# Log source with different field type - mapper\_parsing\_exception

**URL:** <https://discuss.elastic.co/t/log-source-with-different-field-type-mapper-parsing-exception/217655>\
**Category:** Elasticsearch\
**Created:** [February 3, 2020, 3:44pm UTC](https://discuss.elastic.co/t/log-source-with-different-field-type-mapper-parsing-exception/217655 "2020-02-03T15:44:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nitzang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nitzang/32/61957_2.png) [@nitzang](https://discuss.elastic.co/u/nitzang)\
**Post date:** [February 3, 2020, 3:44pm UTC](https://discuss.elastic.co/t/log-source-with-different-field-type-mapper-parsing-exception/217655/1 "2020-02-03T15:44:45Z")

</div>

Hello,

I recently started getting AWS cloud logs to ES and received many exceptions for indexing issues, such as:

` [2020-02-03T15:35:56,728][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"cloudtrail-2020.02.03", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0x7a78e3e4>], :response=>{"index"=>{"_index"=>"cloudtrail-2020.02.03", "_type"=>"_doc", "_id"=>"G-axC3AB9zZoOkkBpkYb", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [Records.requestParameters.DescribeVpcEndpointsRequest] tried to parse field [DescribeVpcEndpointsRequest] as object, but found a concrete value"}}}}`

I did some reading and I know it's due to trying to get text data to object and vice-versa.

The problem is that's how Cloudtrail logs look like.

Is there any way to get both? or manipulating the logs (I'm using Logstash) that whenever a text field will arrive it will replace its name?

Any ideas?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2020, 3:44pm UTC](https://discuss.elastic.co/t/log-source-with-different-field-type-mapper-parsing-exception/217655/2 "2020-03-02T15:44:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
