# "object mapping for \[monitor\] tried to parse field \[monitor\] as object, but found a concrete value"

**URL:** <https://discuss.elastic.co/t/object-mapping-for-monitor-tried-to-parse-field-monitor-as-object-but-found-a-concrete-value/137806>\
**Category:** Logstash\
**Created:** [June 28, 2018, 2:47pm UTC](https://discuss.elastic.co/t/object-mapping-for-monitor-tried-to-parse-field-monitor-as-object-but-found-a-concrete-value/137806 "2018-06-28T14:47:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hollowimage](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@hollowimage](https://discuss.elastic.co/u/hollowimage)\
**Post date:** [June 28, 2018, 2:47pm UTC](https://discuss.elastic.co/t/object-mapping-for-monitor-tried-to-parse-field-monitor-as-object-but-found-a-concrete-value/137806/1 "2018-06-28T14:47:46Z")

</div>

I am using heartbeat 6.2.2, logstash 6.2.3, elasticsearch 6.2.3

When sending heartbeat tcp monitor data to logstash, i get the following error message:

`[2018-06-28T00:57:22,253][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"heartbeat-2018.06.28", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x25ec0801>], :response=>{"index"=>{"_index"=>"heartbeat-2018.06.28", "_type"=>"doc", "_id"=>"SRrARGQBYXi60TGvyC0m", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [monitor] tried to parse field [monitor] as object, but found a concrete value"}}}}`

I checked my templates, deleted the target index so it re-recreated, but i am not sure what I am missing.

```
input {
  beats {
port => 5044
ssl_certificate_authorities => ["/etc/cert.crt"]
ssl_certificate => "/etc/key.crt"
ssl_key => "/etc/key.key"
  }
}

  } else if [beat][name] == "elk-heartbeat" or [fields][beat][class] == "elk-heartbeat" {
    elasticsearch {
    hosts => ["http://ip-here:9200"]
     ... * removing ssl and user/pass info *
    index => "heartbeat-%{+YYYY.MM.dd}"
    }

```

and then its a simple elasticsearch output. es is not using any pipelines. but as a result the "monitor" field in kibana shows up as one string which is the properly formatted json object, instead of monitor.up, monitor.ip, and the like.

i am using the index template that came with the 6.2.2 heartbeats. (i did update the template to apply to heartbeat-\* indices, not just heartbeat-version-\* )  
any thoughts?

edit:  
kibana field looks like this: [https://i.imgur.com/B3rCoeM.png](https://i.imgur.com/B3rCoeM.png)

---

<div class="post-metadata">

**Author:** ![hollowimage](https://avatars.discourse-cdn.com/v4/letter/h/ee7513/32.png) [@hollowimage](https://discuss.elastic.co/u/hollowimage)\
**Post date:** [June 28, 2018, 11:30pm UTC](https://discuss.elastic.co/t/object-mapping-for-monitor-tried-to-parse-field-monitor-as-object-but-found-a-concrete-value/137806/2 "2018-06-28T23:30:06Z")

</div>

managed to track it down. looks like previous iterations of the indices had that field as a vector, instead of object. had to stop all log flow, remove all old indices, remove kibana index patterns, restart log flow, have the index create correctly and then re-create kibana index pattern for the group.

feel free to close.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2018, 11:30pm UTC](https://discuss.elastic.co/t/object-mapping-for-monitor-tried-to-parse-field-monitor-as-object-but-found-a-concrete-value/137806/3 "2018-07-26T23:30:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
