# "reason"=\>"object mapping for \[host\] tried to parse field \[host\] as object, but found a concrete value"

**URL:** <https://discuss.elastic.co/t/reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/270790>\
**Category:** Logstash\
**Created:** [April 21, 2021, 6:42am UTC](https://discuss.elastic.co/t/reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/270790 "2021-04-21T06:42:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![BlackCat](https://avatars.discourse-cdn.com/v4/letter/b/c37758/32.png) [@BlackCat](https://discuss.elastic.co/u/BlackCat)\
**Post date:** [April 21, 2021, 6:42am UTC](https://discuss.elastic.co/t/reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/270790/1 "2021-04-21T06:42:05Z")

</div>

Please how to do resolve.

Logstash outputs below error log.

```auto
[2021-04-21T15:31:47,803][WARN][logstash.outputs.elasticsearch][＜pipeline.id＞][b0981f4f69ba05c595e4bfce70b5e813c0b082207400c67bd72b366d2d36ba65] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"server_log_2021", :routing=>nil, :_type=>"_doc"}, #<LogStash::Event:0x2c68b9c>], :response=>{"index"=>{"_index"=>"server_log_2021", "_type"=>"_doc", "_id"=>"u6kg83gBU2gZoWhPq95O", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [host] tried to parse field [host] as object, but found a concrete value"}}}}

```

Data flow is below.  
Filebeat → Logstash → Elasticsearch

Version is all 7.12.

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [April 21, 2021, 7:01am UTC](https://discuss.elastic.co/t/reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/270790/2 "2021-04-21T07:01:52Z")

</div>

Hi,  
Maybe [This](https://discuss.elastic.co/t/problem-with-transfer-filebeat-6-1-3-logstash-6-1-3-elasticsearch-6-1-3/136264) can help

---

<div class="post-metadata">

**Author:** ![BlackCat](https://avatars.discourse-cdn.com/v4/letter/b/c37758/32.png) [@BlackCat](https://discuss.elastic.co/u/BlackCat)\
**Post date:** [April 21, 2021, 8:18am UTC](https://discuss.elastic.co/t/reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/270790/3 "2021-04-21T08:18:04Z")

</div>

I tried [this](https://discuss.elastic.co/t/problem-with-transfer-filebeat-6-1-3-logstash-6-1-3-elasticsearch-6-1-3/136264/4).  
But result is no change.

I attached mapping information of "host" at Elasticsearch.  
 ![キャプチャ](https://us1.discourse-cdn.com/elastic/original/3X/7/6/768e4da4431a3114676310939250e649ef667a70.png)

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [April 21, 2021, 8:48am UTC](https://discuss.elastic.co/t/reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/270790/4 "2021-04-21T08:48:13Z")

</div>

and how do you reference/treat the host field in logstash?

---

<div class="post-metadata">

**Author:** ![BlackCat](https://avatars.discourse-cdn.com/v4/letter/b/c37758/32.png) [@BlackCat](https://discuss.elastic.co/u/BlackCat)\
**Post date:** [April 21, 2021, 9:53am UTC](https://discuss.elastic.co/t/reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/270790/5 "2021-04-21T09:53:57Z")

</div>

I using below config of logstash.

```auto
input {
   tcp {
     port => ＜port number＞
codec => line { charset => "Shift_JIS" }
   }
}

filter {
 if "＜server ip＞" in [host][ip] {

      mutate {
       rename => { "message" => "Message" }
       add_field => { "Host" => "＜I using hope hostname.＞" }
      }

 }
}

```

---

<div class="post-metadata">

**Author:** ![Anabella\_Cristaldi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anabella_cristaldi/32/23612_2.png) [@Anabella\_Cristaldi](https://discuss.elastic.co/u/Anabella_Cristaldi)\
**Post date:** [April 21, 2021, 10:09am UTC](https://discuss.elastic.co/t/reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/270790/6 "2021-04-21T10:09:36Z")

</div>

I see... the host is defined as an object in the mapping.  
What happens if you use this

`add_field => { "[host][name]" => "＜I using hope hostname.＞" }`

instead of  
`add_field => { "Host" => "＜I using hope hostname.＞" }`

In this way you will be using the [ECS host fields](https://www.elastic.co/guide/en/ecs/current/ecs-host.html#:~:text=A%20host%20is%20defined%20as,Docker%20containers%2C%20and%20Kubernetes%20nodes.)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2021, 10:10am UTC](https://discuss.elastic.co/t/reason-object-mapping-for-host-tried-to-parse-field-host-as-object-but-found-a-concrete-value/270790/7 "2021-05-19T10:10:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
