# Logstash to Elastic search, Could not index event to Elasticsearch , "reason"=\>"mapper \[\] of different type, current\_type \[long\], merged\_type \[text\]

**URL:** <https://discuss.elastic.co/t/logstash-to-elastic-search-could-not-index-event-to-elasticsearch-reason-mapper-of-different-type-current-type-long-merged-type-text/168279>\
**Category:** Logstash\
**Created:** [February 13, 2019, 7:37pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-could-not-index-event-to-elasticsearch-reason-mapper-of-different-type-current-type-long-merged-type-text/168279 "2019-02-13T19:37:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![SuperTomcat1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supertomcat1/32/40899_2.png) [@SuperTomcat1](https://discuss.elastic.co/u/SuperTomcat1)\
**Post date:** [February 13, 2019, 7:37pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-could-not-index-event-to-elasticsearch-reason-mapper-of-different-type-current-type-long-merged-type-text/168279/1 "2019-02-13T19:37:16Z")

</div>

error i see in logstash logs:

`Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"arrayx1", :_type=>"doc", :routing=>nil}, #<LogStash::Event:0x55602f10>], :response=> {"index"=>{"_index"=>"norcalx1", "_type"=>"doc", "_id"=>"cclL6GgBpI0vWuktYEZR", "status"=>400, "error"=>{"type"=>"illegal_argument_exception", "reason"=>"mapper [volumes.lun-mapping-list] of different type, current_type [long], merged_type [text]`

I am trying to pull data from a restfulAPI using http\_poller. So far i have had no success. the fields it is having issues on are not really useful info so i tried to remove them with remove\_field and tried mutate. that seem to have no effect. I must be not doing something right. semi new to ELK and logstash. I did some research and noticed logstash and elastic dont like nested arrays. i am sure i am missing something easy. Thankyou for you help

here is my config file:

```
input {
http_poller {
urls => {
   norcalxio => {
    # Supports all options supported by ruby's Manticore HTTP client
    method => get
    user => "user"
    password => "password"
    url => "https://X.X.X.X/api/json/v3/types/volumes?full=1"
    headers => {
      Accept => "application/json"
    }
     }
    }
    request_timeout => 60
    # Supports "cron", "every", "at" and "in" schedules by rufus scheduler
    schedule => { cron => "* * * * * UTC"}
        codec => "json"
        # A hash of request metadata info (timing, response headers, etc.) will be sent here
        metadata_target => "http_poller_metadata"
        cacert => "/etc/logstash/website.cer"
      }
    }

    filter {
            json {
                    remove_field => ["volumes.lun-mapping-list", "volumes.vol-id", "volumes.xms-id", "volumes.snapgrp-id", "volumes.sys-id"]
                    source => "message"
                    }        
    }

    output {
      elasticsearch {
            hosts => ["http://X.X.X.X:9200"]
            action => "index"
    index => "arrayx1"
      }
      stdout { codec => rubydebug }
    }

```

here is a sample of the data logstash is pulling in:

```
    {
        "params": {
            "id-property": "vol-id"
        }, 
        "volumes": [
            {
                "small-io-alerts": "disabled", 
                "last-refreshed-from-obj-name": null, 
                "obj-severity": "information", 
                "rd-bw": "11", 
                "iops": "43", 
                "replication-wr-bw-kbps": 0, 
        "qos-effective-bw": null, 
        "lb-size": 512, 
        "qos-exceeded-iops": "0", 
        "unaligned-rd-iops": "0", 
        "vaai-tp-alerts": "enabled", 
        "unaligned-io-alerts": "disabled", 
        "qos-exceeded-bw": "0", 
        "unique-physical-space": "0", 
        "tag-list": [], 
        "unaligned-io-ratio": "54", 
        "lun-mapping-list": [
                    [
                        [
                            "2c571a17371c48c5a96f1d3d8fe7c952", 
                            "dell_r640_esxi_cluster", 
                            2
                        ], 
                        [
                            "3635e0f1a92e4868a4df1cac9f6630ae", 
                            "Default", 
                            1
                        ], 
                                1
                    ]
                ], 
                "wr-iops": "39"
    }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 15, 2019, 10:42pm UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-could-not-index-event-to-elasticsearch-reason-mapper-of-different-type-current-type-long-merged-type-text/168279/2 "2019-02-15T22:42:58Z")

</div>

> [@SuperTomcat1](#):
>
> i tried to remove them with remove\_field and tried mutate. that seem to have no effect. I must be not doing something right.

I posted what was wrong with that filter in the other thread. Please do not open multiple threads for the same issue.

---

<div class="post-metadata">

**Author:** ![SuperTomcat1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/supertomcat1/32/40899_2.png) [@SuperTomcat1](https://discuss.elastic.co/u/SuperTomcat1)\
**Post date:** [February 17, 2019, 1:07am UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-could-not-index-event-to-elasticsearch-reason-mapper-of-different-type-current-type-long-merged-type-text/168279/3 "2019-02-17T01:07:06Z")

</div>

NP badger, problem was resolved thanks to you in other thread! Here is a link for anyone in the future that might run into this issue.

> [@Logstash filter mutate remove\_field inside of an array](https://discuss.elastic.co/t/logstash-filter-mutate-remove-field-inside-of-an-array/168503):
>
> so i was trying to filter out all references to "volumes.lun-mapping-list" in my json http\_poller input. so this field repeats multiple times but the data is not valuable and its an array inside of the an array so ES doesnt like that at all with the index. Here is my filter i was trying... filter { mutate { remove\_field =\> ["[volumes][lun-mapping-list]0"] } json { source =\> "message" } } which above does NOT wo…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2019, 1:07am UTC](https://discuss.elastic.co/t/logstash-to-elastic-search-could-not-index-event-to-elasticsearch-reason-mapper-of-different-type-current-type-long-merged-type-text/168279/4 "2019-03-17T01:07:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
