# Ingest Pipelines - illegal\_argument\_exception reason field not present as part of path

**URL:** <https://discuss.elastic.co/t/ingest-pipelines-illegal-argument-exception-reason-field-not-present-as-part-of-path/338267>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [July 13, 2023, 1:58am UTC](https://discuss.elastic.co/t/ingest-pipelines-illegal-argument-exception-reason-field-not-present-as-part-of-path/338267 "2023-07-13T01:58:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dmrlixos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmrlixos/32/99836_2.png) [@dmrlixos](https://discuss.elastic.co/u/dmrlixos)\
**Post date:** [July 13, 2023, 1:58am UTC](https://discuss.elastic.co/t/ingest-pipelines-illegal-argument-exception-reason-field-not-present-as-part-of-path/338267/1 "2023-07-13T01:58:57Z")

</div>

Hi  
I trying apply a ingest pipeline into a datastream.  
I'm using logstash to send to datastream, this datastream has a mapping:

```auto
 {
       "template": {
         "mappings": {
           "properties": {
             "@timestamp": {
               "type": "date",
               "format": "date_optional_time||epoch_millis"
             },
             "ipAddress": {
               "type": "ip"
             }
           }
         }
       }
     }

```

This is my Ingest Pipeline

name - logs-geoip

```auto
       {
         "geoip": {
           "field": "ipAddress"
         }
       }
     ]

```

When the log was arrived on elastic this pipeline not are invoking to start the fielld transformation ipAddress to put geoip information

I try run the command bellow to force run pipeline

POST logs-teste-geoip/\_update\_by\_query?pipeline=logs-geoip

The response:

```auto
 {
   "took": 450,
   "timed_out": false,
   "total": 233549,
   "updated": 758,
   "deleted": 0,
   "batches": 1,
   "version_conflicts": 0,
   "noops": 0,
   "retries": {
     "bulk": 0,
     "search": 0
   },
   "throttled_millis": 0,
   "requests_per_second": -1,
   "throttled_until_millis": 0,
   "failures": [
     {
       "index": ".ds-logs-teste-2023.07.13-000001",
       "id": "vau7TIkBASEFwumKBSKz",
       "cause": {
         "type": "illegal_argument_exception",
         "reason": "field [ipAddress] not present as part of path [ipAddress]"
       },
       "status": 400
     }
     ...
     ...
     ...
   }

```

Some can help how to do this ingest pipeline works together with my datastream

I 'm using this doc to reference.

- [Ingest pipelines | Elasticsearch Guide [8.8] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/8.8/ingest.html#conditionally-run-processor)
- [GeoIP processor | Elasticsearch Guide [8.8] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/geoip-processor.html)

---

<div class="post-metadata">

**Author:** ![dmrlixos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmrlixos/32/99836_2.png) [@dmrlixos](https://discuss.elastic.co/u/dmrlixos)\
**Post date:** [July 14, 2023, 2:00am UTC](https://discuss.elastic.co/t/ingest-pipelines-illegal-argument-exception-reason-field-not-present-as-part-of-path/338267/2 "2023-07-14T02:00:14Z")

</div>

somebody can help me?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 14, 2023, 3:53am UTC](https://discuss.elastic.co/t/ingest-pipelines-illegal-argument-exception-reason-field-not-present-as-part-of-path/338267/3 "2023-07-14T03:53:42Z")

</div>

Hi @dmrlixos please try to be patient, there is a very limited number of folks answering questions right now...

You need to to provide a sample document.

> [@dmrlixos](#):
>
> ` "updated": 758,`

And the result show 758 updated which leads me believe only a subset of your docs have the proper field.

Did you also try to run ingest \_simulate to test your pipeline

---

<div class="post-metadata">

**Author:** ![dmrlixos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmrlixos/32/99836_2.png) [@dmrlixos](https://discuss.elastic.co/u/dmrlixos)\
**Post date:** [July 19, 2023, 8:23pm UTC](https://discuss.elastic.co/t/ingest-pipelines-illegal-argument-exception-reason-field-not-present-as-part-of-path/338267/4 "2023-07-19T20:23:09Z")

</div>

Hi @stephenb i know man, sorry

About your question, make sense i'm looking into this issue with mo details and some cases, the ip address are IPV6 anothers case is a local ip like 192.168.x.x or 172.17.x.x etc.

I will still looking inside this error with more details to find the real way to do this.

Thanks for your support

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 16, 2023, 8:24pm UTC](https://discuss.elastic.co/t/ingest-pipelines-illegal-argument-exception-reason-field-not-present-as-part-of-path/338267/5 "2023-08-16T20:24:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
