# Could not index event to Elasticsearch reason failed to parse field \[rule\] of type \[text\] in document

**URL:** <https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-failed-to-parse-field-rule-of-type-text-in-document/207470>\
**Category:** Logstash\
**Created:** [November 12, 2019, 9:12am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-failed-to-parse-field-rule-of-type-text-in-document/207470 "2019-11-12T09:12:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nghia\_huynh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nghia_huynh/32/54189_2.png) [@nghia\_huynh](https://discuss.elastic.co/u/nghia_huynh)\
**Post date:** [November 12, 2019, 9:12am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-failed-to-parse-field-rule-of-type-text-in-document/207470/1 "2019-11-12T09:12:49Z")

</div>

Hi everyone,

Today, I check log from logstash-plain.log and I see many event was spam from one error like that:

`[2019-11-12T16:03:53,696][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"pfsense-2019.11.12", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0x2ee2f488>], :response=>{"index"=>{"_index"=>"pfsense-2019.11.12", "_type"=>"_doc", "_id"=>"fI7aXm4BoRxUhT6C4-Ah", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [rule] of type [text] in document with id 'fI7aXm4BoRxUhT6C4-Ah'. Preview of field's value: '{firedtimes=89, level=1, groups=[syslog, errors], comment=Unknown problem somewhere in the system., sidid=1002}'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:270"}}}}}`

`[2019-11-12T16:03:53,696][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"pfsense-2019.11.12", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0x5bcd95a7>], :response=>{"index"=>{"_index"=>"pfsense-2019.11.12", "_type"=>"_doc", "_id"=>"fY7aXm4BoRxUhT6C4-Ah", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [rule] of type [text] in document with id 'fY7aXm4BoRxUhT6C4-Ah'. Preview of field's value: '{firedtimes=30, level=1, groups=[local, syslog], comment=Multi Unknown problem somewhere in the system, sidid=100037, frequency=2}'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:270"}}}}}`

`[2019-11-12T16:03:53,697][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"pfsense-2019.11.12", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0x739b5fd4>], :response=>{"index"=>{"_index"=>"pfsense-2019.11.12", "_type"=>"_doc", "_id"=>"fo7aXm4BoRxUhT6C4-Ah", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [rule] of type [text] in document with id 'fo7aXm4BoRxUhT6C4-Ah'. Preview of field's value: '{firedtimes=94, level=1, groups=[syslog, errors], comment=Unknown problem somewhere in the system., sidid=1002}'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:270"}}}}}`

`[2019-11-12T16:03:53,697][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"pfsense-2019.11.12", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0xc7ba976>], :response=>{"index"=>{"_index"=>"pfsense-2019.11.12", "_type"=>"_doc", "_id"=>"f47aXm4BoRxUhT6C4-Ah", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [rule] of type [text] in document with id 'f47aXm4BoRxUhT6C4-Ah'. Preview of field's value: '{firedtimes=96, level=1, groups=[syslog, errors], comment=Unknown problem somewhere in the system., sidid=1002}'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:270"}}}}}`

My logstash version: 7.3.1  
Please help me to clarify where is bug and how to debug.  
I'm looking forward to hearing from you soon

---

<div class="post-metadata">

**Author:** ![nuwancs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nuwancs/32/46419_2.png) [@nuwancs](https://discuss.elastic.co/u/nuwancs)\
**Post date:** [November 12, 2019, 11:25am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-failed-to-parse-field-rule-of-type-text-in-document/207470/2 "2019-11-12T11:25:38Z")

</div>

@nghia_huynh check what are you sending to [rule] field. probably it's null!  
That's why you are getting `mapper_parsing_exception` exception.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 10, 2019, 11:25am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch-reason-failed-to-parse-field-rule-of-type-text-in-document/207470/3 "2019-12-10T11:25:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
