# Mapper\_parsing\_exception Using GelfD and Logstash

**URL:** <https://discuss.elastic.co/t/mapper-parsing-exception-using-gelfd-and-logstash/143450>\
**Category:** Logstash\
**Created:** [August 8, 2018, 8:03am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-using-gelfd-and-logstash/143450 "2018-08-08T08:03:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Or\_Arnon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/or_arnon/32/43677_2.png) [@Or\_Arnon](https://discuss.elastic.co/u/Or_Arnon)\
**Post date:** [August 8, 2018, 8:03am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-using-gelfd-and-logstash/143450/1 "2018-08-08T08:03:00Z")

</div>

We're using GelfD to ship our logs and although nothing has changed, we get these errors:

> [2018-08-07T13:50:57,225][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-gelf2kafka-2018.08.07", :\_type=\>"logs", :\_routing=\>nil}, 2018-08-07T13:50:56.751Z auto1-task-scheduler.sonic-dev.us-east-1 task scheduler fetched tasks:], :response=\>{"index"=\>{"\_index"=\>"logstash-gelf2kafka-2018.08.07", "\_type"=\>"logs", "\_id"=\>"AWUUp6rIWiXbnjb5AibS", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"object mapping for [host] tried to parse field [host] as object, but found a concrete value"}}}}

We run:  
Elasticsearch 5.4.2  
Logstash 5.4.2

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [August 8, 2018, 4:48pm UTC](https://discuss.elastic.co/t/mapper-parsing-exception-using-gelfd-and-logstash/143450/2 "2018-08-08T16:48:29Z")

</div>

> [@Or\_Arnon](#):
>
> object mapping for [host] tried to parse field [host] as object, but found a concrete value

The error is raised by Elasticsearch; Logstash is attempting to insert a string-valued `host` field, but the Elasticsearch index already has a field called `host` that contains an _object_ (likely with sub-fields like `name`, `ip`, etc.).

There have been some recent conflicts with various plugins and data sources attempting to use the `host` field in different ways that work fine independently, but clash as above when used together.

There has been effort to define an "Elastic Common Schema" (ECS) to ensure we don't have these conflicts between plugins; the ECS defines the `host` field as an object with a variety of sub-keys that provide more information about the host in question.

Do you have other things pushing into the index (e.g., Beats via Elasticsearch Ingest Node)? Does the index's mapping template define host explicitly?

Moving the string-value `host` field to a non-clashing field such as `source.ip` prior to output may be a suitable workaround:

```auto
filter {
  mutate {
    rename => { "[host]" => "[source][ip]" }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Or\_Arnon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/or_arnon/32/43677_2.png) [@Or\_Arnon](https://discuss.elastic.co/u/Or_Arnon)\
**Post date:** [August 9, 2018, 7:19am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-using-gelfd-and-logstash/143450/3 "2018-08-09T07:19:01Z")

</div>

Hi,  
Thank you for elaborating. I have seen this in some other context so I went ahead and checked our Elasticsearch mapping for this index. It looks like we're expecting a string based host field.

```auto
"host": {
            "properties": {
              "name": {
                "type": "text",
                "norms": false,
                "fields": {
                  "raw": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              }
            }

```

And there's hostname that comes with beat probably but again, it's a different field

```auto
"beat": {
            "properties": {
              "hostname": {
                "type": "text",
                "norms": false,
                "fields": {
                  "raw": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              },
              "ip": {
                "type": "text",
                "norms": false,
                "fields": {
                  "raw": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              },
              "name": {
                "type": "text",
                "norms": false,
                "fields": {
                  "raw": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              },

```

---

<div class="post-metadata">

**Author:** ![Or\_Arnon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/or_arnon/32/43677_2.png) [@Or\_Arnon](https://discuss.elastic.co/u/Or_Arnon)\
**Post date:** [August 9, 2018, 8:03am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-using-gelfd-and-logstash/143450/4 "2018-08-09T08:03:26Z")

</div>

When I'm trying to see what object I'm getting, it fails as well:

```auto
rename => { "host" => "testfield" }

```

---

<div class="post-metadata">

**Author:** ![Or\_Arnon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/or_arnon/32/43677_2.png) [@Or\_Arnon](https://discuss.elastic.co/u/Or_Arnon)\
**Post date:** [August 9, 2018, 8:28am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-using-gelfd-and-logstash/143450/5 "2018-08-09T08:28:46Z")

</div>

As it turns out, we were confused between the filebeat object and the host.name object.  
When we looked into another index which has only filebeat as an input source so now we have converted host to host.name

```auto
rename => { "host" => "[host][name]" }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 6, 2018, 8:36am UTC](https://discuss.elastic.co/t/mapper-parsing-exception-using-gelfd-and-logstash/143450/6 "2018-09-06T08:36:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
