# Logstash Parser error - tried to parse field as object, but found a concrete value

**URL:** <https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140>\
**Category:** Logstash\
**Created:** [April 3, 2021, 5:50am UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140 "2021-04-03T05:50:13Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Automation\_Scripts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/automation_scripts/32/85374_2.png) [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Post date:** [April 3, 2021, 5:50am UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/1 "2021-04-03T05:50:13Z")

</div>

Hi,

I am trying to parse a log but i have this error.

_[source] tried to parse field [source] as object, but found a concrete value_

```auto
if "string" in [tags] {
      grok {            
          match => ["message", "(?<ts>(.*?))\t(?<fuid>(.*?))\t(?<tx_hosts>(.*?))\t(?<rx_hosts>(.*?))\t(?<conn_uids>(.*?))\t(?<source>(.*?))\t(?<depth>(.*?))\t(?<analyzers>(.*?))\t(?<mime_type>(.*?))\t(?<filename>(.*?))\t(?<duration>(.*?))\t(?<local_orig>(.*?))\t(?<is_orig>(.*?))\t(?<seen_bytes>(.*?))\t(?<total_bytes>(.*?))\t(?<missing_bytes>(.*?))\t(?<overflow_bytes>(.*?))\t(?<timedout>(.*?))\t(?<parent_fuid>(.*?))\t(?<md5>(.*?))\t(?<sha1>(.*?))\t(?<sha256>(.*?))\t(?<extracted>(.*))"]
       } 
        mutate { 
          add_tag => ["hello world from source"] 
          convert => ["source", "string"]
      } 
    }

```

The actual log

```auto
1295981542.761080	FLNLOJ2zgI814vI3Lh	72.14.213.102	192.168.3.131	COcbTZ3MjJb30W6Wba	HTTP	0	(empty)	text/json	-	0.000000	-	F	273	-	0	0	F	-	-	-	-	-	-	-

```

Thank you in advance!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 3, 2021, 3:08pm UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/2 "2021-04-03T15:08:29Z")

</div>

> [@Automation\_Scripts](#):
>
> found a concrete value

There are a boatload of threads in this forum that discuss this. [Here](https://discuss.elastic.co/t/error-indexing-using-xml-plugin/223774/2) is one.

---

<div class="post-metadata">

**Author:** ![Automation\_Scripts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/automation_scripts/32/85374_2.png) [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Post date:** [April 4, 2021, 5:19am UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/3 "2021-04-04T05:19:59Z")

</div>

is not normal to find a concrete value? we still have to parse a value if exists or not

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 4, 2021, 5:57am UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/4 "2021-04-04T05:57:53Z")

</div>

Try this test, hopefully this makes it clearer

```
POST test/_doc
{
  "myfield" : "myvalue",
  "myotherfield" :
  {
    "mysubfield1" : "mysubvalue1",
    "mysubfield2" : "mysubvalue2"
  }
}

```

Then Post

```
POST test/_doc
{
  "myfield" : "myvalue",
  "myotherfield" : "myconcretevalue"
}

```

and you will get this error.

```
{
  "error" : {
    "root_cause" : [
      {
        "type" : "mapper_parsing_exception",
        "reason" : "object mapping for [myotherfield] tried to parse field [myotherfield] as object, but found a concrete value"
      }
    ],
    "type" : "mapper_parsing_exception",
    "reason" : "object mapping for [myotherfield] tried to parse field [myotherfield] as object, but found a concrete value"
  },
  "status" : 400
}

```

This is because the first document created a mapping where `myotherfield` is an object ...

You can see the mapping by running

`GET /test/`

then when you try to post a document that has `myotherfield` as a simple concrete field/ data type it throws an error , that field can not be both types.

The mapping (schema) is static for each field

Either a field is and object or a simple data type or and array etc ... once the type is defined that type is "static" not "dynamic". All documents to be indexed need to adhere to the mapping. You either need to put it in a different field or not index that document.

