# Could not index event to Elasticsearch

**URL:** <https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/291397>\
**Category:** Logstash\
**Created:** [December 10, 2021, 8:10am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/291397 "2021-12-10T08:10:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bropid](https://avatars.discourse-cdn.com/v4/letter/b/f04885/32.png) [@bropid](https://discuss.elastic.co/u/bropid)\
**Post date:** [December 10, 2021, 8:10am UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/291397/1 "2021-12-10T08:10:09Z")

</div>

Hi, i'm try to parse the ngfw event with logstash in tcp port 5000 to Elasticsearch but the logstash-plain.log always said:

`"status"=>400, "error"=>{"type"=>"ma pper_parsing_exception", "reason"=>"object mapping for [host] tried to parse fie ld [host] as object, but found a concrete value"`

my logstash config is:

```auto
input {
        tcp {
                port => 5000
                codec => cef {
                delimiter => "\n"
                ecs_compatibility => v1
           }
        }
}

output {
        elasticsearch {
                hosts => "<my ip>:9200"
                user => "elastic"
                password => "<mypass>"
                index => "ngfw"
                ecs_compatibility => disabled
        }
}

```

What should i do to make the event show in kibana?

---

<div class="post-metadata">

**Author:** ![bropid](https://avatars.discourse-cdn.com/v4/letter/b/f04885/32.png) [@bropid](https://discuss.elastic.co/u/bropid)\
**Post date:** [December 10, 2021, 12:01pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/291397/2 "2021-12-10T12:01:48Z")

</div>

This is the example on of the logs:

`[2021-12-10T11:18:05,919][WARN][logstash.outputs.elasticsearch][main][191a48d708ce268260e394dcd10fa3216c216c4b3e54757d7b36c439b470dd20] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"ngfw", :routing=>nil}, {"observer"=>{"name"=>"xx node 1", "ip"=>"xx", "product"=>"Firewall", "version"=>"6.9.0", "vendor"=>"xx", "ingress"=>{"interface"=>{"name"=>"12"}}, "hostname"=>"xx"}, "destination"=>{"ip"=>"xx", "port"=>"62912"}, "source"=>{"ip"=>"xx", "port"=>"21694"}, "host"=>"xx", "@version"=>"1", "@timestamp"=>2021-12-10T18:18:03.000Z, "port"=>36616, "log"=>{"syslog"=>{"facility"=>{"code"=>"Packet Filtering"}}}, "cef"=>{"name"=>"Connection_Discarded", "version"=>"<6>CEF:0", "device_custom_string_1"=>{"label"=>"RuleID", "value"=>"21.0"}}, "network"=>{"protocol"=>"UDP/62912", "transport"=>"17"}, "event"=>{"action"=>"Discard", "severity"=>"0", "code"=>"70019"}}], :response=>{"index"=>{"_index"=>"ngfw", "_type"=>"_doc", "_id"=>"lO8QpH0Bx0dBNubZhZ1Z", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [host] tried to parse field [host] as object, but found a concrete value"}}}}`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 10, 2021, 4:53pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/291397/3 "2021-12-10T16:53:15Z")

</div>

> [@bropid](#):
>
> ma pper\_parsing\_exception

See [this](https://discuss.elastic.co/t/getting-illegal-state-exception-error-while-pushing-logs-to-elasticsearch/290029/2) post.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2022, 4:53pm UTC](https://discuss.elastic.co/t/could-not-index-event-to-elasticsearch/291397/4 "2022-01-07T16:53:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
