# Problem with transfer Filebeat 6.1.3 \> Logstash 6.1.3 \> Elasticsearch 6.1.3

**URL:** <https://discuss.elastic.co/t/problem-with-transfer-filebeat-6-1-3-logstash-6-1-3-elasticsearch-6-1-3/136264>\
**Category:** Logstash\
**Created:** [June 18, 2018, 9:03am UTC](https://discuss.elastic.co/t/problem-with-transfer-filebeat-6-1-3-logstash-6-1-3-elasticsearch-6-1-3/136264 "2018-06-18T09:03:15Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![pavan.idm](https://avatars.discourse-cdn.com/v4/letter/p/8c91f0/32.png) [@pavan.idm](https://discuss.elastic.co/u/pavan.idm)\
**Post date:** [July 19, 2018, 3:31am UTC](https://discuss.elastic.co/t/problem-with-transfer-filebeat-6-1-3-logstash-6-1-3-elasticsearch-6-1-3/136264/7 "2018-07-19T03:31:42Z")

</div>

I also have the issue and following are the details of the issue.

```
We have upgraded filebeat and logstash to 6.3 as part of patching. 
#logstash -V
logstash 6.3.0

#filebeat version
filebeat version 6.3.0 (amd64), libbeat 6.3.0

we noticed that the format of host through logstash has changed as follows:
e.g. "host":"xxx.ood.ops" to "host": { "name": "xxx.ood.ops" }

After doing the upgrade we are getting the following errors
 In logstash:
 Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>"3320728454", :_index=>"logstash-2018.07.18", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x4e8bfcd8>], :response=>{"index"=>{"_index"=>"logstash-2018.07.18", "_type"=>"doc", "_id"=>"3320728454", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [host] tried to parse field [host] as object, but found a concrete value"}}}}

 In elasticsearch:
 [2018-07-18T17:01:04,903][DEBUG][o.e.a.b.TransportShardBulkAction] [logstash-2018.07.18][1] failed to execute bulk item (index) BulkShardRequest [[logstash-2018.07.18][1]] containing [11] requests

```

org.elasticsearch.index.mapper.MapperParsingException: object mapping for [host] tried to parse field [host] as object, but found a concrete value

```
 The json format as seen in kibana:
 {

```

"\_index": "logstash-2018.07.18",  
"\_type": "doc",  
"\_id": "2114191840",  
"\_version": 102181,  
"\_score": null,  
"\_source": {  
"prospector": {  
"type": "log"  
},  
"host": {  
"name": "xxx.ood.ops"  
},  
"source": "/var/log/sample.out",  
"beat": {  
"name": "xxx.ood.ops",  
"hostname": "xxx.ood.ops",  
"version": "6.3.0"  
},  
"input": {  
"type": "log"  
}

I tried the solution of renaming and following is the error:

[2018-07-18T16:01:10,186][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>"4218739081", :\_index=\>"logstash-2018.07.18", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x14e8812e], :response=\>{"index"=\>{"\_index"=\>"logstash-2018.07.18", "\_type"=\>"doc", "\_id"=\>"4218739081", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse [host.name]", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"=\>"Can't get text on a START\_OBJECT at 1:57"}}}}}

Can you please help ?

---

_[View the full topic](https://discuss.elastic.co/t/problem-with-transfer-filebeat-6-1-3-logstash-6-1-3-elasticsearch-6-1-3/136264)._
