# Handling elastic mapping errors when using logstash elastic output plugin

**URL:** <https://discuss.elastic.co/t/handling-elastic-mapping-errors-when-using-logstash-elastic-output-plugin/81777>\
**Category:** Logstash\
**Created:** [April 10, 2017, 8:55am UTC](https://discuss.elastic.co/t/handling-elastic-mapping-errors-when-using-logstash-elastic-output-plugin/81777 "2017-04-10T08:55:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sharbel\_Cherian\_Konn](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@Sharbel\_Cherian\_Konn](https://discuss.elastic.co/u/Sharbel_Cherian_Konn)\
**Post date:** [April 10, 2017, 8:55am UTC](https://discuss.elastic.co/t/handling-elastic-mapping-errors-when-using-logstash-elastic-output-plugin/81777/1 "2017-04-10T08:55:42Z")

</div>

Hi

We have built and deployed an ELK Solution for one of our partners suing Elastic Cloud and a Logstash Cluster. The logs are generated from many different apps developed by different teams and there have been instances where the datatypes does not match. How can we deal with this problem?

Saw a few threads/ issues in logstash git repo where people had similar issues. There were also discussions to come with a Dead letter queue which is not released yet. Is it possible to configure a queue or another ES index where such 400 errors can be logged. Currently the errors are partly read from SQS and the logs gets deleted.

Any suggestions / ideas to deal with this problem other than extending the elastic search output plugin ourselves.

Regards  
Sharbel

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2017, 9:06am UTC](https://discuss.elastic.co/t/handling-elastic-mapping-errors-when-using-logstash-elastic-output-plugin/81777/2 "2017-05-08T09:06:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
