# Resolving mapping parser errors

**URL:** <https://discuss.elastic.co/t/resolving-mapping-parser-errors/312840>\
**Category:** Elasticsearch\
**Created:** [August 24, 2022, 8:43pm UTC](https://discuss.elastic.co/t/resolving-mapping-parser-errors/312840 "2022-08-24T20:43:59Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Austin\_ES\_Questions](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austin_es_questions/32/98119_2.png) [@Austin\_ES\_Questions](https://discuss.elastic.co/u/Austin_ES_Questions)\
**Post date:** [August 24, 2022, 8:43pm UTC](https://discuss.elastic.co/t/resolving-mapping-parser-errors/312840/1 "2022-08-24T20:43:59Z")

</div>

I'm using filebeat -\> pipeline -\> Elasticsearch, so at the moment everything is going to one index.

at some point this field structure was inferred from my data

```auto
                "name": {
                  "properties": {
                    "first_name": {
                      "type": "keyword",
                      "ignore_above": 1024
                    },
                    "last_name": {
                      "type": "keyword",
                      "ignore_above": 1024
                    },
                    "middle_name": {
                      "type": "keyword",
                      "ignore_above": 1024
                    }
                  }
                },

```

however, I'm also getting `name` records that are just strings and not objects:

> {"type":"mapper\_parsing\_exception","reason":"object mapping for [app.name] tried to parse field [name] as object, but found a concrete value"}, dropping event!

How can I resolve?

I tried calling

```auto
GET filebeat-7.17.3/_mapping

```

and as a test writing back the output

```auto
PUT filebeat-7.17.3/_mapping
{
    "mappings": {
      "_meta": {
        "beat": "filebeat",
        "version": "7.17.3"
      },
      "dynamic_templates": [
        {
          "labels": {
            "path_match": "labels.*",
            "match_mapping_type": "string",
            "mapping": {
              "type": "keyword"
            }
          }
        },
...

```

but immediately get an error

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "mapper_parsing_exception",
        "reason": "Root mapping definition has unsupported parameters: [mappings : {_meta={beat=filebeat, version=7.17.3},

```

(1) Is there an easy way to fix a single typing error like `app.name`  
(2) Is there a way to get the file mapping from `GET`, modify it and resupply it to `PUT`?

Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 25, 2022, 12:36am UTC](https://discuss.elastic.co/t/resolving-mapping-parser-errors/312840/2 "2022-08-25T00:36:44Z")

</div>

You cannot modify existing mappings, only templates. If you want to change the mapping then your best option is to;

1. update the template
2. wait for an index rollover, where it will use the new mapping
3. reindex the old data so it uses the right mapping

Part of your issue here though is that you have some data that is coming in with `name.first_name`, `name.last_name` etc, so you need to factor that in.

---

<div class="post-metadata">

**Author:** ![Austin\_ES\_Questions](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austin_es_questions/32/98119_2.png) [@Austin\_ES\_Questions](https://discuss.elastic.co/u/Austin_ES_Questions)\
**Post date:** [August 29, 2022, 7:55pm UTC](https://discuss.elastic.co/t/resolving-mapping-parser-errors/312840/3 "2022-08-29T19:55:12Z")

</div>

Thanks Mark,

It seems like there isn't a good solution to having data with multiple types, like

```auto
name: "Keanu Reeves"

```

and

```auto
name: {
  first: "Keanu",
  last: "Reeves"
}

```

?

We are looking to use Elasticsearch for general purpose debugging logging - application authors are capable of creating new logs with competing types, and rather than failing to log we'd prefer to accept multiple types.

Is there some best practice to handle this case? E.g., is there a way through filebeat / elasticsearch pipelines to automatically correct an arbitrary field to something like

```auto
field -> field_string
field -> field_object
filed -> field_number

```

?

Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 29, 2022, 11:40pm UTC](https://discuss.elastic.co/t/resolving-mapping-parser-errors/312840/4 "2022-08-29T23:40:41Z")

</div>

There's not, no. Your best option would be to flatten it during ingestion.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2022, 11:41pm UTC](https://discuss.elastic.co/t/resolving-mapping-parser-errors/312840/5 "2022-09-26T23:41:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
