# Problem elastic "document\_parsing\_exception" type field

**URL:** <https://discuss.elastic.co/t/problem-elastic-document-parsing-exception-type-field/356690>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [April 3, 2024, 1:43pm UTC](https://discuss.elastic.co/t/problem-elastic-document-parsing-exception-type-field/356690 "2024-04-03T13:43:55Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 3, 2024, 2:26pm UTC](https://discuss.elastic.co/t/problem-elastic-document-parsing-exception-type-field/356690/2 "2024-04-03T14:26:30Z")

</div>

You need to map the top-level field `requestParameters` as a `flattened` field, this way the entire json object of this field will be stored.

This is how elastic do that with the Cloudtrail integration.

They also copy the object field to another field to also keep the field as a string.

You can check how the ingest pipeline process the logs [here](https://github.com/elastic/integrations/blob/main/packages/aws/data_stream/cloudtrail/elasticsearch/ingest_pipeline/default.yml).

Are you using logstash? I have a filter for the 4 fields in cloudtrail logs that are dynamic, maybe you can adapt it for your use case.

---

_[View the full topic](https://discuss.elastic.co/t/problem-elastic-document-parsing-exception-type-field/356690)._
