# Metricbeat kubernetes WARN unable to index event

**URL:** <https://discuss.elastic.co/t/metricbeat-kubernetes-warn-unable-to-index-event/147092>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [September 3, 2018, 2:25pm UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-warn-unable-to-index-event/147092 "2018-09-03T14:25:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alex\_Armstrong](https://avatars.discourse-cdn.com/v4/letter/a/da6949/32.png) [@Alex\_Armstrong](https://discuss.elastic.co/u/Alex_Armstrong)\
**Post date:** [September 3, 2018, 2:25pm UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-warn-unable-to-index-event/147092/1 "2018-09-03T14:25:54Z")

</div>

We only have one warning level error being logged by metricbeat which stated as unable to index an event with a mapper\_parsing\_exception. Could you please advise on how to correct this.

log sample:  
`2018-09-03T14:13:05.055Z	WARN	elasticsearch/client.go:520	Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0xbedb6e3b9d530d18, ext:122658578627, loc:(*time.Location)(0x37d2d20)}, Meta:common.MapStr(nil), Fields:common.MapStr{"beat":common.MapStr{"name":"ip-120-0-12-235", "hostname":"ip-120-0-12-235", "version":"6.4.0"}, "host":common.MapStr{"name":"ip-120-0-12-235"}, "meta":common.MapStr{"cloud":common.MapStr{"instance_id":"i-00c63fa0e261452f6", "machine_type":"c5.xlarge", "region":"us-east-1", "availability_zone":"us-east-1b", "provider":"ec2"}}, "metricset":common.MapStr{"rtt":1806499, "namespace":"kubernetes.container", "name":"state_container", "module":"kubernetes", "host":"kube-state-metrics.monitoring.svc:8080"}, "kubernetes":common.MapStr{"namespace":"env-stg", "pod":common.MapStr{"name":"app-proxy-7d459f4d88-rd7vp"}, "node":common.MapStr{"name":"ip-120-0-12-235.us-east-1.compute.internal"}, "labels":common.MapStr{"role":"proxy", "env":"env-stg", "k8s-app":"app", "pod-template-hash":"3801590844"}, "container":common.MapStr{"id":"docker://38b4dc42ad8cda23b80f364872286016a133a59d69bf3d7f4ecf0462b1ca6739", "name":"nginx", "status":common.MapStr{"phase":"running", "restarts":0, "ready":true}, "image":"accountno.dkr.ecr.us-east-1.amazonaws.com/registry/nginx:latest"}}}, Private:interface {}(nil)}, Flags:0x0} (status=400): {"type":"mapper_parsing_exception","reason":"object mapping for [kubernetes.labels.role] tried to parse field [role] as object, but found a concrete value"}`

---

<div class="post-metadata">

**Author:** ![exekias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exekias/32/28718_2.png) [@exekias](https://discuss.elastic.co/u/exekias)\
**Post date:** [September 4, 2018, 10:03am UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-warn-unable-to-index-event/147092/2 "2018-09-04T10:03:57Z")

</div>

Hi Alex\_Armstrong,

It looks like `role` label is used in different ways across your cluster, where some use `role.something: value` and this pod uses `role: value`. Sounds like this is the case?

As dots represent nesting in Elasticsearch, this is causing mapping issues (`role` is expected to be an object as for previous documents). You can use `rename` processor to rename `role` to something else that won't break the mapping: [https://www.elastic.co/guide/en/beats/metricbeat/current/rename-fields.html](https://www.elastic.co/guide/en/beats/metricbeat/current/rename-fields.html)

Best regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2018, 10:03am UTC](https://discuss.elastic.co/t/metricbeat-kubernetes-warn-unable-to-index-event/147092/3 "2018-10-02T10:03:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
