# Filebeat Exception - Cannot Get Text on a Start Object

**URL:** <https://discuss.elastic.co/t/filebeat-exception-cannot-get-text-on-a-start-object/134258>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 1, 2018, 4:42pm UTC](https://discuss.elastic.co/t/filebeat-exception-cannot-get-text-on-a-start-object/134258 "2018-06-01T16:42:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tarpanpathak](https://avatars.discourse-cdn.com/v4/letter/t/0ea827/32.png) [@tarpanpathak](https://discuss.elastic.co/u/tarpanpathak)\
**Post date:** [June 1, 2018, 4:42pm UTC](https://discuss.elastic.co/t/filebeat-exception-cannot-get-text-on-a-start-object/134258/1 "2018-06-01T16:42:13Z")

</div>

This is my first post so hello.

I'm trying to debug a Filebeat exception error but not making much progress.

We are running Filebeat through a Helm chart and without changes to the environment are seeing the following messages across all our environments:

```auto
2018/05/30 00:22:19.159723 client.go:465: WARN Can not index event (status=400): {"type":"mapper_parsing_exception","reason":"failed to parse [log]","caused_by":{"type":"illegal_state_exception","reason":"Can't get text on a START_OBJECT at 1:225"}}
2018/05/30 00:22:19.159734 client.go:465: WARN Can not index event (status=400): {"type":"mapper_parsing_exception","reason":"failed to parse [log]","caused_by":{"type":"illegal_state_exception","reason":"Can't get text on a START_OBJECT at 1:301"}}
2018/05/30 00:22:19.159748 client.go:465: WARN Can not index event (status=400): {"type":"mapper_parsing_exception","reason":"failed to parse [log]","caused_by":{"type":"illegal_state_exception","reason":"Can't get text on a START_OBJECT at 1:260"}}

```

The Helm chart version is: `filebeat-0.1.2`

Here is a link to the chart: [https://github.com/kubernetes/charts/tree/master/stable/filebeat](https://github.com/kubernetes/charts/tree/master/stable/filebeat)

Additionally, here are the configurations being used:

1. **filebeat-chart.yml** :

```auto
# Default values for filebeat.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.
elasticsearch:
  host: <sensitive>
  port: 443
  username:
  password:

apiVersion: "extensions/v1beta1"

# Set the daemonset api version ^
daemonSetVersion: "extensions/v1beta1"

nameSpace: kube-system
rbac:
  create: true
  serviceAccountName: default

daemonset:
  create: true

```

1. **filebeat-config.yml** :

```auto
apiVersion: v1
data:
  filebeat.yml: "filebeat.config:\n prospectors:\n # Mounted `filebeat-prospectors`
    configmap:\n path: ${path.config}/prospectors.d/*.yml\n # Reload prospectors
    configs as they change:\n reload.enabled: false\n modules:\n path: ${path.config}/modules.d/*.yml\n
    \ # Reload module configs as they change:\n reload.enabled: false\n\nprocessors:\n
    \ - add_cloud_metadata:\n\ncloud.id: ${ELASTIC_CLOUD_ID}\ncloud.auth: ${ELASTIC_CLOUD_AUTH}\n\noutput.elasticsearch:\n
    \ hosts: ['<sensitive>']\n
    \ username: \n password:"
kind: ConfigMap
metadata:
  creationTimestamp: 2018-04-17T00:22:56Z
  labels:
    app: filebeat
    chart: filebeat-0.1.2
    heritage: Tiller
    release: filebeat
  name: filebeat-config
  namespace: kube-system
  resourceVersion: "<sensitive>"
  selfLink: /api/v1/namespaces/kube-system/configmaps/filebeat-config
  uid: <sensitive>

```

1. **filebeat-prospector.yaml** :

```auto
apiVersion: v1
data:
  kubernetes.yml: |-
    - type: log
      paths:
        - /var/lib/docker/containers/*/*.log
      json.message_key: log
      json.keys_under_root: true
      processors:
        - add_kubernetes_metadata:
            in_cluster: true
            namespace: ${POD_NAMESPACE}
        - decode_json_fields:
            fields: ["log"]
      output.console.pretty: true
kind: ConfigMap
metadata:
  creationTimestamp: 2018-04-17T00:22:56Z
  labels:
    app: filebeat
    chart: filebeat-0.1.2
    heritage: Tiller
    release: filebeat
  name: filebeat-prospectors
  namespace: kube-system
  resourceVersion: "<sensitive>"
  selfLink: /api/v1/namespaces/kube-system/configmaps/filebeat-prospectors
  uid: <sensitive>

```

Any help/response is greatly appreciated.

Let me know if more details are required to help you understand this issue.

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [June 1, 2018, 5:40pm UTC](https://discuss.elastic.co/t/filebeat-exception-cannot-get-text-on-a-start-object/134258/2 "2018-06-01T17:40:30Z")

</div>

Hi @tarpanpathak,

From what I see, that version is not taking benefit from the `docker` prospector, so your log messages end up under the `log` field, instead of the expected `message`. I see that newer versions are correct: [https://github.com/kubernetes/charts/blob/master/stable/filebeat/values.yaml#L26](https://github.com/kubernetes/charts/blob/master/stable/filebeat/values.yaml#L26)

Any reason to use such and old version?

Best regards

---

<div class="post-metadata">

**Author:** ![tarpanpathak](https://avatars.discourse-cdn.com/v4/letter/t/0ea827/32.png) [@tarpanpathak](https://discuss.elastic.co/u/tarpanpathak)\
**Post date:** [June 1, 2018, 10:04pm UTC](https://discuss.elastic.co/t/filebeat-exception-cannot-get-text-on-a-start-object/134258/3 "2018-06-01T22:04:38Z")

</div>

Hi @exekias,

Thx for pointing this out. To answer your question, no, the old/current version has been working until this issue so we have been using it.

Do you suggest upgrading to the latest (chart) version and testing/monitoring?

---

<div class="post-metadata">

**Author:** ![tarpanpathak](https://avatars.discourse-cdn.com/v4/letter/t/0ea827/32.png) [@tarpanpathak](https://discuss.elastic.co/u/tarpanpathak)\
**Post date:** [June 4, 2018, 6:57pm UTC](https://discuss.elastic.co/t/filebeat-exception-cannot-get-text-on-a-start-object/134258/4 "2018-06-04T18:57:56Z")

</div>

Update, I misspoke earlier, we are actually using Filebeat version 6.0.1 but still seeing these errors.

Any thoughts on why?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 2, 2018, 6:58pm UTC](https://discuss.elastic.co/t/filebeat-exception-cannot-get-text-on-a-start-object/134258/5 "2018-07-02T18:58:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
