Please do not ping people not already involved in the issue. This forum is manned by volunteers, so please be patient and wait for someone to respond.
This has nothing to do with grok, but rather the structure of your document. Elasticsearch requires that every field has a single mapping, and you have a field name state that in different parts of the document contains a concrete value and in others an object. This is not allowed, so you need to change the structure.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.