You can clean that up and do it it the opposite order... then the type will be a simple field (keyword and text) then if you try to add the doc with the sub object it will complain with a different error.

Once the mapping is defined for a field... the data type is static.

So in your case you have logs coming in where some fields get defined as an object and some logs where that same field is a simple concrete value... you need to figure out which and solve for it.

---

<div class="post-metadata">

**Author:** ![Automation\_Scripts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/automation_scripts/32/85374_2.png) [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Post date:** [April 6, 2021, 11:32am UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/5 "2021-04-06T11:32:51Z")

</div>

Thank you! As far as I can see the field is a string and I don’t lnow why it parsed as an object. Thank you for your answer!

---

<div class="post-metadata">

**Author:** ![Automation\_Scripts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/automation_scripts/32/85374_2.png) [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Post date:** [April 8, 2021, 4:28pm UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/6 "2021-04-08T16:28:32Z")

</div>

Do you know how this error can be solved?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 8, 2021, 4:37pm UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/7 "2021-04-08T16:37:04Z")

</div>

One solution is partially parse the message and using some other identifier to conditionally split the parsing one for an object and one for a concrete value and put them in different fields.

---

<div class="post-metadata">

**Author:** ![Automation\_Scripts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/automation_scripts/32/85374_2.png) [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Post date:** [April 8, 2021, 4:37pm UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/8 "2021-04-08T16:37:54Z")

</div>

can you please give me an example ==\> a programming one

---

<div class="post-metadata">

**Author:** ![Automation\_Scripts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/automation_scripts/32/85374_2.png) [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Post date:** [April 8, 2021, 4:40pm UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/9 "2021-04-08T16:40:59Z")

</div>

or how can I change the mapping type of a field? is is object to make it text? how this cast can be done?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 8, 2021, 4:45pm UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/10 "2021-04-08T16:45:02Z")

</div>

You can't just "Cast" an object to a mapping...

Perhaps @Badger can show you how to `toString()` something.

This is not an easy problem to solve...

Question is how many logs does this affect 50%... 1% .... 0.00002%

That would be what I focus on and solve for the majority first... then work on the left overs

Is there an identifier that you could sort on.?  
Can you post 1 log that has a concrete and 1 log that has an object

Perhaps we can take a look but I can't really write your code for you.

---

<div class="post-metadata">

**Author:** ![Automation\_Scripts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/automation_scripts/32/85374_2.png) [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Post date:** [April 8, 2021, 4:48pm UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/11 "2021-04-08T16:48:51Z")

</div>

this happens to 3 different types of logs. Please note that all the tools have 7.12 version.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 8, 2021, 4:52pm UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/12 "2021-04-08T16:52:56Z")

</div>

This isn't an issue with the Stack Version this is an issue that you have 3 types of Logs with different structure you are trying to force into a single schema, you can do it but it will take some work.

Can you provide a sample of the 3 types of logs... if not we certainly can not help.

I asked you other questions that you did not answer... I asked them for specific reasons.

Do you know the ratio of the logs, start with that one first. Get it working, then move on to the next.

That is my suggestion, if you want help ... you need to provide the answers and samples I / we requested.

---

<div class="post-metadata">

**Author:** ![Automation\_Scripts](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/automation_scripts/32/85374_2.png) [@Automation\_Scripts](https://discuss.elastic.co/u/Automation_Scripts)\
**Post date:** [April 8, 2021, 6:30pm UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/13 "2021-04-08T18:30:58Z")

</div>

thank you! I've split the fields and renamed the one with the incorrect type and worked like a charm. Thank you for your support!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 8, 2021, 6:42pm UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/14 "2021-04-08T18:42:57Z")

</div>

Nice ...

@Automation_Scripts We would ask you to share your solution to help others ... please 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2021, 6:43pm UTC](https://discuss.elastic.co/t/logstash-parser-error-tried-to-parse-field-as-object-but-found-a-concrete-value/269140/15 "2021-05-06T18:43:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
