# Logstash Json Data processing issue

**URL:** <https://discuss.elastic.co/t/logstash-json-data-processing-issue/368309>\
**Category:** Logstash\
**Created:** [October 6, 2024, 6:33am UTC](https://discuss.elastic.co/t/logstash-json-data-processing-issue/368309 "2024-10-06T06:33:36Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sai\_ravi\_shankar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_ravi_shankar/32/120767_2.png) [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Post date:** [October 6, 2024, 6:33am UTC](https://discuss.elastic.co/t/logstash-json-data-processing-issue/368309/1 "2024-10-06T06:33:36Z")

</div>

Hi ELK Community,

I need your help with an issue I'm encountering.

In my JSON data processing pipeline, some fields are coming in two formats: as an array and as a keyword.

When I set the mapping for "field\_name" as an object in the index template, I get errors in the Logstash pipeline: "Unable to parse the keyword as object. Reason: Can't get text on a START\_OBJECT at 1:6546."

When I set the mapping for "field\_name" as a keyword in the index template, I receive the error: "Unable to parse the keyword as object, but found a concrete value."

How can I resolve this issue?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 6, 2024, 9:07am UTC](https://discuss.elastic.co/t/logstash-json-data-processing-issue/368309/2 "2024-10-06T09:07:42Z")

</div>

Could you share the Elasticsearch mapping and 2 sample documents?

---

<div class="post-metadata">

**Author:** ![sai\_ravi\_shankar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_ravi_shankar/32/120767_2.png) [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Post date:** [October 6, 2024, 11:16am UTC](https://discuss.elastic.co/t/logstash-json-data-processing-issue/368309/3 "2024-10-06T11:16:46Z")

</div>

Mapping:  
json.get.value ==\> keyword  
json.get.key ==\> keyword

{  
"@timestamp": "2024-10-06 11:09",  
"json": {  
"get": [  
{  
"value": "test-1",  
"key": "check-1"  
},  
{  
"value": "test-2",  
"key": "check-2"  
}  
]  
}  
}  
{  
"@timestamp": "2024-10-06 11:09",  
"json": {  
"get": [  
{  
"value": "test-3",  
"key": "check-3"  
}  
]  
}  
}

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 6, 2024, 11:44am UTC](https://discuss.elastic.co/t/logstash-json-data-processing-issue/368309/4 "2024-10-06T11:44:49Z")

</div>

I don't see which one would fail.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 6, 2024, 11:45am UTC](https://discuss.elastic.co/t/logstash-json-data-processing-issue/368309/5 "2024-10-06T11:45:52Z")

</div>

> [@sai\_ravi\_shankar](#):
>
> In my JSON data processing pipeline, some fields are coming in two formats: as an array and as a keyword.

As an array of concrete values or as an array of objects? It is no clear, the example you shared would not lead to conflict.

Can you share the entire log from Logstash when you get the error?

Also, you didn't share the mapping, you need to get the mapping using `GET index-name/_mapping`.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 6, 2024, 5:24pm UTC](https://discuss.elastic.co/t/logstash-json-data-processing-issue/368309/6 "2024-10-06T17:24:22Z")

</div>

You can't have a field that is a keyword in some documents and an object in others. To resolve it you will need to either convert the field to an object when it is a keyword or convert the field to a keyword when it is an object. See [this](https://discuss.elastic.co/t/getting-illegal-state-exception-error-while-pushing-logs-to-elasticsearch/290029/2) thread.

---

<div class="post-metadata">

**Author:** ![sai\_ravi\_shankar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sai_ravi_shankar/32/120767_2.png) [@sai\_ravi\_shankar](https://discuss.elastic.co/u/sai_ravi_shankar)\
**Post date:** [October 7, 2024, 10:55am UTC](https://discuss.elastic.co/t/logstash-json-data-processing-issue/368309/7 "2024-10-07T10:55:01Z")

</div>

Thanks @badger,

I tried using the painless script but getting some errors.

Painless Script:

if(ctx.get.key != null)  
{  
ctx.get.key = ctx.get.key.toString();  
}  
if(ctx.get.value != null)  
{  
ctx.get.value = ctx.get.value.toString();  
}

condition:  
(ctx.get.key instanceof List) || (ctx.get.value instanceof List)

Error:"Illegal list shortcut value [key]."
