# Single field object to Elasticsearch using Logstash

**URL:** <https://discuss.elastic.co/t/single-field-object-to-elasticsearch-using-logstash/215735>\
**Category:** Logstash\
**Created:** [January 20, 2020, 12:21pm UTC](https://discuss.elastic.co/t/single-field-object-to-elasticsearch-using-logstash/215735 "2020-01-20T12:21:24Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![KrishK](https://avatars.discourse-cdn.com/v4/letter/k/c89c15/32.png) [@KrishK](https://discuss.elastic.co/u/KrishK)\
**Post date:** [January 20, 2020, 12:21pm UTC](https://discuss.elastic.co/t/single-field-object-to-elasticsearch-using-logstash/215735/1 "2020-01-20T12:21:24Z")

</div>

Hi Support,

I have group concat field values like 🙂

**Document\_Type**  
1,2,3,4,5,6

In Elasticsearch field mapping with object type

```
"Document_Type": {
        "properties": {
          "d": {
            "type": "short"
          }
        }
 }

```

When I run Logstash getting this "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"object mapping for [Document\_Type] tried to parse field [Document\_Type] as object, but found a concrete value"}}}}

Can you please help me?

Thanks

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [January 20, 2020, 1:50pm UTC](https://discuss.elastic.co/t/single-field-object-to-elasticsearch-using-logstash/215735/2 "2020-01-20T13:50:16Z")

</div>

Hi there,

it means that in your mapping you defined that `Document_Type` as a object (in fact it looks like an object) but you're passing it as something different (in fact what you wrote there under that bold **Document\_Type** is an array of numbers, not an object).

Can you please share a sample of input doc and the complete mapping for that index?

---

<div class="post-metadata">

**Author:** ![KrishK](https://avatars.discourse-cdn.com/v4/letter/k/c89c15/32.png) [@KrishK](https://discuss.elastic.co/u/KrishK)\
**Post date:** [January 23, 2020, 3:14am UTC](https://discuss.elastic.co/t/single-field-object-to-elasticsearch-using-logstash/215735/3 "2020-01-23T03:14:58Z")

</div>

Hi Fabio,

Thanks for the reply.

Yes, You understood well.

Below is the mapping and example.

```
DELETE testindex
PUT testindex
PUT testindex/_mappings
{
"properties": {    
      "Document_Type": {
        "type": "object",
        "properties": {
          "d": {
            "type": "short"
          }
        }
      },
	  "filename": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "fileid": {
        "type": "long"
      }
    }
}
POST testindex/_doc
{
  "Document_Type":[{"d":1},{"d":1}],
  "fileid" : 1,
  "filename" :"elasticsearch filename.pdf"
}
GET testindex/_search

```

Above example working fine, But when indexing using logstash.

```
input {
  jdbc { 
    jdbc_connection_string => "jdbc:mysql://localhost:3306/test?useCursorFetch=true"
    # The path to our downloaded jdbc driver
    jdbc_driver_library => "mysql-connector-java-8.0.18.jar"
    jdbc_driver_class => "com.mysql.jdbc.Driver"
       # our query
    statement => "SELECT a.fileid, a.filename, group_concat(b.document_type) as Document_Type FROM file_table AS a LEFT JOIN file_doctype AS b ON a.fileid = b.fileid group by a.fileid order by a.fileid"    
    }
  }
  
output {
stdout { codec => rubydebug }
  elasticsearch {
    hosts => ["localhost:9200"]
    index => ["testindex"]
  }
}

```

I am getting this "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"object mapping for [Document\_Type] tried to parse field [Document\_Type] as object, but found a concrete value"}}}}

Now can you clear me on this?

Thanks

---

<div class="post-metadata">

**Author:** ![KrishK](https://avatars.discourse-cdn.com/v4/letter/k/c89c15/32.png) [@KrishK](https://discuss.elastic.co/u/KrishK)\
**Post date:** [January 28, 2020, 5:39am UTC](https://discuss.elastic.co/t/single-field-object-to-elasticsearch-using-logstash/215735/4 "2020-01-28T05:39:32Z")

</div>

Any Hope?

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [February 10, 2020, 2:58pm UTC](https://discuss.elastic.co/t/single-field-object-to-elasticsearch-using-logstash/215735/5 "2020-02-10T14:58:40Z")

</div>

Hi there,

I'm sorry I've been kinda busy and didn't see the notification. Anyway, can you share the output of logstash? I mean, you're sending to both elasticsearch and standard output.

What is written in the stdout?

---

<div class="post-metadata">

**Author:** ![KrishK](https://avatars.discourse-cdn.com/v4/letter/k/c89c15/32.png) [@KrishK](https://discuss.elastic.co/u/KrishK)\
**Post date:** [February 13, 2020, 8:39am UTC](https://discuss.elastic.co/t/single-field-object-to-elasticsearch-using-logstash/215735/6 "2020-02-13T08:39:51Z")

</div>

Hi Fabio,

I have resolved it.

Thanks

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [February 13, 2020, 9:01am UTC](https://discuss.elastic.co/t/single-field-object-to-elasticsearch-using-logstash/215735/7 "2020-02-13T09:01:59Z")

</div>

Very good!

Would you mind posting here your solution and mark it as the solution? It might be useful for future users.

---

<div class="post-metadata">

**Author:** ![KrishK](https://avatars.discourse-cdn.com/v4/letter/k/c89c15/32.png) [@KrishK](https://discuss.elastic.co/u/KrishK)\
**Post date:** [February 13, 2020, 9:31am UTC](https://discuss.elastic.co/t/single-field-object-to-elasticsearch-using-logstash/215735/8 "2020-02-13T09:31:17Z")

</div>

Sure Fabio.

Below is the solution.

```
 ruby {
  code => "
    r = []
	data = event.get('Document_Type').split(',')
    	data.each { |values|        
        item = {
            'd' => values,            
        }
        r << item
    }
    event.set('Document_Type', r)
  "
	}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2020, 9:31am UTC](https://discuss.elastic.co/t/single-field-object-to-elasticsearch-using-logstash/215735/9 "2020-03-12T09:31:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
