# Error in parsing some logs from firewall due to object being returned

**URL:** <https://discuss.elastic.co/t/error-in-parsing-some-logs-from-firewall-due-to-object-being-returned/328349>\
**Category:** Logstash\
**Created:** [March 23, 2023, 12:45pm UTC](https://discuss.elastic.co/t/error-in-parsing-some-logs-from-firewall-due-to-object-being-returned/328349 "2023-03-23T12:45:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![viera120](https://avatars.discourse-cdn.com/v4/letter/v/74df32/32.png) [@viera120](https://discuss.elastic.co/u/viera120)\
**Post date:** [March 23, 2023, 12:45pm UTC](https://discuss.elastic.co/t/error-in-parsing-some-logs-from-firewall-due-to-object-being-returned/328349/1 "2023-03-23T12:45:17Z")

</div>

Hi all,

The setup is:

`Firewall --> Filebeat --> Logstash --> Elasticsearch`

The following error keeps appearing in `/var/log/logstash/logstash-plain.log`

`[2023-03-23T18:03:53,651][WARN][logstash.outputs.elasticsearch][main][96d3f1a45a0ecad7c0b459780eeece72a47c0655a8a6ffc6c49e0f8255fc9ec6] Could not index event to Elasticsearch. status: 400, action: ["index", {:_id=>nil, :_index=>"firewall", :routing=>nil}, {"reason"=>"file-size", "action"=>"roll-log", "level"=>"notice", "type"=>"event", "@timestamp"=>2023-03-23T12:33:44.000Z, "logdesc"=>"Disk log rolled", "msg"=>"\"Disk", "eventtime"=>"1679574823731437365", "devname"=>"FORTIGATE", "subtype"=>"system", "log"=>"tlog", **"service"=>{"type"=>"fortinet"}** }], response: {"index"=>{"_index"=>"firewall-2023.03.23", "_id"=>"Q1d2DocBJN2GzK3gGZMP", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [service_] of type [text] in document with id 'Q1d2DocBJN2GzK3gGZMP'. **Preview of field's value: '{type=fortinet}**'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:277"}}}}`

The filters in the logstash conf file are:

```auto
filter
{
  grok
  {
    match => {"message" => "%{SYSLOG5424PRI}%{GREEDYDATA:message}"}
    overwrite => ["message"]
  }

  mutate
  {
    remove_field => ["@timestamp","agent","input","event","fileset","tags","ecs","log","source","@version"]
  }
  kv
  {
    field_split => " "
  }
  mutate
  {
    remove_field => ["message"]
    add_field => { "logdate" => "%{date} %{time}" }
  }
  date
  {
    match => ["logdate", "yyyy-MM-dd HH:mm:ss"]
    timezone => "Asia/Kolkata"
    target => "@timestamp"
  }
}

```

The field **service =\> "{"type"=\>"fortinet"}"** appears to be the reason for the error, i am unable identify the source of this field with this particular value in the logs. This is because the firewall's logs reference does not have mention of such a field with this particular value. The raw log from the firewall doesn't have it either.

How can this be resolved?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 23, 2023, 3:57pm UTC](https://discuss.elastic.co/t/error-in-parsing-some-logs-from-firewall-due-to-object-being-returned/328349/2 "2023-03-23T15:57:57Z")

</div>

> [@viera120](#):
>
> How can this be resolved?

[This](https://discuss.elastic.co/t/getting-illegal-state-exception-error-while-pushing-logs-to-elasticsearch/290029/2) answer discusses the issue and possible solutions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2023, 3:58pm UTC](https://discuss.elastic.co/t/error-in-parsing-some-logs-from-firewall-due-to-object-being-returned/328349/3 "2023-04-20T15:58:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
