# Mapper parsing exception from autodiscover docker logs

**URL:** <https://discuss.elastic.co/t/mapper-parsing-exception-from-autodiscover-docker-logs/171551>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 8, 2019, 8:06pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-from-autodiscover-docker-logs/171551 "2019-03-08T20:06:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cova](https://avatars.discourse-cdn.com/v4/letter/c/5f8ce5/32.png) [@Cova](https://discuss.elastic.co/u/Cova)\
**Post date:** [March 8, 2019, 8:06pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-from-autodiscover-docker-logs/171551/1 "2019-03-08T20:06:37Z")

</div>

There seems to be a type conflict with the way the fields get created by filebeat with auto-discovered docker logs, which is causing me to get mapper parsing exceptions from my nginx logs.

I've got a bunch of different containers being monitored by filebeat using autodiscover with hints. One of the first ones I got setup was my elasticsearch container, which has these labels set for hints in its docker-compose file:

&nbsp;&nbsp;&nbsp;labels:  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;co.elastic.logs/module: elasticsearch  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;co.elastic.logs/fileset: server

The default index template then created an elastic field of type keyword named "docker.container.labels.co.elastic.logs/fileset" which has a value of "server" for those documents.

As I kept working, on my nginx container I added the following labels in its compose file:

&nbsp;&nbsp;&nbsp;labels:  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;co.elastic.logs/module: nginx  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;co.elastic.logs/fileset.stdout: access  
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;co.elastic.logs/fileset.stderr: error

And so it is trying to index an object into the "docker.container.labels.co.elastic.logs/fileset" field that looks more like {"stderr":"error", "stdout":"access"} and getting the parsing exception as a result.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2019, 8:06pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-from-autodiscover-docker-logs/171551/2 "2019-04-05T20:06:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
