# org.elasticsearch.index.mapper.MapperParsingException: object mapping for \[message\] tried to parse field \[message\] as object, but found a concrete value

**URL:** <https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597>\
**Category:** Logstash\
**Created:** [May 24, 2019, 9:20am UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597 "2019-05-24T09:20:43Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [May 24, 2019, 9:20am UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597/1 "2019-05-24T09:20:43Z")

</div>

I upload a template, and try to parse a column, but it recognized as a string, how to make it as a object, please help...

Here is my template:

```auto
{
  "index_patterns": "springboot*",
  "order": 0,
  "settings": {
    "number_of_shards": 1,
    "number_of_replicas": "0"
  },
  "aliases": {
    "alias_1": {}
  },
  "mappings": {
    "properties": {
      "@timestamp": {
        "type": "date"
      },
      "@version": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "host": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "level": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "level_value": {
        "type": "long"
      },
      "logger_name": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "message": {
       "type":"object", 
        
        "properties": {
          "appName": {
            "type": "text"
          },
          "className": {
            "type": "text"
            
          },
          "methodName": {
            "type": "text"
            
          }
        }
      },
      "port": {
        "type": "long"
      },
      "tags": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "thread_name": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [May 24, 2019, 11:03am UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597/2 "2019-05-24T11:03:54Z")

</div>

I think either you have an existing index before you have added the Template or the object is not recognized as an object in logstash.

So if it is a json object you can use the json filter. After that Elasticsearch can Index it as an object.

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [May 24, 2019, 12:53pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597/3 "2019-05-24T12:53:58Z")

</div>

```auto
filter {
  json {
    source => "message"
  }
}

```

I add the json filter to my logstash conf, but it does not work.

[https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 24, 2019, 1:09pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597/4 "2019-05-24T13:09:05Z")

</div>

What do you get if you use

```
output { stdout { codec => rubydebug } }

```

What does logstash log?

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [May 24, 2019, 1:14pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597/5 "2019-05-24T13:14:02Z")

</div>

Here is the output:

```auto
[2019-05-24T21:11:17,880][DEBUG][o.e.a.b.TransportShardBulkAction] [VM_0_17_centos] [springboot-logstash-2019.05.24][0] failed to execute bulk item (index) index {[springboot-logstash-2019.05.24][_doc][mV_36WoBWEbX7YrrlP54], source[{"@timestamp":"2019-05-24T13:12:57.691Z","thread_name":"http-nio-8080-exec-1","@version":"1","logger_name":"com.example.demo.MyLog","message":"{\"appName\":\"demo\",\"className\":\"HelloController\",\"methodName\":\"hello\"}","appName":"demo","port":19333,"level":"INFO","host":"111.203.45.2","className":"HelloController","methodName":"hello","level_value":20000}]}
org.elasticsearch.index.mapper.MapperParsingException: object mapping for [message] tried to parse field [message] as object, but found a concrete value
        at org.elasticsearch.index.mapper.DocumentParser.parseObjectOrNested(DocumentParser.java:363) ~[elasticsearch-7.0.0.jar:7.0.0]
        at org.elasticsearch.index.mapper.DocumentParser.parseObjectOrField(DocumentParser.java:465) ~[elasticsearch-7.0.0.jar:7.0.0]
        at org.elasticsearch.index.mapper.DocumentParser.parseValue(DocumentParser.java:596) ~[elasticsearch-7.0.0.jar:7.0.0]
        at org.elasticsearch.index.mapper.DocumentParser.innerParseObject(DocumentParser.java:407) ~[elasticsearch-7.0.0.jar:7.0.0]
        at org.elasticsearch.index.mapper.DocumentParser.parseObjectOrNested(DocumentParser.java:381) ~[elasticsearch-7.0.0.jar:7.0.0]
        at org.elasticsearch.index.mapper.DocumentParser.internalParseDocument(DocumentParser.java:98) ~[elasticsearch-7.0.0.jar:7.0.0]
        at org.elasticsearch.index.mapper.DocumentParser.parseDocument(DocumentParser.java:71) ~[elasticsearch-7.0.0.jar:7.0.0]
        at org.elasticsearch.index.mapper.DocumentMapper.parse(DocumentMapper.java:267) ~[elasticsearch-7.0.0.jar:7.0.0]
        at org.elasticsearch.index.shard.IndexShard.prepareIndex(IndexShard.java:770) ~[elasticsearch-7.0.0.jar:7.0.0]
        at org.elasticsearch.index.shard.IndexShard.applyIndexOperation(IndexShard.java:747) ~[elasticsearch-7.0.0.jar:

```

---

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [May 24, 2019, 2:25pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597/6 "2019-05-24T14:25:48Z")

</div>

How does the "message" look like? not the logstash log.

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [May 24, 2019, 2:54pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597/7 "2019-05-24T14:54:52Z")

</div>

Here is the "message":

```auto
"message":"{\"appName\":\"demo\",\"className\":\"HelloController\",\"methodName\":\"hello\"}"

```

I want to parse it as a json object.

---

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [May 24, 2019, 3:15pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597/8 "2019-05-24T15:15:27Z")

</div>

ah ok, this is not an object.

with this you get "appName" and "className"... as fields on their own.  
so they won´t be nested under "message"

this means:  
you will have the "message" field and all of those fields extracted with the json filter as fields on top level.

if you want to get something like [message][appName] and [message][className]...  
then you can try the json filter with the option "target" =\> "message"

BUT if you try to put other logs inside this index which only have a "message" field with a normal value then it wont be logged.

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [May 24, 2019, 3:31pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597/9 "2019-05-24T15:31:28Z")

</div>

Thanx a lot!!!

So, I should make it like this:

```auto
filter {
  json {
    source => "message"
    target => "message"
  }
}

```

Am I right?

---

<div class="post-metadata">

**Author:** ![logger](https://avatars.discourse-cdn.com/v4/letter/l/34f0e0/32.png) [@logger](https://discuss.elastic.co/u/logger)\
**Post date:** [May 24, 2019, 3:41pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597/10 "2019-05-24T15:41:57Z")

</div>

yes this should delete the original message which is "key":"value" and create a "object":{"key":"value","key":value"}

I havent tried it but this should work.  
or If you want to be more safe you can:  
`mutate { rename => { "message" => "msg" } }`  
`json { source => "msg" target => "message" }`

then you will have the msg field with the original event and the message should be an object

---

<div class="post-metadata">

**Author:** ![KeithTt](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keithtt/32/29447_2.png) [@KeithTt](https://discuss.elastic.co/u/KeithTt)\
**Post date:** [May 24, 2019, 4:13pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597/11 "2019-05-24T16:13:54Z")

</div>

Thanks a loooot.

I will have a try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2019, 4:14pm UTC](https://discuss.elastic.co/t/org-elasticsearch-index-mapper-mapperparsingexception-object-mapping-for-message-tried-to-parse-field-message-as-object-but-found-a-concrete-value/182597/12 "2019-06-21T16:14:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
