# Mapper error even though no mapping is present

**URL:** <https://discuss.elastic.co/t/mapper-error-even-though-no-mapping-is-present/211203>\
**Category:** Elasticsearch\
**Created:** [December 9, 2019, 11:18pm UTC](https://discuss.elastic.co/t/mapper-error-even-though-no-mapping-is-present/211203 "2019-12-09T23:18:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![braem](https://avatars.discourse-cdn.com/v4/letter/b/ed8c4c/32.png) [@braem](https://discuss.elastic.co/u/braem)\
**Post date:** [December 9, 2019, 11:18pm UTC](https://discuss.elastic.co/t/mapper-error-even-though-no-mapping-is-present/211203/1 "2019-12-09T23:18:02Z")

</div>

Logstash trying to insert a document into the index of elastic search will result in the following error:  
`"error"=>{"type"=>"illegal_argument_exception", "reason"=>"mapper [msg.Fwd Header Length] of different type, current_type [long], merged_type [ObjectMapper]"}`  
that even though the index is empty and there is no mapping predefined and retrieving the mapping of the index returns:  
`{ "mapping": {} }`  
I'm running logstash and elasticsearch 7.5 but the same problem was already present before upgrading (both on version 7.4.2)  
I'm really not sure where the problem lies. And any help is appreciated

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 10, 2019, 12:21am UTC](https://discuss.elastic.co/t/mapper-error-even-though-no-mapping-is-present/211203/2 "2019-12-10T00:21:18Z")

</div>

If there is no mapping template that matches the index name then the field type is set by the first document that contains the field. Are you saying that you are getting a mapping exception on the first document that is indexed?

By the way, you might get a better response in the elasticsearch forum: this error is actually occuring in elasticsearch and just being reported by logstash.

---

<div class="post-metadata">

**Author:** ![braem](https://avatars.discourse-cdn.com/v4/letter/b/ed8c4c/32.png) [@braem](https://discuss.elastic.co/u/braem)\
**Post date:** [December 10, 2019, 12:38am UTC](https://discuss.elastic.co/t/mapper-error-even-though-no-mapping-is-present/211203/3 "2019-12-10T00:38:39Z")

</div>

Yes strangely enough thats what happens, as after leaving logstash parsing the whole log I still have an empty index...

> [@Badger](#):
>
> By the way, you might get a better response in the elasticsearch forum: this error is actually occuring in elasticsearch and just being reported by logstash.

Yes makes sense. Is there some way to move this topic to the elasticsearch forum?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 10, 2019, 12:55am UTC](https://discuss.elastic.co/t/mapper-error-even-though-no-mapping-is-present/211203/4 "2019-12-10T00:55:43Z")

</div>

I believe that the author can move a post from one forum to another. Not sure how.

What does the event look like in?...

```
output { stdout { codec => rubydebug} }

```

Is there a [msg.Fwd Header Length] field whose name contains a period, or is it a [msg] object that contains a [Fwd Header Length] field? Or both 🙂

---

<div class="post-metadata">

**Author:** ![braem](https://avatars.discourse-cdn.com/v4/letter/b/ed8c4c/32.png) [@braem](https://discuss.elastic.co/u/braem)\
**Post date:** [December 17, 2019, 10:18pm UTC](https://discuss.elastic.co/t/mapper-error-even-though-no-mapping-is-present/211203/5 "2019-12-17T22:18:18Z")

</div>

Looking through the event, I found that there is an error in the script writing the logs, as it duplicated the [Fwd Header Length] field and adding it once as [Fwd Header Length] to the [msg] object and once as [Fwd Header Length.1]. Removing that duplication solved the problem and I could feed the logs into Elasticsearch.

So my guess is, that even though the event correctly had [Fwd Header Length.1] as name for the corresponding field and not as an object containing a field [1], Elasticsearch seemed to have read it as an object, that contains a field with the name [1]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 14, 2020, 10:28pm UTC](https://discuss.elastic.co/t/mapper-error-even-though-no-mapping-is-present/211203/6 "2020-01-14T22:28:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
