# Object type vs Data type in Filebeat

**URL:** <https://discuss.elastic.co/t/object-type-vs-data-type-in-filebeat/279185>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 20, 2021, 3:50pm UTC](https://discuss.elastic.co/t/object-type-vs-data-type-in-filebeat/279185 "2021-07-20T15:50:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gentle\_ghost](https://avatars.discourse-cdn.com/v4/letter/g/ea5d25/32.png) [@gentle\_ghost](https://discuss.elastic.co/u/gentle_ghost)\
**Post date:** [July 20, 2021, 3:50pm UTC](https://discuss.elastic.co/t/object-type-vs-data-type-in-filebeat/279185/1 "2021-07-20T15:50:09Z")

</div>

Hello,

I'm circling back on this older discussion I posted about object type vs concrete types trying to push data to elasticsearch using filebeat:

> [@Having an issue with filebeat pushing to Elasticsearch](https://discuss.elastic.co/t/having-an-issue-with-filebeat-pushing-to-elasticsearch/271822/4):
>
> Did you fix the rest of the formatting? Is your elasticsearch really running on https? did you enable security authentication etc. setup certs do all that stuff? Looks like bad creds... that is the error you get with bad creds... pretty simple try to curl from filebeat host with the same host and creds that are in the elasticsearch.output section filebeat.yml see what you get First try this is ignores the self signed cert. curl --insecure -u "username:password" https://elastichost:9200

The error I've been running into is this:

`{"type":"mapper_parsing_exception","reason":"object mapping for [entries] tried to parse field [entries] as object, but found a concrete value"}`

I think i've made more sense of this error message in that I originally thought of this as an issue with incorrect data types but what really is happening is an issue with object vs the data itself. What is happening is the value returned for `entries` is is a value and not an object (nested field/array). I'm taking the field `length_stayed` which is an integer field parsed from a grok pattern. `This is the script processor that I'm using that is failing:

`if(ctx.length_stayed >= 60) { ctx.entries = 1; }`

I see that I need to adjust `ctx.entries = 1;` to an object instead of a root level item I'm just not sure how to accomplish that.

Thanks

---

<div class="post-metadata">

**Author:** ![gentle\_ghost](https://avatars.discourse-cdn.com/v4/letter/g/ea5d25/32.png) [@gentle\_ghost](https://discuss.elastic.co/u/gentle_ghost)\
**Post date:** [July 20, 2021, 8:25pm UTC](https://discuss.elastic.co/t/object-type-vs-data-type-in-filebeat/279185/2 "2021-07-20T20:25:57Z")

</div>

Just bumping this. Could really use the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2021, 10:25pm UTC](https://discuss.elastic.co/t/object-type-vs-data-type-in-filebeat/279185/3 "2021-08-17T22:25:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
