# Mapper\_parsing\_exception on data from AWS Lambda

**URL:** <https://discuss.elastic.co/t/mapper-parsing-exception-on-data-from-aws-lambda/201806>\
**Category:** Elasticsearch\
**Created:** [October 1, 2019, 1:15pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-on-data-from-aws-lambda/201806 "2019-10-01T13:15:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arty\_Sidorenko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arty_sidorenko/32/53190_2.png) [@Arty\_Sidorenko](https://discuss.elastic.co/u/Arty_Sidorenko)\
**Post date:** [October 1, 2019, 1:15pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-on-data-from-aws-lambda/201806/1 "2019-10-01T13:15:21Z")

</div>

I'm trying to send http logs from AWS Cloudwatch to ES (Kibana), and a large chunk of logs are not being sent with the following error message:

```
mapper_parsing_exception, "reason":"object mapping for [responseData.client] tried to parse field [client] as object, but found a concrete value

```

I've tried to force my logs to stringify responseData.client so that it's always a string, however the error is persisting.

The index that AWS is sending to is incremented every day (it's called cwl-\<today's date\>) so my understanding was that it would create a new index after the change I implemented and keep the responseData.client field as a string, but it appears not to be working.

Is there a way to force ES to keep this field as a string?

Thank you!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 1, 2019, 4:31pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-on-data-from-aws-lambda/201806/2 "2019-10-01T16:31:34Z")

</div>

Yes, create an index template with the desired mapping.

---

<div class="post-metadata">

**Author:** ![Arty\_Sidorenko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arty_sidorenko/32/53190_2.png) [@Arty\_Sidorenko](https://discuss.elastic.co/u/Arty_Sidorenko)\
**Post date:** [October 1, 2019, 5:14pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-on-data-from-aws-lambda/201806/3 "2019-10-01T17:14:58Z")

</div>

Thanks, there are two things I am concerned about before attempting this change:

- there are 2000+ different fields in that index: do I need to include them all in the index template? Can I send a mapping for the problematic field only?
- a new index is being created every day - my understanding is that its mappings are a function of whatever data it is sent from AWS (apologies for my lack of knowledge but I inherited this process and am not sure how it was initially set up). Could my mapping that I submit for, for example “cwl-01-10-2019”, get overwritten the next day when the index “cwl-02-10-2019” is initialised?

Thanks again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2019, 5:15pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-on-data-from-aws-lambda/201806/4 "2019-10-29T17:15:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
