# Mapper parsing exception - failed to parse field

**URL:** <https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040>\
**Category:** Logstash\
**Created:** [April 9, 2022, 9:12pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040 "2022-04-09T21:12:40Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robert777](https://avatars.discourse-cdn.com/v4/letter/r/53a042/32.png) [@Robert777](https://discuss.elastic.co/u/Robert777)\
**Post date:** [April 9, 2022, 9:12pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040/1 "2022-04-09T21:12:40Z")

</div>

Hello, could you please advise what this problem is related to and how to solve it?  
Below is a snippet of the warning I am getting from logstash.  
A little situational description, we have a large number of microservices on k8, they send logs to stdout where they are collected by filebeat and directed to logstash and then ES. The problem described below affects only 1 or 2% of the services. Of the remaining number of services, about 98% of the logs are delivered to ES without problem. It is a mystery to me where to look for the cause and what it could be.

```auto
[2022-03-24T11:59:22,689][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"json-k8-2022.03.24", :_type=>"_doc", :_routing=>nil}, #<LogStash::Event:0x55ed7bfa>], :response=>{"index"=>{"_index"=>"json-k8-2022.03.24", "_type"=>"_doc", "_id"=>"9APLu38Bt4zdiU7zsGs7", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [level] of type [long] in document with id '9APLu38Bt4zdiU7zsGs7'. Preview of field's value: 'INFO'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"For input string: \"INFO\""}}}}}

```

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [April 9, 2022, 9:21pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040/2 "2022-04-09T21:21:58Z")

</div>

Hi @Robert777 , welcome!

> [@Robert777](#):
>
> `"reason"=>"failed to parse field [level] of type [long]`

Have you checked the data as it looks like a mapping issue

---

<div class="post-metadata">

**Author:** ![Robert777](https://avatars.discourse-cdn.com/v4/letter/r/53a042/32.png) [@Robert777](https://discuss.elastic.co/u/Robert777)\
**Post date:** [April 9, 2022, 9:28pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040/3 "2022-04-09T21:28:24Z")

</div>

Do you mean checking the data (logs) that are generated in the service? Could you please elaborate further on your question?

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [April 9, 2022, 9:33pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040/4 "2022-04-09T21:33:01Z")

</div>

Correct, checking the data and that the field with the issue is consistently of the correct type - LONG

---

<div class="post-metadata">

**Author:** ![Robert777](https://avatars.discourse-cdn.com/v4/letter/r/53a042/32.png) [@Robert777](https://discuss.elastic.co/u/Robert777)\
**Post date:** [April 9, 2022, 9:42pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040/5 "2022-04-09T21:42:05Z")

</div>

I will try to check it out in the next few days.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 9, 2022, 11:03pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040/6 "2022-04-09T23:03:59Z")

</div>

> [@Robert777](#):
>
> `Preview of field's value: 'INFO'"`

In elasticsearch you either created a mapping that tells it that [level] should be a number, or dynamic mapping has decided that the field should be long, due to the value in the first document indexed that included that field. It cannot parse "INFO" as a long.

---

<div class="post-metadata">

**Author:** ![Robert777](https://avatars.discourse-cdn.com/v4/letter/r/53a042/32.png) [@Robert777](https://discuss.elastic.co/u/Robert777)\
**Post date:** [April 10, 2022, 9:04am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040/7 "2022-04-10T09:04:55Z")

</div>

@Badger  
Do you think the value type for [level] to other than LONG type can be or should be changed in the microservice? It looks like ES somehow decides why it dynamically assigned the LONG type. Or what would be the preferred solution so that the change does not affect other logging services?  
I would prefer the change to be possible at the service level so that it does not affect other service that are logging correctly into the same index.  
I am not an expert on the subject and my questions may be imprecise, but I am looking for all possible advice.

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [April 10, 2022, 9:13am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040/8 "2022-04-10T09:13:58Z")

</div>

@Robert777

Maybe change the field to string?

Or via Logstash do some mutations ?

---

<div class="post-metadata">

**Author:** ![Robert777](https://avatars.discourse-cdn.com/v4/letter/r/53a042/32.png) [@Robert777](https://discuss.elastic.co/u/Robert777)\
**Post date:** [April 10, 2022, 9:20am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040/9 "2022-04-10T09:20:13Z")

</div>

@zx8086  
Yes I'll investigate both suggestions.

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [April 10, 2022, 9:44am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040/10 "2022-04-10T09:44:23Z")

</div>

@Robert777

When you have numbers and strings, like i do, i normalise the log.level this way, as an example

```auto
    if [log.level] =~ "1" 
      {
        mutate
          {
            replace =>
              {
                "log.level" => "Error"
              }
            }
        }

    if [log.level] =~ "2" 
      {
        mutate {
          replace => 
            {
              "log.level" => "Warning"
            }
        }
      }

    if [log.level] =~ "3" 
      {
        mutate {
          replace => 
            {
              "log.level" => "Info"
            }
        }
      }

    if [log.level] =~ "4" 
      {
        mutate {
          replace => 
            {
              "log.level" => "Trace"
            }
        }
      }

    if [log.level] =~ "5" 
      {
        mutate {
          replace => 
            {
              "log.level" => "File Event"
            }
        }
      }

  }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2022, 9:44am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse-field/302040/11 "2022-05-08T09:44:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
