# Same field different types (primitive vs. complex)

**URL:** <https://discuss.elastic.co/t/same-field-different-types-primitive-vs-complex/218047>\
**Category:** Elasticsearch\
**Created:** [February 5, 2020, 6:39pm UTC](https://discuss.elastic.co/t/same-field-different-types-primitive-vs-complex/218047 "2020-02-05T18:39:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bartlomiej\_Palmowski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bartlomiej_palmowski/32/45037_2.png) [@Bartlomiej\_Palmowski](https://discuss.elastic.co/u/Bartlomiej_Palmowski)\
**Post date:** [February 5, 2020, 6:39pm UTC](https://discuss.elastic.co/t/same-field-different-types-primitive-vs-complex/218047/1 "2020-02-05T18:39:02Z")

</div>

Hi,  
please forgive me for this very basic question but I can't find an answer so far. I'm sending my logs to AWS CloudWatch and from there I'm using an AWS Lambda to push said logs to AWS hosted ElasticSearch.

The problem I have is that my logs even though are json they are not well structured. Sometimes a field can be a simple value like a string but the very next log line might have the same field as an object.  
e.g.  
log line A:  
{"msg": "foo bar", "status": "Success"}  
log line B:  
{"msg": "quux", "status": {"finished": "2020-02-05T18:37:15Z"}}

This way I can't really index all my log lines. What's the preferred way of dealing with this issue?

---

<div class="post-metadata">

**Author:** ![elk11](https://avatars.discourse-cdn.com/v4/letter/e/45deac/32.png) [@elk11](https://discuss.elastic.co/u/elk11)\
**Post date:** [February 6, 2020, 4:01pm UTC](https://discuss.elastic.co/t/same-field-different-types-primitive-vs-complex/218047/2 "2020-02-06T16:01:08Z")

</div>

You should handle this before indexing these kind of logs to elasticsearch and convert them to any one type. Otherwise it will result in mapping conflict.

I don't think you can index these kind of logs to an index.

---

<div class="post-metadata">

**Author:** ![Bartlomiej\_Palmowski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bartlomiej_palmowski/32/45037_2.png) [@Bartlomiej\_Palmowski](https://discuss.elastic.co/u/Bartlomiej_Palmowski)\
**Post date:** [February 7, 2020, 4:54pm UTC](https://discuss.elastic.co/t/same-field-different-types-primitive-vs-complex/218047/3 "2020-02-07T16:54:15Z")

</div>

These are third party applications, I can't know what they're going to look like. Perhaps best option would be to store the log line as a string instead of parsing it?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2020, 4:54pm UTC](https://discuss.elastic.co/t/same-field-different-types-primitive-vs-complex/218047/4 "2020-03-06T16:54:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
