# Failed to parse field \[\[observer.hostname\]\]

**URL:** <https://discuss.elastic.co/t/failed-to-parse-field-observer-hostname/293676>\
**Category:** Logstash\
**Created:** [January 6, 2022, 4:52pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-observer-hostname/293676 "2022-01-06T16:52:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![eO2H\_LG](https://avatars.discourse-cdn.com/v4/letter/e/ce7236/32.png) [@eO2H\_LG](https://discuss.elastic.co/u/eO2H_LG)\
**Post date:** [January 6, 2022, 4:52pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-observer-hostname/293676/1 "2022-01-06T16:52:42Z")

</div>

Hello All,

Hoping somebody can assist me with the following error. It seems some of my DHCP data is failing to ingest due to a parsing issue with the observer.hostname field.

Below is the error output from logstash-plain.log

```auto
[2022-01-06T11:27:33,527][WARN][logstash.outputs.elasticsearch][main][0333efb347b760d89aa286d374f72b4afb134c9060bf796e12c73a5540111601] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"mcafee-1.0", :routing=>nil}, {"host.os.family"=>"windows", "network.transport"=>"udp", "timestamp"=>"01/06/22,11:27:08", "network.protocol"=>"dhcpv4", "event.category"=>"network, network_traffic", "event.type"=>"connection, protocol", "agent"=>{"hostname"=>"DHCP-SERVER-1", "id"=>"aace8503-d37a-40b7-806a-4e4830c64dff", "ephemeral_id"=>"1e604d93-9c73-4871-ae70-25941c8dc08f", "name"=>"DHCP-SERVER-1", "type"=>"filebeat", "version"=>"7.16.2"}, "process.name"=>"microsoft.dhcp", "dhcpv4.client_ip"=>"192.168.5.42", "dhcpv4.id"=>"31", "input"=>{"type"=>"log"}, "log"=>{"offset"=>6294498, "file"=>{"path"=>"C:\\Windows\\Stsyem32\\dhcp\\DhcpSrvLog-Thu.log"}}, "dhcpv4.option.hostname"=>"Computer1.domain.com", "event.dataset"=>"dhcpv4", "network.type"=>"ipv4", "message"=>"31,01/06/22,11:27:08,DNS Update Failed,192.168.5.42,Computer1.domain.com,,,0,6,,,,,,,,,9017", "dhcpv4.transaction_id"=>"0", "dhcpv4.option.message"=>"9017", "host.os.platform"=>"windows", "observer.hostname"=>{"name"=>"DHCP-SERVER-1"}, "dhcpv4.option.message_type"=>"DNS Update Failed", "event.kind"=>"event", "@timestamp"=>2022-01-06T16:27:08.000Z, "ecs"=>{"version"=>"1.12.0"}, "dhcpv4.op_code"=>"No Quarantine Information Probation Time", "dhcpv4.hardware_type"=>"Ethernet", "host.os.name"=>"windows", "@version"=>"1", "tags"=>["beats_input_codec_plain_applied", "DHCP", "_grokparsefailure"]}], :response=>{"index"=>{"_index"=>"mcafee-1.0", "_type"=>"_doc", "_id"=>"randomID", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [observer.hostname] of type [text] in document with id 'randomID'. Preview of field's value: '{name=DHCP-SERVER-1}'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:913"}}}}}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 6, 2022, 5:08pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-observer-hostname/293676/2 "2022-01-06T17:08:16Z")

</div>

See [this](https://discuss.elastic.co/t/getting-illegal-state-exception-error-while-pushing-logs-to-elasticsearch/290029/2) answer. Once you have indexed a document in which [observer.hostname] is a string, any event in which [observer.hostname] is an object (a hash) will be rejected.

---

<div class="post-metadata">

**Author:** ![eO2H\_LG](https://avatars.discourse-cdn.com/v4/letter/e/ce7236/32.png) [@eO2H\_LG](https://discuss.elastic.co/u/eO2H_LG)\
**Post date:** [January 6, 2022, 6:37pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-observer-hostname/293676/3 "2022-01-06T18:37:31Z")

</div>

Hi Badger,

Thank you so much for the link. My question is as all of this data can be re-ingested again is there a way to convert or force [observer.hostname] to avoid these errors each time the index rolls over.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 6, 2022, 6:48pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-observer-hostname/293676/4 "2022-01-06T18:48:07Z")

</div>

That post discusses a couple of ways to do that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2022, 6:48pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-observer-hostname/293676/5 "2022-02-03T18:48:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
