# Logstash event- Failed to Parse field

**URL:** https://discuss.elastic.co/t/logstash-event-failed-to-parse-field/230351
**Category:** Logstash
**Created:** [April 29, 2020, 10:35am UTC](https://discuss.elastic.co/t/logstash-event-failed-to-parse-field/230351 "2020-04-29T10:35:16Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Miguel\_Alvarez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miguel_alvarez/32/67311_2.png) [@Miguel\_Alvarez](https://discuss.elastic.co/u/Miguel_Alvarez)
#### Post date: [April 29, 2020, 10:35am UTC](https://discuss.elastic.co/t/logstash-event-failed-to-parse-field/230351/1 "2020-04-29T10:35:16Z")

</div>

Hi.

I have this error in my logstash:

```auto
[2020-04-28T14:58:13,744][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"nonfood_pro-2020.04.26", :_type=>"logs", :routing=>nil}, #<LogStash::Event:0x3f9c10ba>], :response=>{"index"=>{"_index"=>"nonfood_pro-2020.04.26", "_type"=>"logs", "_id"=>"N4jdwHEB94vKD11jxvSI", "status"=>400, "error"=>{"type"=>"mapper_parsing
exception", "reason"=>"failed to parse field [MessageParam2] of type [float] in document with id 'N4jdwHEB94vKD11jxvSI'", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"XAException.XAER_RMFAIL\""}}}}}
[2020-04-28T14:58:13,744][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"nonfood_pro-2020.04.26", :_type=>"logs", :routing=>nil}, #<LogStash::Event:0x29fd7147>], :response=>{"index"=>{"_index"=>"nonfood_pro-2020.04.26", "_type"=>"logs", "_id"=>"OIjdwHEB94vKD11jxvSI", "status"=>400, "error"=>{"type"=>"mapper_parsing
exception", "reason"=>"failed to parse field [MessageParam2] of type [float] in document with id 'OIjdwHEB94vKD11jxvSI'", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"XAException.XAER_RMFAIL\""}}}}}

```

These are my filters:

```auto
	                grok {
	                    match => ["message", "(?m)(?<timestamp>%{YEAR}-%{MONTHNUM}-%{MONTHDAY}[T]%{HOUR}:?%{MINUTE}(?::?%{SECOND})) +%{LOGLEVEL:logLevel} +\[%{GREEDYDATA:componentName}\] +\[%{GREEDYDATA:threadName}\:ipaddr=%{GREEDYDATA:iplist}\;path=%{GREEDYDATA:request}\;sessionid=%{NOTSPACE:jsessionid}\] +\[(userID: +%{NOTSPACE:profileid})?\] +%{GREEDYDATA:logMsg}"]
	                    match => ["message", "(?m)(?<timestamp>%{YEAR}-%{MONTHNUM}-%{MONTHDAY}[T]%{HOUR}:?%{MINUTE}(?::?%{SECOND})) +%{LOGLEVEL:logLevel} +\[%{DATA}\] +\[%{DATA}\] +\[(userID: +%{NOTSPACE:profileid})?\] +%{GREEDYDATA} +\(thread=%{GREEDYDATA:threadName}\:ipaddr=%{GREEDYDATA:iplist}\;path=%{GREEDYDATA:request}\;sessionid=%{NOTSPACE:jsessionid}\, member=%{DATA}\)\: +%{GREEDYDATA:logMsg}"]
	                    overwrite => ["message"]
	                }
	                mutate {
	                    split => {
	                        "iplist" => ","
	                    }
	                    add_field => {
	                        "clientip" => "%{[iplist][0]}"
	                    }
	                }

```

Can anybody tell me what is going on or what I need to check?. I am lost.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [April 29, 2020, 1:09pm UTC](https://discuss.elastic.co/t/logstash-event-failed-to-parse-field/230351/2 "2020-04-29T13:09:21Z")

</div>

> [@Miguel\_Alvarez](#):
>
> "reason"=\>"failed to parse field [MessageParam2] of type [float] in document with id 'OIjdwHEB94vKD11jxvSI'", "caused\_by"=\>{"type"=\>"number\_format\_exception", "reason"=\>"For input string: "XAException.XAER\_RMFAIL""

elasticsearch is expecting the [MessageParam2] field to be a float. However, you have an event where the value of the field is "XAException.XAER\_RMFAIL", which ES cannot parse as a float.

There could be an [index template](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-template.html) that tells ES that that field should be a float. Or you may need to [create one](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html) that tells it that it is not (if ES just learned it by parsing the first document it indexed)

---

<div class="post-metadata">

### Author: ![Miguel\_Alvarez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miguel_alvarez/32/67311_2.png) [@Miguel\_Alvarez](https://discuss.elastic.co/u/Miguel_Alvarez)
#### Post date: [April 30, 2020, 8:28am UTC](https://discuss.elastic.co/t/logstash-event-failed-to-parse-field/230351/3 "2020-04-30T08:28:27Z")

</div>

> [@Miguel\_Alvarez](#):
>
> logstash

@Badger Thank you very much.

One question. Can you tell me where this parameter: MessageParam2 comes from?. I cannot see any configuration file that tells logstash to split all the parameters into: MessageParam1, MessageParam2, ... I only have the filters above mentioned. Perhaps I am missing something?.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [April 30, 2020, 2:44pm UTC](https://discuss.elastic.co/t/logstash-event-failed-to-parse-field/230351/4 "2020-04-30T14:44:02Z")

</div>

> [@Miguel\_Alvarez](#):
>
> Can you tell me where this parameter: MessageParam2 comes from?

I have no idea.

---

<div class="post-metadata">

### Author: ![Miguel\_Alvarez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/miguel_alvarez/32/67311_2.png) [@Miguel\_Alvarez](https://discuss.elastic.co/u/Miguel_Alvarez)
#### Post date: [April 30, 2020, 3:03pm UTC](https://discuss.elastic.co/t/logstash-event-failed-to-parse-field/230351/5 "2020-04-30T15:03:16Z")

</div>

@Badger But this parameter is not in the log file, so it has be added by logstash, am I right?

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [April 30, 2020, 3:05pm UTC](https://discuss.elastic.co/t/logstash-event-failed-to-parse-field/230351/6 "2020-04-30T15:05:16Z")

</div>

I do not know.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [May 28, 2020, 3:05pm UTC](https://discuss.elastic.co/t/logstash-event-failed-to-parse-field/230351/7 "2020-05-28T15:05:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
