# Logstash and elasticsearch mismatch

**URL:** <https://discuss.elastic.co/t/logstash-and-elasticsearch-mismatch/241758>\
**Category:** Logstash\
**Created:** [July 18, 2020, 6:24pm UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch-mismatch/241758 "2020-07-18T18:24:03Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 18, 2020, 7:41pm UTC](https://discuss.elastic.co/t/logstash-and-elasticsearch-mismatch/241758/2 "2020-07-18T19:41:50Z")

</div>

I suggest you read [this](https://discuss.elastic.co/t/logstash-errors-mapper-parsing-exception-vs-illegal-argument-exception/236783/3) post and then [this](https://discuss.elastic.co/t/problem-logstash-outputs-elasticsearch-could-not-index-event-to-elasticsearch-wazuh-alerts-3-x-2020-05-30/235038/6) post.

The beats input adds a [host] object to the event, the file input adds a [host] string to the event. A field cannot be an object on some documents and string on others. If you decide you want [host] to be an object you can do a mutate that is conditional upon [host] being a string. If you decide you want [host] to be a string then make the mutate conditional upon it being an object. Then once you start over with an empty index you should be OK.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-and-elasticsearch-mismatch/241758)._
