# Error with indexing nested object (Elasticsearch 5.6)

**URL:** <https://discuss.elastic.co/t/error-with-indexing-nested-object-elasticsearch-5-6/182869>\
**Category:** Elasticsearch\
**Created:** [May 27, 2019, 9:08am UTC](https://discuss.elastic.co/t/error-with-indexing-nested-object-elasticsearch-5-6/182869 "2019-05-27T09:08:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sabdoul](https://avatars.discourse-cdn.com/v4/letter/s/74df32/32.png) [@sabdoul](https://discuss.elastic.co/u/sabdoul)\
**Post date:** [May 27, 2019, 9:08am UTC](https://discuss.elastic.co/t/error-with-indexing-nested-object-elasticsearch-5-6/182869/1 "2019-05-27T09:08:23Z")

</div>

Hello,  
I get an error (**logstash error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"object mapping [sender\_mail] can't be changed from nested to non-nested**) when I index a nested object field with logstash in Elasticsearch.  
Yet my mapping and the nested object field created from logstash are correct.  
Below my mapping:

```
PUT _template/mail 
{
	....
    "sender_mail": {
      "type": "nested",
      "properties": {
        "id": {
          "type": "integer"
        },
        "mail": {
          "type": "keyword",
          "ignore_above": 1024
        }
      }
    }
	....
 }

```

And the logstash code for creating my nested object field:

```
aggregate {
task_id => "%{mail_id}"
code => "
		if !event.get('sender_mail').nil? 
			map['sender_mail'] ||= []
			map['sender_mail'] << { 'mail' => event.get('mail'), 'id' => event.get('id') }
		end
}

```

And I get a nested object of this format with this code above:

```
"sender_mail": [
  {
   "id": "0",
    "mail": "xxx1@gmail.com"
 },
  {
   "id": "1",
   "mail": "xxx2@gmail.com"
  },
  {
  "id": "2",
  "mail": "xxx3@gmail.com"
  }
]

```

If I remove the field sender\_mail (nested object) in the mapping, the field is well created but not with the good datatype (nested):  
 ![Capture_nested](https://us1.discourse-cdn.com/elastic/original/3X/8/7/872478214d5698eafeb8e8c29e642c3d74f852e5.png)  
And in my mapping he creates me for the field nested object with this datatype by default :

```
.....
"sender_mail": {
"properties": {
"id": {
"type": "text",
"fields": {
  "keyword": {
	"type": "keyword",
	"ignore_above": 256
  }
}
},
"mail": {
"type": "text",
"fields": {
  "keyword": {
	"type": "keyword",
	"ignore_above": 256
    }
   }
  }
 }
},
.....

```

Which means that my sender\_mail field actually has the correct json format but why do I have this error when I put in my mapping the datatype nested with this syntax?

```
PUT _template/mail 
{
	....
    "sender_mail": {
      "type": "nested",
      "properties": {
        "id": {
          "type": "integer"
        },
        "mail": {
          "type": "keyword",
          "ignore_above": 1024
        }
      }
    }
	....
 }

```

Ps: I specify when I do tests manually with this same field recovered after indexing, I have no error so why by automating from ingestion logstash it does not work?

Thank you for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2019, 9:10am UTC](https://discuss.elastic.co/t/error-with-indexing-nested-object-elasticsearch-5-6/182869/2 "2019-06-24T09:10:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
