# Logstash mapping not working correctly

**URL:** <https://discuss.elastic.co/t/logstash-mapping-not-working-correctly/276446>\
**Category:** Logstash\
**Created:** [June 20, 2021, 1:29am UTC](https://discuss.elastic.co/t/logstash-mapping-not-working-correctly/276446 "2021-06-20T01:29:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jeremy\_D](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremy_d/32/52061_2.png) [@Jeremy\_D](https://discuss.elastic.co/u/Jeremy_D)\
**Post date:** [June 20, 2021, 1:29am UTC](https://discuss.elastic.co/t/logstash-mapping-not-working-correctly/276446/1 "2021-06-20T01:29:51Z")

</div>

Really unclear as to what I need to do to make this work right. My logs coming from my Python application are nested within "message" rather than being mapped to the proper fields.

 ![chrome_Wmqg3DaqD9](https://us1.discourse-cdn.com/elastic/original/3X/e/f/ef78a81dd8eae509932ca13a51fb92870103500a.png)

Notice how "message" has all the contents that the mapping would normally look for as distinct properties like "@timestamp". What the message is _supposed_ to say is "Serving on [http://0.0.0.0:8180](http://0.0.0.0:8180)"

Here's what I'm sending to logstash:

```auto
{'@timestamp': '2021-06-20T01:26:35.743Z', '@message': 'Serving on http://0.0.0.0:8180', '@source': 'logstash://DESKTOP-M87VCB0/C:\\Users\\Jeremy\\PycharmProjects\\comparebench\\venv\\lib\\site-packages\\waitress\\wasyncore.py', '@source_host': 'DESKTOP-M87VCB0', '@source_path': 'C:\\Users\\Jeremy\\PycharmProjects\\comparebench\\venv\\lib\\site-packages\\waitress\\wasyncore.py', '@tags': [], '@type': 'logstash', '@fields': {'levelname': 'INFO', 'logger': 'waitress', 'stack_info': None}}

```

I have no clue how to fix this and "logstash mapping not working" isn't a very easy google search. I'm using the python-logstash library and the Pyramid framework, using this to hook into python's logging:

```auto
host = '192.168.1.177'
logger = logging.getLogger()
logger.setLevel(logging.INFO)
logger.addHandler(logstash.TCPLogstashHandler(host, 5000, version=0))

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 20, 2021, 2:47am UTC](https://discuss.elastic.co/t/logstash-mapping-not-working-correctly/276446/2 "2021-06-20T02:47:26Z")

</div>

Please do not post pictures of text. Just post the text. You can copy the contents of the [message] field by expanding an event in Discover and then clicking on the JSON tab.

Your message is JSON. If you do not parse it with either json codec or a json filter then it will be sent to elasticsearch unmodified.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2021, 2:47am UTC](https://discuss.elastic.co/t/logstash-mapping-not-working-correctly/276446/3 "2021-07-18T02:47:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
