# Mapper parsing exeption logstash

**URL:** <https://discuss.elastic.co/t/mapper-parsing-exeption-logstash/223108>\
**Category:** Logstash\
**Created:** [March 11, 2020, 11:24am UTC](https://discuss.elastic.co/t/mapper-parsing-exeption-logstash/223108 "2020-03-11T11:24:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![calanon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/calanon/32/64004_2.png) [@calanon](https://discuss.elastic.co/u/calanon)\
**Post date:** [March 11, 2020, 11:24am UTC](https://discuss.elastic.co/t/mapper-parsing-exeption-logstash/223108/1 "2020-03-11T11:24:59Z")

</div>

Hi I am receiving this error message. I have been searching for hours where the problem is but I cannot find it. Is there a method to finding exactly where the problem is occurring?

M`är 11 12:21:16 mon logstash[16980]: [2020-03-11T12:21:16,291][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"var_log-2020.03.11", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x6354a9d5>], :response=>{"index"=>{"_index"=>"var_log-2020.03.11", "_type"=>"_doc", "_id"=>"XdBTyXABRKnuFwD_yIyg", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [timestamp] of type [date] in document with id 'XdBTyXABRKnuFwD_yIyg'. Preview of field's value: '20200311 122115'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"failed to parse date field [20200311 122115] with format [yyyy/MM/dd HH:mm:ss||yyyy/MM/dd||epoch_millis]", "caused_by"=>{"type"=>"date_time_parse_exception", "reason"=>"Failed to parse with all enclosed parsers"}}}}}}`

---

<div class="post-metadata">

**Author:** ![calanon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/calanon/32/64004_2.png) [@calanon](https://discuss.elastic.co/u/calanon)\
**Post date:** [March 11, 2020, 12:09pm UTC](https://discuss.elastic.co/t/mapper-parsing-exeption-logstash/223108/2 "2020-03-11T12:09:52Z")

</div>

Update:

I notice in the kibana index mapping json output I have this in one of the indexes:

```
 "timestamp": {
          "type": "date",
          "format": "yyyy/MM/dd HH:mm:ss||yyyy/MM/dd||epoch_millis"
        }

```

How can I remove this because on previous days the entry does not exist.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 11, 2020, 3:08pm UTC](https://discuss.elastic.co/t/mapper-parsing-exeption-logstash/223108/3 "2020-03-11T15:08:58Z")

</div>

> [@calanon](#):
>
> on previous days the entry does not exist

What did the mapping look like previously?

---

<div class="post-metadata">

**Author:** ![calanon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/calanon/32/64004_2.png) [@calanon](https://discuss.elastic.co/u/calanon)\
**Post date:** [March 11, 2020, 7:50pm UTC](https://discuss.elastic.co/t/mapper-parsing-exeption-logstash/223108/4 "2020-03-11T19:50:47Z")

</div>

This entry was not there

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 8, 2020, 7:50pm UTC](https://discuss.elastic.co/t/mapper-parsing-exeption-logstash/223108/5 "2020-04-08T19:50:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
