[2021-01-10T15:02:28,890][WARN ][logstash.outputs.elasticsearch][main][62fa879f9cb3d6d767fe396c109c26137c7dc5006c2178486e9ce8686fcd58c5] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"filebeat-7.10.1", :routing=>nil, :_type=>"_doc"}, #LogStash::Event:0x2f050055], :response=>{"index"=>{"_index"=>"filebeat-7.10.1-2020.12.24-000001", "_type"=>"_doc", "_id"=>"wjmI63YBHDLDNbTjU-Dc", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [txnDateTime] of type [keyword] in document with id 'wjmI63YBHDLDNbTjU-Dc'. Preview of field's value: '{date={month=1, year=2021, day=7}, time={hour=10, nano=0, minute=23, second=1}}'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:478"}}}}}
Please format your code/logs/config using the </> button, or markdown style back ticks. It helps to make things easy to read which helps us help you
Specficially Preview of field's value: '{date={month=1, year=2021, day=7}, time={hour=10, nano=0, minute=23, second=1 is not valid for that field type. You need to find what is generating this and fix it.
Thanks for reply.
First time logs format was wrong. Now I logs format json type. All logs better now. But not show index. cause preview logs format was wrong. How can upgrade fields format so that any logs not lose.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.