# JSON Index Error: same field names different datatypes

**URL:** <https://discuss.elastic.co/t/json-index-error-same-field-names-different-datatypes/85352>\
**Category:** Elasticsearch\
**Created:** [May 11, 2017, 8:46am UTC](https://discuss.elastic.co/t/json-index-error-same-field-names-different-datatypes/85352 "2017-05-11T08:46:20Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndreAga](https://avatars.discourse-cdn.com/v4/letter/a/ed8c4c/32.png) [@AndreAga](https://discuss.elastic.co/u/AndreAga)\
**Post date:** [May 11, 2017, 8:46am UTC](https://discuss.elastic.co/t/json-index-error-same-field-names-different-datatypes/85352/1 "2017-05-11T08:46:21Z")

</div>

Hi all,  
I'm indexing some application logs that contain json in the message body.  
In the logstash config file, I extract the JSON and use the json plugin to convert the string in a object. All works fine, but some fields could have the same name but different datatypes (some are strings, other are json objects). In this case the logs are not indexed and the error is "mapper\_parsing\_exception".

Is there a way to ignore this error and index logs anyway?

Thanks.  
KR.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 14, 2017, 9:14am UTC](https://discuss.elastic.co/t/json-index-error-same-field-names-different-datatypes/85352/2 "2017-05-14T09:14:29Z")

</div>

Every indexed field must be mapped to a single data type in Elasticsearch, so the data you are describing can not be indexed into Elasticsearch. I suspect declaring the field to not be indexed might allow them to be indexed, but you would need to know which fields are affected upfront and would not be able to search or aggregate on them.

---

<div class="post-metadata">

**Author:** ![AndreAga](https://avatars.discourse-cdn.com/v4/letter/a/ed8c4c/32.png) [@AndreAga](https://discuss.elastic.co/u/AndreAga)\
**Post date:** [May 15, 2017, 7:59am UTC](https://discuss.elastic.co/t/json-index-error-same-field-names-different-datatypes/85352/3 "2017-05-15T07:59:18Z")

</div>

Hi Christian, thank you for your help. As I thought, there’s no a way to index it, but can I catch that event after the failure, in order to not to lose the log? Now I index the logstash logs which contain also the lost event, but I hope there is a different and elegant way to handle that.

Thank you.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 15, 2017, 8:29am UTC](https://discuss.elastic.co/t/json-index-error-same-field-names-different-datatypes/85352/4 "2017-05-15T08:29:13Z")

</div>

At the moment there is as far as I know no way of catching events that fail like this, but the Logstash team are working on introducing a [dead letter queue](https://github.com/elastic/logstash/issues/6700) that would be able to catch events like this. If there are specific fields that are causing this problem you could check as part of the pipeline, but I can not think of a generic solution.

---

<div class="post-metadata">

**Author:** ![AndreAga](https://avatars.discourse-cdn.com/v4/letter/a/ed8c4c/32.png) [@AndreAga](https://discuss.elastic.co/u/AndreAga)\
**Post date:** [May 15, 2017, 8:32am UTC](https://discuss.elastic.co/t/json-index-error-same-field-names-different-datatypes/85352/5 "2017-05-15T08:32:55Z")

</div>

Ok, thank you so much for your time 🙂  
Hope to see the DLQ available soon.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2017, 8:41am UTC](https://discuss.elastic.co/t/json-index-error-same-field-names-different-datatypes/85352/6 "2017-06-12T08:41:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
