# Filebeat -\> logstash -\> rabbitmq -\> logstash -\> elasticsearch

**URL:** <https://discuss.elastic.co/t/filebeat-logstash-rabbitmq-logstash-elasticsearch/197695>\
**Category:** Logstash\
**Created:** [September 2, 2019, 1:40pm UTC](https://discuss.elastic.co/t/filebeat-logstash-rabbitmq-logstash-elasticsearch/197695 "2019-09-02T13:40:27Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 2, 2019, 4:06pm UTC](https://discuss.elastic.co/t/filebeat-logstash-rabbitmq-logstash-elasticsearch/197695/8 "2019-09-02T16:06:08Z")

</div>

You cannot index both types of messages to the same elasticsearch index. The structures are incompatible. In one [host] is a string

```
"host": "xxx.xxx.xxx.xxx",

```

and in the other it is an object

```
"host": {
    "name": "ip-xx-xx-xx-xx"
 },

```

Whichever one gets indexed first will cause all the messages of the other format to get mapping exceptions.

You could mutate+rename [host] if ![host][name]

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-logstash-rabbitmq-logstash-elasticsearch/197695)._
