# Mapper\_parsing\_exception & failed to parse

**URL:** <https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse/120540>\
**Category:** Logstash\
**Created:** [February 20, 2018, 12:35am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse/120540 "2018-02-20T00:35:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [February 20, 2018, 12:35am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse/120540/1 "2018-02-20T00:35:25Z")

</div>

I'm trying to use [Json filter plugin | Logstash Reference](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html#plugins-filters-json-source):

```
filter {
  json {
    skip_on_invalid_json => true
    source => "message"
  }
}

```

logstash log - getting bombarded with similar messages:

`logstash11 | [2018-02-20T03:23:10,028][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"logstash-2018.02.20", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x62f0c359>], :response=>{"index"=>{"_index"=>"logstash-2018.02.20", "_type"=>"doc", "_id"=>"Qos8sWEBfs5EPH_FiQVE", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [level]", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"For input string: \"DEBUG\""}}}}}`

via Dev Tools:

> GET /logstash-2018.02.20/doc/Qos8sWEBfs5EPH\_FiQVE

```
{
  "_index": "logstash-2018.02.20",
  "_type": "doc",
  "_id": "Qos8sWEBfs5EPH_FiQVE",
  "found": false
}

```

* * *

1. at least one of the issue here is due to trying to save _string_ instead of _numerical_ value, hence warning.
2. the other issue is due to the fact that messages are being dropped and never making into _elasticsearch_ - is it outcome of first issue?

Please advise.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 20, 2018, 8:51pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse/120540/2 "2018-02-20T20:51:57Z")

</div>

1. If the `level` field has been mapped as a number and you're trying to index documents where that field contains a non-number then that's certainly the cause of this.
2. Yes. Events will be dropped unless you've configured the dead letter queue feature.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [February 21, 2018, 3:43pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse/120540/3 "2018-02-21T15:43:15Z")

</div>

1. Ok, I was right)
2. [Dead Letter Queues | Logstash Reference [6.2] | Elastic](https://www.elastic.co/guide/en/logstash/current/dead-letter-queues.html))

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2018, 3:43pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-failed-to-parse/120540/4 "2018-03-21T15:43:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
