# Filebeat json to Elasticsearch, error processing pipeline

**URL:** <https://discuss.elastic.co/t/filebeat-json-to-elasticsearch-error-processing-pipeline/245767>\
**Category:** Elasticsearch\
**Created:** [August 20, 2020, 12:39pm UTC](https://discuss.elastic.co/t/filebeat-json-to-elasticsearch-error-processing-pipeline/245767 "2020-08-20T12:39:31Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 20, 2020, 2:00pm UTC](https://discuss.elastic.co/t/filebeat-json-to-elasticsearch-error-processing-pipeline/245767/2 "2020-08-20T14:00:25Z")

</div>

Perhaps take a look at this

[https://www.elastic.co/guide/en/elasticsearch/reference/current/dot-expand-processor.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/dot-expand-processor.html)

"client.ip" is not a "valid" name / json construction with respect to elasticsearch.

`{"client.ip":"8.8.8.8","email.from":"user@email.com"}`

valid json should look like this

`{"client" : {"ip":"8.8.8.8"} ,"email" : {"from":"user@email.com"}}`

the grok in regular logs is creating the correct json.

So you might need to use the dot expander I referenced above

EDIT : This can seem a bit confusing because after you create valid json you can reference a field like `client.ip` but that is not the correct way to create it from a json document

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-json-to-elasticsearch-error-processing-pipeline/245767)._
