# Elasticsearch IllegalArgumentException

**URL:** <https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942>\
**Category:** Elasticsearch\
**Created:** [April 11, 2016, 5:40am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942 "2016-04-11T05:40:05Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![suhae](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@suhae](https://discuss.elastic.co/u/suhae)\
**Post date:** [April 11, 2016, 5:40am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/1 "2016-04-11T05:40:06Z")

</div>

Hello.

I am new to Elasticsearch. i am using Fluentd, Elasticsearch, Kibana.

my Fluentd configuration :

`<source>`  
type tail  
path /var/log/access/assets.access/\*  
pos\_file /var/log/access/assets.access/readlog.pos  
read\_from\_head true  
format multiline  
format nginx  
tag assets.access  
time\_format %d/%b/%Y:%H:%M:%S %z  
keep\_time\_key true  
`</source>`

`<match assets.access>`  
type elasticsearch  
host 192.168.1.32  
port 9200  
index\_name assets.access  
type\_name access  
flush\_interval 10s  
format json  
`</match>`

and Elasticsearch Index mapping like this :

curl -XPOST 'elastic.local:9200/assets.access' -d '  
{  
"mappings":{  
"assets.access":{  
"properties":{  
"time":{  
"type":"date",  
"format": "dd/MMM/yyyy:HH:mm:ss Z"  
}  
}  
}  
}  
}'

Index mapping and fluentd configuration generated no error.  
but in the process of inserting document to index, i got this error :

Suppressed: MapperParsingException[failed to parse [time]]; nested: IllegalArgumentException[Invalid format: "28/Mar/2016:15:03:49 +0900" is malformed at "/Mar/2016:15:03:49 +0900"];

In a different way,  
i configure fluentd like this :

`<source>`  
type tail  
path /var/log/access/assets.access/\*  
pos\_file /var/log/access/assets.access/readlog.pos  
read\_from\_head true  
format multiline  
format nginx  
tag sample  
`</source>`

`<filter **>`  
type record\_transformer  
`<record>`  
date ${time}  
`</record>`  
`</filter>`

`<match sample>`  
type record\_reformer  
output\_tag assets.access  
date ${time.strftime('%Y-%m-%d %H:%M:%S %z')}  
`</match>`

`<match assets.access>`  
type elasticsearch  
host 192.168.1.32  
port 9200  
index\_name assets.access  
type\_name access  
flush\_interval 10s  
format json  
`</match>`

and Elasticsearch Index mapping :

curl -XPOST 'elastic.local:9200/assets.access' -d '  
{  
"mappings":{  
"assets.access":{  
"properties":{  
"date":{  
"type":"date",  
"format": "yyyy-MM-dd HH:mm:ss Z"  
}  
}  
}  
}  
}'

and i got this error :  
MapperParsingException[failed to parse [date]]; nested: IllegalArgumentException[Invalid format: "2016-04-05 15:50:47 +0900" is malformed at " 15:50:47 +0900"];

why this error happened?  
thanks.

---

<div class="post-metadata">

**Author:** ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)\
**Post date:** [April 12, 2016, 8:44am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/2 "2016-04-12T08:44:18Z")

</div>

Hi,

with the data you post it is not exactly to tell but you definitely have a wrong mapping. A mapping is valid for an index and a type The index name is "assets.access" in your FluentD configuration and in your Elasticsearch config. But the type name is called "access" in FluentD and once again "assets.access" in Elasticsearch. This is definitely wrong.

The mapping that matches your FluentD configuration is:

```auto
POST /assets.access
{
   "mappings": {
      "access": {
         "properties": {
            "date": {
               "type": "date",
               "format": "yyyy-MM-dd HH:mm:ss Z"
            }
         }
      }
   }
}

```

Note that the element below "mappings" is called "access" which matches your FluentD configuration. I have chosen the date pattern from the second example.

Also note that the mapping for a field named "foo" must be identical for all types within an index so I suggest you delete the index entirely (just issue `DELETE /assets.access`) and start from scratch with the mapping above (assuming that you are on a test system).

