# Failed to parse field \[host\] of type \[text\] .. can't get text on a START\_OBJECT at 1:974

**URL:** <https://discuss.elastic.co/t/failed-to-parse-field-host-of-type-text-cant-get-text-on-a-start-object-at-1-974/235221>\
**Category:** Logstash\
**Tags:** beats-module\
**Created:** [June 1, 2020, 7:06pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-host-of-type-text-cant-get-text-on-a-start-object-at-1-974/235221 "2020-06-01T19:06:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mskadu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mskadu/32/69520_2.png) [@mskadu](https://discuss.elastic.co/u/mskadu)\
**Post date:** [June 1, 2020, 7:06pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-host-of-type-text-cant-get-text-on-a-start-object-at-1-974/235221/1 "2020-06-01T19:06:25Z")

</div>

My first question on this forum, so apologies for missing to post any detail. If I can also take this opportunity to say a big hello to everyone from a newbie to the world of Elastic Stack! 🙂

I have a CSV file i am trying to send to logstash sourcing from both local input and via a filebeat - the exact same format. My filebeat config for local file input works. But the same file when coming in via filebeats (all v7.7) throws the error

```auto
error => "mapper_parsing_exception"
reason => "failed to parse field [host] of type [text] in documents with id 'blah blah'. Preview of field's value: '{name=my.host.name}'"
caused_by => "illegal state exception"
reason => "Can't get text on START_OBJECT at 1:974"

```

My logstash conf (conf.d/my-csv-data.conf)

```auto
input {
   file {
	   start_position => "beginning"
	   path => "/what/ever/*.csv"
   }
   beats {
	   id => "some-id"
	   port => 5044
   }
}
output {
   elasticsearch {
	   hosts => ["localhosts:9200"]
	   action => "index"
	   index => "myindex"
   }
}

```

The filebeat config is essentially a path added to the default filebeats.input.paths collecting \*.csv and pointing to the above logstash host on port 5044. But as below, all the same:

```auto
filebeats,inputs:
- type: log
  enabled: true
  paths:
     - /path/to/data/*.csv
  tags: ["csv-type-x"]

- type: log
  enabled: true
  paths:
     - /other/path/to/data/*.csv
  tags: ["csv-type-y"]
  # etc etc
output.logstash:
   hosts: ["logstashhost:5044"]
 # and the rest of the default stuff here

```

The CSV fields do not appear to be the problem when the file is processed locally (the hostname is populated properly too). I am wondering what could be different about the same data coming in through filebeats?

Any hints would be really appreciated!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 1, 2020, 8:30pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-host-of-type-text-cant-get-text-on-a-start-object-at-1-974/235221/2 "2020-06-01T20:30:33Z")

</div>

Read [this](https://discuss.elastic.co/t/problem-logstash-outputs-elasticsearch-could-not-index-event-to-elasticsearch-wazuh-alerts-3-x-2020-05-30/235038/6) post.

---

<div class="post-metadata">

**Author:** ![mskadu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mskadu/32/69520_2.png) [@mskadu](https://discuss.elastic.co/u/mskadu)\
**Post date:** [June 2, 2020, 12:30pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-host-of-type-text-cant-get-text-on-a-start-object-at-1-974/235221/3 "2020-06-02T12:30:31Z")

</div>

Thanks for this. This solved the problem for me.

However, if I can point out that I needed to correct the rename from below

```auto
if ! [host][name] { mutate { rename { "[host]" => "[host][name]" } } }

```

to

```auto
if ! [host][name] { mutate { rename { "[host]" => "%{[host][name]}" } } }

```

source: [Logstash docs - Access Events data and fields in the configuration](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html)

And thank you for your prompt help 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2020, 12:30pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-host-of-type-text-cant-get-text-on-a-start-object-at-1-974/235221/4 "2020-06-30T12:30:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
