# Error in elasticsearch filter of logstash: Failed to query elasticsearch for previous event

**URL:** <https://discuss.elastic.co/t/error-in-elasticsearch-filter-of-logstash-failed-to-query-elasticsearch-for-previous-event/256686>\
**Category:** Logstash\
**Created:** [November 25, 2020, 4:19pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-filter-of-logstash-failed-to-query-elasticsearch-for-previous-event/256686 "2020-11-25T16:19:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vita\_Rosenberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vita_rosenberg/32/77149_2.png) [@Vita\_Rosenberg](https://discuss.elastic.co/u/Vita_Rosenberg)\
**Post date:** [November 25, 2020, 4:19pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-filter-of-logstash-failed-to-query-elasticsearch-for-previous-event/256686/1 "2020-11-25T16:19:04Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d35410a5fa4c95aafa8c3c95514e715c4f22ba3.png)

Hello.  
I have an index in kibana called poc1\*, it contains fields of machineId and timestamp  
I need to get from that index a maximum value of timestamp to a new index for each machineId (which is deviceId in sql).  
It is working if I specify a certain machine (ma1). But when trying to join machineId to deviceId it fails with - Failed to query elasticsearch for previous event.  
Any ideas? What am I doing wrong?

this is the full error log:

```auto
 [3fc577f9e5c3f1bffc1199cd5f29ecdcd345d10b38736973b643f854c440f086] Failed to query elasticsearch for previous event {:index=>"poc1-2020.11.25", :error=>"[400] {\"error\":{\"root_cause\":[{\"type\":\"query_shard_exception\",\"reason\":\"Failed to parse query [MachineId:%{[deviceId]}]\",\"index_uuid\":\"-hEaWnQ-ThOunikXCMS9cg\",\"index\":\"poc1-2020.11.25\"}],\"type\":\"search_phase_execution_exception\",\"reason\":\"all shards failed\",\"phase\":\"query\",\"grouped\":true,\"failed_shards\":[{\"shard\":0,\"index\":\"poc1-2020.11.25\",\"node\":\"p9GnWMV3RGiiE9AUHRD5Qg\",\"reason\":{\"type\":\"query_shard_exception\",\"reason\":\"Failed to parse query [MachineId:%{[deviceId]}]\",\"index_uuid\":\"-hEaWnQ-ThOunikXCMS9cg\",\"index\":\"poc1-2020.11.25\",\"caused_by\":{\"type\":\"parse_exception\",\"reason\":\"Cannot parse 'MachineId:%{[deviceId]}': Encountered \\\" \\\"]\\\" \\\"] \\\"\\\" at line 1, column 21.\\nWas expecting:\\n \\\"TO\\\" ...\\n \",\"caused_by\":{\"type\":\"parse_exception\",\"reason\":\"Encountered \\\" \\\"]\\\" \\\"] \\\"\\\" at line 1, column 21.\\nWas expecting:\\n \\\"TO\\\" ...\\n \"}}}}]},\"status\":400}"}

```

Thanks.

---

<div class="post-metadata">

**Author:** ![tbennett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbennett/32/80304_2.png) [@tbennett](https://discuss.elastic.co/u/tbennett)\
**Post date:** [December 4, 2020, 11:05pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-filter-of-logstash-failed-to-query-elasticsearch-for-previous-event/256686/2 "2020-12-04T23:05:25Z")

</div>

I'd love to get an answer as well. I'm experiencing the same issue.

```auto
query => "organization.id: %{[organization][id]}"

"reason":"parse_exception: Encountered \\" \\"]\\" \\"] \\"\\" at line 1, column 31.\\nWas expecting:\\n \\"TO\\" ...\\n "

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 5, 2020, 1:16am UTC](https://discuss.elastic.co/t/error-in-elasticsearch-filter-of-logstash-failed-to-query-elasticsearch-for-previous-event/256686/3 "2020-12-05T01:16:21Z")

</div>

> [@Vita\_Rosenberg](#):
>
> "reason":"Failed to parse query [MachineId:%{[deviceId]}]",

The elasticsearch filter [does](https://github.com/logstash-plugins/logstash-filter-elasticsearch/blob/03e1277a285d46de3f4283701beb84456287d959/lib/logstash/filters/elasticsearch.rb#L129) process sprintf references in the query option. If it does not get processed it is telling you that that event does not have a [deviceId] field.

---

<div class="post-metadata">

**Author:** ![Vita\_Rosenberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vita_rosenberg/32/77149_2.png) [@Vita\_Rosenberg](https://discuss.elastic.co/u/Vita_Rosenberg)\
**Post date:** [December 5, 2020, 4:45pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-filter-of-logstash-failed-to-query-elasticsearch-for-previous-event/256686/4 "2020-12-05T16:45:16Z")

</div>

Hi.  
I solved mine. It never worked with the query. Though i did manage to make this work with a query\_template.json. Please show me your full code, maybe I can help you as well..

---

<div class="post-metadata">

**Author:** ![tbennett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbennett/32/80304_2.png) [@tbennett](https://discuss.elastic.co/u/tbennett)\
**Post date:** [December 11, 2020, 1:10am UTC](https://discuss.elastic.co/t/error-in-elasticsearch-filter-of-logstash-failed-to-query-elasticsearch-for-previous-event/256686/6 "2020-12-11T01:10:01Z")

</div>

I did try it without the sprintf references just in case, but that didn't appear to make a difference; which would make sense.

I think what got me on mine was, for debugging purposes I added an output to file plugin immediately after that, but I guess that plugin was not catching it until all the other filters were processed. So the output of my output plugin for debugging did not match the actual event itself.

specifically [organization][id] did not exist at that point, setting the debug level high enough to log the event as it crossed the pipeline showed the field had a different name [orgid].

---

<div class="post-metadata">

**Author:** ![tbennett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbennett/32/80304_2.png) [@tbennett](https://discuss.elastic.co/u/tbennett)\
**Post date:** [December 11, 2020, 1:11am UTC](https://discuss.elastic.co/t/error-in-elasticsearch-filter-of-logstash-failed-to-query-elasticsearch-for-previous-event/256686/7 "2020-12-11T01:11:20Z")

</div>

I suspect your events did not have [deviceId], as that's what my own debugging lead me to believe for my situation

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2021, 1:11am UTC](https://discuss.elastic.co/t/error-in-elasticsearch-filter-of-logstash-failed-to-query-elasticsearch-for-previous-event/256686/8 "2021-01-08T01:11:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
