# Failed to parse field

**URL:** <https://discuss.elastic.co/t/failed-to-parse-field/281112>\
**Category:** Logstash\
**Created:** [August 11, 2021, 7:43pm UTC](https://discuss.elastic.co/t/failed-to-parse-field/281112 "2021-08-11T19:43:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Senthil\_ak](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Post date:** [August 11, 2021, 7:43pm UTC](https://discuss.elastic.co/t/failed-to-parse-field/281112/1 "2021-08-11T19:43:57Z")

</div>

Hi admin,  
I am getting some strange exception in the logstash all of a sudden. I try to debug but unable to do so. Need your kind help.

```auto
[2021-08-11T15:37:35,189][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"dev-ecp-cluster-01-2021.08.11", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0x571119f0>], :response=>{"index"=>{"_index"=>"dev-cluster-01-2021.08.11", "_type"=>"_doc", "_id"=>"Zvu4NnsB4pQCkHpaVLyA", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [attr.error] of type [text] in document with id 'Zvu4NnsB4pQCkHpaVLyA'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:863"}}}}}

```

I tried below but still the error is coming.

`if [attr.error] { mutate { rename => { "[attr.error]" => "[attr][error]" } } }`

Thanks  
Senthil.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 11, 2021, 8:10pm UTC](https://discuss.elastic.co/t/failed-to-parse-field/281112/2 "2021-08-11T20:10:13Z")

</div>

> "mapper\_parsing\_exception", "reason"=\>"failed to parse field [attr.error] of type [text] in document with id 'Zvu4NnsB4pQCkHpaVLyA'", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"=\>"Can't get text on a START\_OBJECT at 1:863"}}}}}

elasticsearch expects the [attr.error] field (which, unless the name contains a . would be referred to using [attr][error] in logstash) to be text. However, it is finding that the value of that field is an object. In other words, there is an [attr][error][someField]. You could try converting [attr][error]

```
if [attr][error] { mutate { convert => { "[attr][error" => "string" } } }

```

---

<div class="post-metadata">

**Author:** ![Senthil\_ak](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Post date:** [August 12, 2021, 12:57am UTC](https://discuss.elastic.co/t/failed-to-parse-field/281112/3 "2021-08-12T00:57:51Z")

</div>

Thanks, i will try that... I tried with

`if [attr][error] { mutate { convert => { "[attr][error]" => "string" } } }`

but still i am getting error.

```auto
[2021-08-11T20:58:32,584][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"dev-ecp-cluster-01-2021.08.12", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0x2b63239c>], :response=>{"index"=>{"_index"=>"dev-cluster-01-2021.08.12", "_type"=>"_doc", "_id"=>"Dd7eN3sB7IddBQa8LOaG", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [attr.error] of type [text] in document with id 'Dd7eN3sB7IddBQa8LOaG'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:1294"}}}}}
[2021-08-11T20:58:32,587][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"dev-ecp-cluster-01-2021.08.12", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0x42717ac4>], :response=>{"index"=>{"_index"=>"dev-cluster-01-2021.08.12", "_type"=>"_doc", "_id"=>"D97eN3sB7IddBQa8LOaG", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [attr.error] of type [text] in document with id 'D97eN3sB7IddBQa8LOaG'", "caused_by"=>{"type"=>"illegal_state_exception", "reason"=>"Can't get text on a START_OBJECT at 1:1295"}}}}}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2021, 1:15am UTC](https://discuss.elastic.co/t/failed-to-parse-field/281112/4 "2021-08-12T01:15:53Z")

</div>

Is it possible that the field name is actually attr.error? Look at a document that does get indexed, and in the Discover pane of kibana, as I recall, you can tell the difference when you expand the event, possibly on the JSON tab.

---

<div class="post-metadata">

**Author:** ![Senthil\_ak](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Post date:** [August 12, 2021, 1:25pm UTC](https://discuss.elastic.co/t/failed-to-parse-field/281112/5 "2021-08-12T13:25:01Z")

</div>

I am converting k8s logs to json object, I am having below line in the logstash.

`if [message] =~ "\A\{.+\}\z" { json { source => "message" } }`

I did commented the line and the error is not occurring also I am able to see the att.error filed in the kibana.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/9/493bf30cb78d7d1e656cea0344e506197ece1e1e.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 9, 2021, 1:26pm UTC](https://discuss.elastic.co/t/failed-to-parse-field/281112/6 "2021-09-09T13:26:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