Daniel

---

<div class="post-metadata">

**Author:** ![suhae](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@suhae](https://discuss.elastic.co/u/suhae)\
**Post date:** [April 14, 2016, 3:21am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/3 "2016-04-14T03:21:10Z")

</div>

Hi danielmitterdorfer, Thank you for answering this topic.  
i try it, define Index\_name as assets.access and type\_name as access, mapping as you suggested.  
then logs insert to elasticsearch with no error and creating index in Kibana work fine.

but Discover tab shows 0hits, No results found.  
and get this error  
[logstash-\*] IndexNotFoundException[no such index]

i don't understand why kibana cannot find index that already create one in Kibana.

---

<div class="post-metadata">

**Author:** ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)\
**Post date:** [April 14, 2016, 4:19am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/4 "2016-04-14T04:19:06Z")

</div>

Hi,

Kibana needs to know at which indices it show look. It assumes that is used together with Logstash by default. So I think you just need to configure another index pattern as default in the "Settings" tab that matches your index name (which is "assets.access").

Daniel

---

<div class="post-metadata">

**Author:** ![suhae](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@suhae](https://discuss.elastic.co/u/suhae)\
**Post date:** [April 14, 2016, 5:05am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/5 "2016-04-14T05:05:27Z")

</div>

is that mean matching Index pattern as "assets.access"?  
i had configured index pattern to same as Index name when create Index.(exclude using logstash\_format)

that is,  
i configured index pattern as assets.access and created.  
also assets.access lists every field (in Settings -\> Indices).  
nevertheless occured that error.

thank you

---

<div class="post-metadata">

**Author:** ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)\
**Post date:** [April 14, 2016, 6:11am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/6 "2016-04-14T06:11:09Z")

</div>

Hi,

do you mind sharing a screenshot of your "Settings" and your "Discover" tabs?

Daniel

---

<div class="post-metadata">

**Author:** ![suhae](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@suhae](https://discuss.elastic.co/u/suhae)\
**Post date:** [April 14, 2016, 6:26am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/7 "2016-04-14T06:26:24Z")

</div>

Hi Daniel, Thanks for Your Patience.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/220e60bf9316c5d5403174f64fd8e36499910311.png)  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/8/834a35c97154790c1f69706cf3d1301de2b82302.png)  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/c345c76abe68415b8186c9e53792e108b7dd1fc2.png)

---

<div class="post-metadata">

**Author:** ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)\
**Post date:** [April 14, 2016, 6:39am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/8 "2016-04-14T06:39:08Z")

</div>

Hi,

That looks ok so far. It just doesn't find any results in the "Discover" screen but the time range is rather short (last 15 minutes). What if you expand the time range to something like a year (see the dropdown in the upper right corner)

Daniel

---

<div class="post-metadata">

**Author:** ![suhae](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@suhae](https://discuss.elastic.co/u/suhae)\
**Post date:** [April 14, 2016, 6:45am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/9 "2016-04-14T06:45:45Z")

</div>

it still doesn't work..

 ![](https://us1.discourse-cdn.com/elastic/original/2X/c/cab7cd95c3fb34bc37dd85adc85e47d65f516311.png)

---

<div class="post-metadata">

**Author:** ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)\
**Post date:** [April 14, 2016, 7:03am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/10 "2016-04-14T07:03:29Z")

</div>

Hmm,

are there any data in Elasticsearch? What does this command (on the command line) return?

```auto
curl 'http://elastic.local:9200/assets.access/_search' -d '
{
    "query": {
        "match_all": {}
    }
}'

```

It shows you the first few documents and the total number of hits (which should be greater than zero).

Daniel

---

<div class="post-metadata">

**Author:** ![suhae](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@suhae](https://discuss.elastic.co/u/suhae)\
**Post date:** [April 14, 2016, 7:14am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/11 "2016-04-14T07:14:00Z")

</div>

this is in ElasticHQ

 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/b9b9fe64e677302e4e1229d597507232c09a0b7e.png)

and your command results :  
{"took":1,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":117,"max\_score":1.0,"hits":[{"\_index":"assets.access","\_type":"access","\_id":"AVQTau4b5xT2ZO9Ht133","\_score":1.0,"\_source":{ ...

it is working correct. but why kibana occured error..?

thank you

---

<div class="post-metadata">

**Author:** ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)\
**Post date:** [April 15, 2016, 10:28am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/12 "2016-04-15T10:28:38Z")

</div>

Hi,

you stopped at the most interesting part, namely the query result. 😉 Can you please share a few of the results? What could happen is that the date format is different from what Kibana expects and that's why it does not find anything.

