# Mapper\_Parsing\_Exception After Logstash Rollback

**URL:** <https://discuss.elastic.co/t/mapper-parsing-exception-after-logstash-rollback/164183>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [January 14, 2019, 6:00pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-after-logstash-rollback/164183 "2019-01-14T18:00:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [January 14, 2019, 6:00pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-after-logstash-rollback/164183/1 "2019-01-14T18:00:22Z")

</div>

We recently rolled back Logstash from 6.5.4 to 6.4.1 due to issues with the geoip plugin. Since then I've seen the below log lines in logstash, the value being mapped changes but it's always the same field. How do I resolve this? We are running Elasticsearch/Kibana 6.5.4 still, if that matters.

`[2019-01-14T11:56:48,122][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"winlogbeat-6.4.1-2019.01.14", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x60f3c3d3>], :response=>{"index"=>{"_index"=>"winlogbeat-6.4.1-2019.01.14", "_type"=>"doc", "_id"=>"mLOCTWgBPHqyIdtlP_Ms", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [event_data.param1] of type [date]", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"Invalid format: \"Remote Registry\""}}}}}`

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [January 14, 2019, 6:16pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-after-logstash-rollback/164183/2 "2019-01-14T18:16:28Z")

</div>

I see in the index mapping that `[event_data][param1]` has two mappings configured. [event\_data] has mappings that go from line 57 to line 2,124. On line 1958:

```
"param1": {
  "type": "date"
},

```

and then again on line 2,405:

```
"param1": {
  "type": "text",
  "fields": {
    "keyword": {
      "type": "keyword",
      "ignore_above": 256
    }
  }
},

```

It appears the earlier mapping is incorrect. How do I remove just this mapping without effecting the entire index template and how did this happen? My logstash pipeline has `manage_template` set to false on the Elasticsearch output, is this the reason this is happening, should it be set to true to prevent this from happening?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [January 14, 2019, 6:31pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-after-logstash-rollback/164183/3 "2019-01-14T18:31:10Z")

</div>

Used the hammer approach, removed the `manage_template` setting, set `template_overwrite => true` and then changed `index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"` to include a 1 after the date to force the generation of a new index and new mappings. The resulting mappings file was reduced from 2,440 lines to 1,632. Not getting mapping errors in the logs anymore.

I'm thinking I set `manage_template` back during initial implementation when I didn't really know what I was doing and it finally came back and bit me. About a weeks worth of unknown logs lost...makes a good argument for getting DLQ configured.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2019, 6:31pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-after-logstash-rollback/164183/4 "2019-02-11T18:31:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
