# Failed to parse mapping \[\_doc\]: unknown parameter \[properties\] on mapper \[error\] of type \[text\]

**URL:** <https://discuss.elastic.co/t/failed-to-parse-mapping-doc-unknown-parameter-properties-on-mapper-error-of-type-text/280322>\
**Category:** Elasticsearch\
**Created:** [August 3, 2021, 1:56pm UTC](https://discuss.elastic.co/t/failed-to-parse-mapping-doc-unknown-parameter-properties-on-mapper-error-of-type-text/280322 "2021-08-03T13:56:53Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [August 3, 2021, 1:56pm UTC](https://discuss.elastic.co/t/failed-to-parse-mapping-doc-unknown-parameter-properties-on-mapper-error-of-type-text/280322/1 "2021-08-03T13:56:53Z")

</div>

I am running filebeat aws module to fetch AWS cloudtrail logs, since 1st August I am getting this error and data is not getting indexed. I am using custom index name and using copied template and pipeline from Filebeat index template and pipeline.

`{"type": "server", "timestamp": "2021-08-03T12:00:33,517Z", "level": "INFO", "component": "o.e.c.m.MetadataCreateIndexService", "cluster.name": "my_cluster_name", "node.name": "node1", "message": "failed on parsing mappings on index creation [cloud-audit-aws-2021.08]", "cluster.uuid": "Q081W-QcSJK7J9N-nkH_1A", "node.id": "Gf8quOkhSi--sNJwRfx3fA" , `  
`"stacktrace": ["org.elasticsearch.index.mapper.MapperParsingException: Failed to parse mapping [_doc]: unknown parameter [properties] on mapper [error] of type [text]"`

Can anyone help asap, getting this issue in the production environment. ?

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [August 4, 2021, 5:54am UTC](https://discuss.elastic.co/t/failed-to-parse-mapping-doc-unknown-parameter-properties-on-mapper-error-of-type-text/280322/2 "2021-08-04T05:54:01Z")

</div>

I tried sending data to a whole new index, but still the same error !!

can anyone help? I am stuck ☹

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 4, 2021, 6:01am UTC](https://discuss.elastic.co/t/failed-to-parse-mapping-doc-unknown-parameter-properties-on-mapper-error-of-type-text/280322/3 "2021-08-04T06:01:20Z")

</div>

It would help if you actually shared your configuration files.

To me it looks like perhaps you have a bad mapping or index template.

Also Where did you define the pipeline in the filebeat configs.

Also just an observation/suggestion is that I would suggest perhaps using the defaults first and understand how that works before customizing but that's just an observation.

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [August 4, 2021, 6:23am UTC](https://discuss.elastic.co/t/failed-to-parse-mapping-doc-unknown-parameter-properties-on-mapper-error-of-type-text/280322/4 "2021-08-04T06:23:45Z")

</div>

Thanks for your response @stephenb !!

my logstash configuration file:

```auto
input
{
        beats 
	{
		port => "5044"
	}
}
output
{

	
	if [service][type] == "gsuite"
	{
		elasticsearch 
		{
		hosts => ["ES_HOST:9200"]
		index => "gsuite"
		ssl => true
		ssl_certificate_verification => false
		user => 'elastic'
		password => 'password'
		}
	}
	if [input][type] == "s3"
        {
                elasticsearch
                {
                hosts => ["ES_HOST:9200"]
                index => "cloud-audit-aws-%{+YYYY.MM}"
	            pipeline => "signals-aws-cloudtrail"
                ssl => true
                ssl_certificate_verification => false
                user => 'elastic'
                password => 'password'
                }
        }

	if [input][type] == "azure-eventhub"
        {
                elasticsearch
                {
                hosts => ["ES_HOST:9200"]
                index => "cloud-audit-azure-%{+YYYY.MM}"
	            pipeline => "signals-azure-activitylogs-pipeline"
                ssl => true
                ssl_certificate_verification => false
                user => 'elastic'
                password => 'password'
                }
        }

	stdout { codec => rubydebug }
}

```

here is my ingest\_pipeline :

> <https://gist.github.com/ankitdevnalkar/d0ead1e65778b38ff060230a0f063135>

Following is the mapping from July's index

> <https://gist.github.com/ankitdevnalkar/c7df2a438c4870532ad31fc1241f320e>

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [August 4, 2021, 8:35am UTC](https://discuss.elastic.co/t/failed-to-parse-mapping-doc-unknown-parameter-properties-on-mapper-error-of-type-text/280322/5 "2021-08-04T08:35:09Z")

</div>

> [@stephenb](#):
>
> Also Where did you define the pipeline in the filebeat configs.

I defined pipeline in Logstash config.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 4, 2021, 2:48pm UTC](https://discuss.elastic.co/t/failed-to-parse-mapping-doc-unknown-parameter-properties-on-mapper-error-of-type-text/280322/6 "2021-08-04T14:48:54Z")

</div>

Hi @ankitdevnalkar

With respect to the Mapping I did not want to see the mapping from an existing index I would want to see your new Template there could be an issue there that seems to be what the error indicates perhaps it is malformed.

The error indicates `unknown parameter [properties]` that there is a `properties` field in the wrong place

Also what happens if you just try to post an empty document to you new index does it work?

```auto
POST cloud-audit-aws-2021-09-test/_doc
{
}

```

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [August 4, 2021, 3:43pm UTC](https://discuss.elastic.co/t/failed-to-parse-mapping-doc-unknown-parameter-properties-on-mapper-error-of-type-text/280322/7 "2021-08-04T15:43:42Z")

</div>

Hey @stephenb

I just resolved the issue. I had a template having two index patterns `cloud-audit-duo*` and `cloud-audit*`. So the `cloud-audit*` was conflicting with `cloud-audit-aws`, I removed `cloud-audit*` and it worked. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2021, 3:44pm UTC](https://discuss.elastic.co/t/failed-to-parse-mapping-doc-unknown-parameter-properties-on-mapper-error-of-type-text/280322/8 "2021-09-01T15:44:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
