# Mapper\_parsing\_exception in filebeat logs suddenly

**URL:** <https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 16, 2018, 11:00am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277 "2018-03-16T11:00:57Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kamal\_Raj](https://avatars.discourse-cdn.com/v4/letter/k/a5b964/32.png) [@Kamal\_Raj](https://discuss.elastic.co/u/Kamal_Raj)\
**Post date:** [March 16, 2018, 11:00am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/1 "2018-03-16T11:00:57Z")

</div>

Suddenly from midnight yesterday, stopped seeing logs in Kibana, and Filebeat logs has the following. Didnot do any change. Please help

2018-03-16T14:43:56+05:30 WARN Can not index event (status=400): {"type":"mapper\_parsing\_exception","reason":"Failed to parse mapping [doc]: Mapping definition for [error] has unsupported parameters: [properties : {code={type=long}, message={norms=false, type=text}, type={ignore\_above=1024, type=keyword}}]","caused\_by":{"type":"mapper\_parsing\_exception","reason":"Mapping definition for [error] has unsupported parameters: [properties : {code={type=long}, message={norms=false, type=text}, type={ignore\_above=1024, type=keyword}}]"}}  
2018-03-16T14:43:56+05:30 WARN Can not index event (status=400): {"type":"mapper\_parsing\_exception","reason":"Failed to parse mapping [doc]: Mapping definition for [error] has unsupported parameters: [properties : {code={type=long}, message={norms=false, type=text}, type={ignore\_above=1024, type=keyword}}]","caused\_by":{"type":"mapper\_parsing\_exception","reason":"Mapping definition for [error] has unsupported parameters: [properties : {code={type=long}, message={norms=false, type=text}, type={ignore\_above=1024, type=keyword}}]"}}

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 16, 2018, 12:02pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/2 "2018-03-16T12:02:38Z")

</div>

Which filebeat version(s) are you running? This looks like a mapping conflict on the `error` field. This can be the case if filebeat 6.x is being run with a 5.x template mapping in Elasticsearch.

Check if you have multiple mapping templates, which will match `filebeat`. The mapping is versioned in newer filebeat versions. But old templates still match on `filebeat-*`.

---

<div class="post-metadata">

**Author:** ![Kamal\_Raj](https://avatars.discourse-cdn.com/v4/letter/k/a5b964/32.png) [@Kamal\_Raj](https://discuss.elastic.co/u/Kamal_Raj)\
**Post date:** [March 16, 2018, 12:31pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/3 "2018-03-16T12:31:25Z")

</div>

Yes, I think I tried installing Filebeat 5x in one of the servers and that lead to this template mismatch. This actually blocked logs push from other servers too, where Filebeat 6x was originally installed..

Having said that, whats the solution here Steffens

Thanks

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [March 16, 2018, 3:53pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/4 "2018-03-16T15:53:34Z")

</div>

Not sure which beats version we introduced versioning. At least filebeat version 5.6 should already version the template mapping and index names.

First of all, [find the name](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html#getting) of the wrong template mapping. Then [delete the template mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html#delete) installed by filebeat 5.x. As todays index has been generated with a wrong mapping, you have to delete the [affected index as well](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-delete-index.html), so a new index with the correct mapping can be created.

If you plan to run filebeat 5.x next to 6.x, only use 5.6. Also check configs actually using the version in the template mapping using versions. Otherwise you might run into the issue again.

---

<div class="post-metadata">

**Author:** ![Kamal\_Raj](https://avatars.discourse-cdn.com/v4/letter/k/a5b964/32.png) [@Kamal\_Raj](https://discuss.elastic.co/u/Kamal_Raj)\
**Post date:** [March 19, 2018, 5:10am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/5 "2018-03-19T05:10:00Z")

</div>

Thanks Steffens  
However my Kibana console always throws an error "Failed to connect to Console's backend.  
Please check the Kibana server is up and running", preventing me from doing the recommended amendments. Could you please suggest an alternative or a way to fix the kibana console error

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 19, 2018, 9:59am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/6 "2018-03-19T09:59:35Z")

</div>

Alternatively you can do the fix over curl.

For your console kibana issue: Does Kibana all work besides that issue?

---

<div class="post-metadata">

**Author:** ![Kamal\_Raj](https://avatars.discourse-cdn.com/v4/letter/k/a5b964/32.png) [@Kamal\_Raj](https://discuss.elastic.co/u/Kamal_Raj)\
**Post date:** [March 19, 2018, 10:17am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/7 "2018-03-19T10:17:15Z")

</div>

Yes. Kibana all works beside that issue

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 19, 2018, 10:21am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/8 "2018-03-19T10:21:36Z")

</div>

I don't think this issue is Beats related. Could you post it into the Kibana forum: [https://discuss.elastic.co/c/kibana](https://discuss.elastic.co/c/kibana) Best check your kibana logs if you see some Error messages there. Restarting could also help.

---

<div class="post-metadata">

**Author:** ![Kamal\_Raj](https://avatars.discourse-cdn.com/v4/letter/k/a5b964/32.png) [@Kamal\_Raj](https://discuss.elastic.co/u/Kamal_Raj)\
**Post date:** [March 19, 2018, 10:24am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/9 "2018-03-19T10:24:51Z")

</div>

But Ruflin, If you'd seen my initial comment, it seems to be a version conflict, which is related to Filebeat

---

<div class="post-metadata">

**Author:** ![Kamal\_Raj](https://avatars.discourse-cdn.com/v4/letter/k/a5b964/32.png) [@Kamal\_Raj](https://discuss.elastic.co/u/Kamal_Raj)\
**Post date:** [March 20, 2018, 12:17pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/10 "2018-03-20T12:17:07Z")

</div>

Hello Ruflin, Please help. Tried every possible thing to solve this.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 21, 2018, 7:44am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/11 "2018-03-21T07:44:25Z")

</div>

Yes, the conflict you posted in your first post is related to a version conflict in Filebeat. But the one you posted that you can't open Console I can't see how it could be related. I'm redirecting you to the Kibana only for the COnsole issue, not the one in your first post.

As recommended earlier, if you can't use Console to put in your commands, best use curl from the command line to remove the templates.

---

<div class="post-metadata">

**Author:** ![Kamal\_Raj](https://avatars.discourse-cdn.com/v4/letter/k/a5b964/32.png) [@Kamal\_Raj](https://discuss.elastic.co/u/Kamal_Raj)\
**Post date:** [March 21, 2018, 12:40pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/12 "2018-03-21T12:40:57Z")

</div>

Thanks Ruflin, It worked. Now I am able to see data. But unfortunately, the older data just disappeared. Is there a way to retrieve the older data as well. Thanks in advance

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [March 22, 2018, 1:25pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/13 "2018-03-22T13:25:34Z")

</div>

Great to hear we are moving forward. Which commands did you exactly run? Did you delete the indices? If yes the old data is done. If no, you should still see the old data if change the time frame in kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2018, 1:25pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-in-filebeat-logs-suddenly/124277/14 "2018-04-19T13:25:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
