# Object mapping error for common field name "error"

**URL:** <https://discuss.elastic.co/t/object-mapping-error-for-common-field-name-error/344768>\
**Category:** Logstash\
**Created:** [October 10, 2023, 11:07pm UTC](https://discuss.elastic.co/t/object-mapping-error-for-common-field-name-error/344768 "2023-10-10T23:07:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![true64gurus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/true64gurus/32/107237_2.png) [@true64gurus](https://discuss.elastic.co/u/true64gurus)\
**Post date:** [October 10, 2023, 11:07pm UTC](https://discuss.elastic.co/t/object-mapping-error-for-common-field-name-error/344768/1 "2023-10-10T23:07:07Z")

</div>

Hello,

I am getting the `object mapping ` error. The logs are coming from Kubernetes cluster . On same index , the field " **error**" comes from App1 as json object , while comes as number from app2, comes as "one word string" from app3, and multiple words from app 4.

Looked at solutions on this forum and non of them worked.

- Renaming field moves the problem to new field name.
- Logstash doesn't provide a way to detect field type on pipeline.

Appreciate help

Thanks  
`"status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [error] tried to parse field [error] as object, but found a concrete value"}}}`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 10, 2023, 11:55pm UTC](https://discuss.elastic.co/t/object-mapping-error-for-common-field-name-error/344768/2 "2023-10-10T23:55:42Z")

</div>

Look at the last option in [this](https://discuss.elastic.co/t/getting-illegal-state-exception-error-while-pushing-logs-to-elasticsearch/290029/2) post.

---

<div class="post-metadata">

**Author:** ![Andrew\_Mora](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_mora/32/125622_2.png) [@Andrew\_Mora](https://discuss.elastic.co/u/Andrew_Mora)\
**Post date:** [October 11, 2023, 2:14am UTC](https://discuss.elastic.co/t/object-mapping-error-for-common-field-name-error/344768/3 "2023-10-11T02:14:40Z")

</div>

> [@true64gurus](#):
>
> Hello,
> 
> I am getting the `object mapping ` error. The logs are coming from Kubernetes cluster . On same index , the field " **error**" comes from App1 as json object , while comes as number from app2, comes as "one word string" from app3, and multiple words from app 4.
> 
> Looked at solutions on this forum and non of them worked.
> 
> - Renaming field moves the problem to new field name.
> - Logstash doesn't provide a way to detect field type on pipeline.
> 
> Appreciate help
> 
> Thanks  
> `"status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [error] tried to parse field [error] as object, but found a concrete value"}}}`

It seems like quite a challenging situation. Have you tried using a Logstash filter to explicitly set the field type based on the source app to address this mapping issue? Wishing you luck in resolving it!

---

<div class="post-metadata">

**Author:** ![true64gurus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/true64gurus/32/107237_2.png) [@true64gurus](https://discuss.elastic.co/u/true64gurus)\
**Post date:** [October 11, 2023, 12:24pm UTC](https://discuss.elastic.co/t/object-mapping-error-for-common-field-name-error/344768/4 "2023-10-11T12:24:06Z")

</div>

@Badger Since most of the logs are object , I am thinking to convert the logs with concrete values to objects instead of other way around .

When field "error" comes as object it usually comes as flat json.

How to convert the "concrete value" to object ?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 11, 2023, 3:43pm UTC](https://discuss.elastic.co/t/object-mapping-error-for-common-field-name-error/344768/5 "2023-10-11T15:43:21Z")

</div>

Do you know what the error objects look like? If you know the name of one of the fields within [error] then there are other solutions in the post I linked to.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2023, 3:44pm UTC](https://discuss.elastic.co/t/object-mapping-error-for-common-field-name-error/344768/6 "2023-11-08T15:44:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
