# Filebeat throwing mapper\_parsing\_exception

**URL:** <https://discuss.elastic.co/t/filebeat-throwing-mapper-parsing-exception/197513>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 30, 2019, 11:58am UTC](https://discuss.elastic.co/t/filebeat-throwing-mapper-parsing-exception/197513 "2019-08-30T11:58:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ulka](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ulka/32/52644_2.png) [@Ulka](https://discuss.elastic.co/u/Ulka)\
**Post date:** [August 30, 2019, 11:58am UTC](https://discuss.elastic.co/t/filebeat-throwing-mapper-parsing-exception/197513/1 "2019-08-30T11:58:53Z")

</div>

I am sending filebeat output to elastic search. In filebeat logs, can see mapper parser error. trying to load dynamic template manually (through postman) but still getting error. filebeat is on K8S cluster and ES is hosted on cloud.  
Here is the filbeat required config and dynamic template.

**Prospectors:**  
- type: log  
paths:  
- /var/lib/docker/containers/_/_.log  
- /var/data/kubeletlogs/_/_/\*.log#  
json.message\_key: log  
json.keys\_under\_root: true  
logging.files.keepfiles: 7  
fields:  
clustername: {{ .Values.clustername }}

Processors:

**processors:**  
- add\_kubernetes\_metadata:  
in\_cluster: true  
- decode\_json\_fields:  
fields: ["message"]  
process\_array: true  
max\_depth: 10

```
index: "app-log-6.5.4-%{+YYYY.MM.dd}"
setup.template:
  name: "max-log"
  pattern: "max-log-*"
  enabled: true
  fields: fields.yml
  overwrite: true

```

**Dynamic template:**

{  
"template" : "app-\*",  
"order" : 1,  
"settings" : {

```
},
"mappings": {
                                       "_default_": {
                                                      "dynamic_templates": [{
                                                                    "message_field": {
                                                                                  "path_match": "message",
                                                                                  "match_mapping_type": "string",
                                                                                  "mapping": {
                                                                                                 "type": "text",
                                                                                                 "norms": false
                                                                                  }
                                                                    }
                                                      }, {
                                                                    "string_fields": {
                                                                                  "match": "*",
                                                                                  "match_mapping_type": "string",
                                                                                  "mapping": {
                                                                                                 "type": "text",
                                                                                                 "norms": false,
                                                                                                 "fields": {
                                                                                                               "keyword": {
                                                                                                                             "type": "keyword",
                                                                                                                             "ignore_above": 256
                                                                                                               }
                                                                                                 }
                                                                                  }
                                                                    }
                                                      }],
                                                      "properties": {
                                                                    "@timestamp": {
                                                                                  "type": "date"
                                                                    },
                                                                    "@version": {
                                                                                  "type": "keyword"
                                                                    },
                                                                    "geoip": {
                                                                                  "dynamic": true,
                                                                                  "properties": {
                                                                                                 "ip": {
                                                                                                               "type": "ip"
                                                                                                 },
                                                                                                 "location": {
                                                                                                               "type": "geo_point"
                                                                                                 },
                                                                                                 "latitude": {
                                                                                                               "type": "half_float"
                                                                                                 },
                                                                                                 "longitude": {
                                                                                                               "type": "half_float"
                                                                                                 }
                                                                                  }
                                                                    }
                                                      }
                                       }
                         }

```

}

1. Deleting indices from ES 2)loading template through postman (PUT req) 3) starting filebeat.

Error: {"type":"mapper\_parsing\_exception","reason":"failed to parse field [message] of type [text] in document with id 'sU9P4mwBlXscRF4xIyDU'","caused\_by":{"type":"illegal\_state\_exception","reason":"Can't get text on a START\_OBJECT at 1:191"}}

What mapping I am doing wrong/missing?

---

<div class="post-metadata">

**Author:** ![Ulka](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ulka/32/52644_2.png) [@Ulka](https://discuss.elastic.co/u/Ulka)\
**Post date:** [September 1, 2019, 7:48am UTC](https://discuss.elastic.co/t/filebeat-throwing-mapper-parsing-exception/197513/2 "2019-09-01T07:48:21Z")

</div>

can someone pl look into it?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2019, 7:48am UTC](https://discuss.elastic.co/t/filebeat-throwing-mapper-parsing-exception/197513/3 "2019-09-29T07:48:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
