+00:00</elem>
<elem key="delta">-1.0</elem>
</script>
</port>
<port protocol="tcp" portid="500"><state state="open" reason="syn-ack" reason_ttl="0"/><service name="isakmp" method="table" conf="3"/></port>
<port protocol="tcp" portid="15001"><state state="closed" reason="conn-refused" reason_ttl="0"/><service name="unknown" method="table" conf="3"/></port>
</ports>
</host>
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2019, 10:57am UTC](https://discuss.elastic.co/t/cant-merge-a-non-object-mapping-with-an-object-mapping-but-mapping-still-do-not-exists/170446/4 "2019-03-29T10:57:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
