# org.elasticsearch.index.mapper.MapperParsingException after a pipeline

**URL:** <https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-after-a-pipeline/255484>\
**Category:** Elasticsearch\
**Created:** [November 16, 2020, 9:42am UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-after-a-pipeline/255484 "2020-11-16T09:42:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![samsalvatico](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samsalvatico/32/47498_2.png) [@samsalvatico](https://discuss.elastic.co/u/samsalvatico)\
**Post date:** [November 16, 2020, 9:42am UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-after-a-pipeline/255484/1 "2020-11-16T09:42:00Z")

</div>

Hi,  
this is my scenario: I receive messages by Fluentbit through an elastic ingestion pipeline.  
This is my ingestion pipeline:

```auto
{
    "jsonize_account_backend":{
        "processors":[
            {
                "grok":{
                    "field":"log",
                    "patterns":[
                        "%{TIMESTAMP_ISO8601:log_timestamp}%{SPACE}%{LOGLEVEL:log_level}%{SPACE}%{GREEDYDATA:log}\\n"
                    ],
                    "ignore_failure":true
                }
            },
            {
                "json":{
                    "field":"log",
                    "target_field":"json_log",
                    "on_failure":[
                        {
                            "set":{
                                "field":"json_log_text",
                                "value":{
                                    "error":"Log is not a valid json"
                                }
                            }
                        }
                    ]
                }
            }
        ]
    }
}

```

So, I expect that, at the second processor, if the "log" field is a valid one it parse the data and set the json data in "json\_log" (flattened field in mapping), otherwise it set the error message into "json\_log\_text".

But, in some cases, I found this error in the elastic logs:

> {"type": "server", "timestamp": "2020-11-16T09:08:35,039Z", "level": "DEBUG", "component": "o.e.a.b.TransportShardBulkAction", "cluster.name": "elasticsearch", "node.name": "elasticsearch-master-1", "message": "[log-account-2020.11.12][0] failed to execute bulk item (index) index {[log-account-2020.11.12][\_doc][MLZQ0HUBM1HcsZbaJtRJ], source[n/a, actual length: [18.6kb], max length: 2kb]}", "cluster.uuid": "D84-LczLRFWqtU30fjfeCg", "node.id": "g6I5hbZ\_Q8-EakdU5NbBMw" ,  
> "stacktrace": ["org.elasticsearch.index.mapper.MapperParsingException: failed to parse field [json\_log] of type [flattened] in document with id 'MLZQ0HUBM1HcsZbaJtRJ'. Preview of field's value: ':null,'",

**Why this error is thrown?**  
I expect that the json\_log is empty if the parsing didn't work with success.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 17, 2020, 11:10pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-after-a-pipeline/255484/2 "2020-11-17T23:10:46Z")

</div>

You can see that it's reporting the value of `json_log` as `:null,`, which looks a little weird to me. Can you see the output that the pipeline is creating?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2020, 11:10pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-after-a-pipeline/255484/3 "2020-12-15T23:10:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