Daniel

---

<div class="post-metadata">

**Author:** ![suhae](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@suhae](https://discuss.elastic.co/u/suhae)\
**Post date:** [April 18, 2016, 3:00am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/14 "2016-04-18T03:00:02Z")

</div>

Hi Daniel!

...i look into the result again, there are no date field!  
but logs contain time contents ([15/Mar/2016:16:21:58 +0900])

results:  
{"took":1,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":117,"max\_score":1.0,"hits":[{"\_index":"assets.access","\_type":"access","\_id":"AVQTau4b5xT2ZO9Ht133","\_score":1.0,"\_source":{"remote":"192.168.1.1","host":"-","user":"-","method":"GET","path":"/favicon.ico","code":"401","size":"605","referer":"-","agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10\_11\_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36"}},{"\_index":"assets.access","\_type":"access","\_id":"AVQTau4b5xT2ZO9Ht135","\_score":1.0,"\_source":{"remote":"192.168.1.1","host":"-","user":"-","method":"GET","path":"/favicon.ico","code":"401","size":"605","referer":"-","agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10\_11\_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36"}},{"\_index":"assets.access","\_type":"access","\_id":"AVQTau4b5xT2ZO9Ht14A","\_score":1.0,"\_source":{"remote":"192.168.1.1","host":"-","user":"-","method":"GET","path":"/public/

just to be sure, Providing fluentd plugin manual,  
"Parser removes time field from event record by default. If you want to keep time field in record, set true to keep\_time\_key. Default is false."

so, then add the "keep\_time\_key true" in fluentd config file,  
results:  
,{"\_index":"assets.access","\_type":"access","\_id":"AVQnE6AH2yWbZbMVF9R9","\_score":1.0,"\_source":{"remote":"192.168.1.1","host":"-","user":"-","time":"16/Mar/2016:15:37:48 +0900","method":"GET","path":"/public/data\_enc.zip.sha","code":"200","size":"55","referer":"-","agent":"Dalvik/2.1.0 (Linux; U; Android 5.0.1; LG-F320K Build/LRX21Y)"}},

this results aren't match the index mapping! (field name, time format)

Thank you.

---

<div class="post-metadata">

**Author:** ![suhae](https://avatars.discourse-cdn.com/v4/letter/s/7bcc69/32.png) [@suhae](https://discuss.elastic.co/u/suhae)\
**Post date:** [April 18, 2016, 3:07am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/15 "2016-04-18T03:07:48Z")

</div>

wow, after adding keep\_time\_key true and changing mapping(field name and time format), it works at kibana!  
thank you Daniel!😄

---

<div class="post-metadata">

**Author:** ![danielmitterdorfer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmitterdorfer/32/110510_2.png) [@danielmitterdorfer](https://discuss.elastic.co/u/danielmitterdorfer)\
**Post date:** [April 18, 2016, 6:57am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/16 "2016-04-18T06:57:51Z")

</div>

Great it finally worked out. That was definitely tricky! 🙂

Daniel

---

<div class="post-metadata">

**Author:** ![ukoodali](https://avatars.discourse-cdn.com/v4/letter/u/898d66/32.png) [@ukoodali](https://discuss.elastic.co/u/ukoodali)\
**Post date:** [June 6, 2017, 12:40pm UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/17 "2017-06-06T12:40:05Z")

</div>

I have installed Kibana and elasticsearch; while starting kibana i am seeing the following error

[17:43:54.891] [error][status][plugin:elasticsearch] Status changed from green to red - [illegal\_argument\_exception] [field\_sort] unknown field [ignore\_unmapped], parser not found

Any idea how to fix this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 4:18am UTC](https://discuss.elastic.co/t/elasticsearch-illegalargumentexception/46942/18 "2022-11-04T04:18:21Z")

</div>


