# Mapper\_parsing\_exception for timestamp field

**URL:** <https://discuss.elastic.co/t/mapper-parsing-exception-for-timestamp-field/87159>\
**Category:** Logstash\
**Created:** [May 25, 2017, 5:01pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-for-timestamp-field/87159 "2017-05-25T17:01:39Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dee/32/18876_2.png) [@Dee](https://discuss.elastic.co/u/Dee)\
**Post date:** [May 25, 2017, 5:01pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-for-timestamp-field/87159/1 "2017-05-25T17:01:39Z")

</div>

Hi,  
For some reason logstash can't parse a field called timestamp in my json events in some environments (on other environments it works fine)  
This is the error I see in logstash logs:

"error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse [timestamp]", "caused\_by"=\>{"type"=\>"number\_format\_exception", "reason"=\>"For input string: "25-05-2017 11:44:09.953""}}}}, :level=\>:warn}

First thing I though was different mappings but the mappings are the same for all environments.  
Any idea what can cause this sporadic behavior? And what is the meaning of this error?

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 29, 2017, 5:25am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-for-timestamp-field/87159/2 "2017-05-29T05:25:18Z")

</div>

Well, what is the mapping of the `timestamp` field?

---

<div class="post-metadata">

**Author:** ![Dee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dee/32/18876_2.png) [@Dee](https://discuss.elastic.co/u/Dee)\
**Post date:** [June 7, 2017, 9:05am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-for-timestamp-field/87159/3 "2017-06-07T09:05:15Z")

</div>

This is the mapping for @timestamp field:  
"@timestamp":{"type":"date","format":"strict\_date\_optional\_time||epoch\_millis"}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 7, 2017, 9:44am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-for-timestamp-field/87159/4 "2017-06-07T09:44:29Z")

</div>

That's the `@timestamp` field. The log entry you posted shows ES complaining about the `timestamp` field.

---

<div class="post-metadata">

**Author:** ![Dee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dee/32/18876_2.png) [@Dee](https://discuss.elastic.co/u/Dee)\
**Post date:** [June 7, 2017, 10:05am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-for-timestamp-field/87159/5 "2017-06-07T10:05:22Z")

</div>

I see, checking again I see that I really don't have any mapping for a field called "timestamp". In another environment where I see no exceptions I do see this in my mapping:  
"timestamp":{"type":"string","norms":{"enabled":false}

Could this be the issue? My index templates in both environments are the same, so how could this happen?

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 7, 2017, 10:16am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-for-timestamp-field/87159/6 "2017-06-07T10:16:18Z")

</div>

Unless you list `timestamp` in your index template (and you haven't disabled the automapper) ES will automatically try to map the field. It's weird that it complains about this field if it doesn't have a mapping.

Do you really want to keep the `timestamp` field? It looks like a temporary field where you've stored the timestamp from the log so that you can parse it with the date filter. If so I'd just delete the field. If you want to keep it, how about adding an explicit mapping in your index template? You can make it a date field and configure it to support your date format.

---

<div class="post-metadata">

**Author:** ![Dee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dee/32/18876_2.png) [@Dee](https://discuss.elastic.co/u/Dee)\
**Post date:** [June 7, 2017, 11:27am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-for-timestamp-field/87159/7 "2017-06-07T11:27:58Z")

</div>

In my json events I am actually looking for a "time" field and parse it, then removing it-

date {  
match =\> ["time", "ISO8601", "dd-MM-yyyy HH:mm:ss", "dd-MM-yyyy HH:mm:ss:SSS", "dd-MM-yyyy HH:mm:ss.SSS", "yyyy-MM-dd HH:mm:ss,SSS", "HH:mm:ss"]  
remove\_field =\> ["time"]  
}

I think i'll add a line to match "timestamp" as well, and remove it afterwards.  
It's just weird to me that on one environment I don't get these exceptions and on another one I do.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:27am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-for-timestamp-field/87159/8 "2017-07-05T11:27:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
