# Get initial log from Logstash warning

**URL:** <https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796>\
**Category:** Logstash\
**Created:** [May 16, 2022, 8:49am UTC](https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796 "2022-05-16T08:49:30Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![arazdolski](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@arazdolski](https://discuss.elastic.co/u/arazdolski)\
**Post date:** [May 16, 2022, 8:49am UTC](https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796/1 "2022-05-16T08:49:30Z")

</div>

Hi,

I have a rsyslog -\> logstash -\> Elasticsearch setup and noticed a lot of warnings with _tried to parse field [v] as an object, but found a concrete value in Logstash logs_, but I cannot find the initial syslog which Logstash received from rsyslog. Is there any way to get syslog because of which logstash threw a warning?

Logstash is running as a service and the version is 7.10.2

Logstash warning:

```auto
May 16 08:43:09 logstash-prod logstash[27402]: [2022-05-16T08:43:09,813][WARN][logstash.outputs.elasticsearch][main][8479a9c2760956f31b7228312a89412d7db93b091cceb8033b031b9671b3efba] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"logstash-2022.05.16", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x1634e346>], :response=>{"index"=>{"_index"=>"logstash-2022.05.16", "_type"=>"_doc", "_id"=>"orAJzIABf21sMtbdGBw4", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [k.v] tried to parse field [v] as object, but found a concrete value"}}}}

```

In other words, I don't understand what is wrong with the input syslog, because I don't see it in the warning message.

---

<div class="post-metadata">

**Author:** ![ibra\_013](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ibra_013/32/104827_2.png) [@ibra\_013](https://discuss.elastic.co/u/ibra_013)\
**Post date:** [May 16, 2022, 2:19pm UTC](https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796/2 "2022-05-16T14:19:47Z")

</div>

Hi,

could you please share the logstash pipeline config you're using?

---

<div class="post-metadata">

**Author:** ![arazdolski](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@arazdolski](https://discuss.elastic.co/u/arazdolski)\
**Post date:** [May 16, 2022, 5:26pm UTC](https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796/3 "2022-05-16T17:26:21Z")

</div>

Sure

```auto
input {
    relp {
        host => "0.0.0.0"
        port => "20515"
        type => "syslog"
    }
}

filter {
    dissect {
      mapping => {
        "message" => "%{syslog_ts} %{} %{source_hostname} %{program}: %{source_ip} %{message}"
      }
    }
    json {
      skip_on_invalid_json => true
      source => "message"
      target => "k"
      remove_field => ["message"]
    }
  }

output {
    elasticsearch {
      hosts => ["hostname:port"]
      user => "admin"
      password => "password"
      template => "/etc/logstash/logstash_template.json"
      template_overwrite => true
      ilm_enabled => false
    }
  }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 16, 2022, 5:45pm UTC](https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796/4 "2022-05-16T17:45:05Z")

</div>

> [@arazdolski](#):
>
> "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"object mapping for [k.v] tried to parse field [v] as object, but found a concrete value"}}}`

See [this](https://discuss.elastic.co/t/getting-illegal-state-exception-error-while-pushing-logs-to-elasticsearch/290029/2) answer. Once you have indexed an document in which [k][v] is an object any event in which [k][v] is text will be rejected.

---

<div class="post-metadata">

**Author:** ![arazdolski](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@arazdolski](https://discuss.elastic.co/u/arazdolski)\
**Post date:** [May 16, 2022, 7:33pm UTC](https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796/5 "2022-05-16T19:33:36Z")

</div>

Thanks for the answer @Badger. It's possible that from the same source (rsyslog) in some cases v is a string, and in others is an object. Now I understand the problem.

Did I understand correctly that my filter should look like this:

```auto
filter {
    dissect {
      mapping => {
        "message" => "%{syslog_ts} %{} %{source_hostname} %{program}: %{source_ip} %{message}"
      }
    }
    json {
      skip_on_invalid_json => true
      source => "message"
      target => "k"
      remove_field => ["message"]
    }
    if ! [k.v][v] { mutate { rename { "v" => "kv" } } }
  }

```

After updating filter I receive this error in Logstash:

```auto
May 16 19:32:22 logstash-prod logstash[3113]: [2022-05-16T19:32:22,594][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"=>\" at line 13, column 37 (byte 322) after filter {\n dissect {\n mapping => {\n \"message\" => \"%{syslog_ts} %{} %{source_hostname} %{program}: %{source_ip} %{message}\"\n }\n }\n json {\n skip_on_invalid_json => true\n source => \"message\"\n target => \"k\"\n remove_field => [\"message\"]\n }\n if ! [k.v][v] { mutate { rename ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:184:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:69:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:365:in `block in converge_state'"]}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 16, 2022, 7:58pm UTC](https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796/6 "2022-05-16T19:58:42Z")

</div>

> [@arazdolski](#):
>
> `if ! [k.v][v] { mutate { rename { "v" => "kv" } } }`

The error happens because you need =\> in `rename => { "v" => "kv" }`

I do not think `if ! [k.v][v] {` is the right test. Perhaps

```
if [k][v] { mutate { rename { "[k][v]" => "kv" } } }`

```

---

<div class="post-metadata">

**Author:** ![arazdolski](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@arazdolski](https://discuss.elastic.co/u/arazdolski)\
**Post date:** [May 17, 2022, 6:00am UTC](https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796/7 "2022-05-17T06:00:57Z")

</div>

Sorry, but still something is incorrect.

Filter configuration:

```auto
filter {
    dissect {
      mapping => {
        "message" => "%{syslog_ts} %{} %{source_hostname} %{program}: %{source_ip} %{message}"
      }
    }
    json {
      skip_on_invalid_json => true
      source => "message"
      target => "k"
      remove_field => ["message"]
    }
    if [k][v] { mutate { rename { "[k][v]" => "kv" } } }
  }

```

Logstash error:

```auto
 May 17 05:52:23 logstash-prod logstash[28069]: [2022-05-17T05:52:23,170][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"=>\" at line 13, column 33 (byte 318) after filter {\n dissect {\n mapping => {\n \"message\" => \"%{syslog_ts} %{} %{source_hostname} %{program}: %{source_ip} %{message}\"\n }\n }\n json {\n skip_on_invalid_json => true\n source => \"message\"\n target => \"k\"\n remove_field => [\"message\"]\n }\n if [k][v] { mutate { rename ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:184:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:69:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:365:in `block in converge_state'"]}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 17, 2022, 12:33pm UTC](https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796/8 "2022-05-17T12:33:13Z")

</div>

As I said, you need to add a `=>`.

---

<div class="post-metadata">

**Author:** ![arazdolski](https://avatars.discourse-cdn.com/v4/letter/a/977dab/32.png) [@arazdolski](https://discuss.elastic.co/u/arazdolski)\
**Post date:** [May 17, 2022, 3:29pm UTC](https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796/9 "2022-05-17T15:29:24Z")

</div>

Added "=\>" after rename, no "Failed to execute action" errors, but unfortunately, this solution doesn't solve my problem. I still have "...found a concrete value" errors.

Could we please return to the question which I initially asked? How to get input syslog for troubleshooting?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 17, 2022, 3:37pm UTC](https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796/10 "2022-05-17T15:37:05Z")

</div>

If you want to store the events for which Elasticsearch returned an error use a [DLQ](https://www.elastic.co/guide/en/logstash/current/dead-letter-queues.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2022, 3:37pm UTC](https://discuss.elastic.co/t/get-initial-log-from-logstash-warning/304796/11 "2022-06-14T15:37:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
