# This error seems to be related to mapping issues in Elasticsearch, below error found in logstash

**URL:** <https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414>\
**Category:** Logstash\
**Created:** [November 4, 2023, 4:37am UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414 "2023-11-04T04:37:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sreecharanhope](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sreecharanhope/32/127217_2.png) [@Sreecharanhope](https://discuss.elastic.co/u/Sreecharanhope)\
**Post date:** [November 4, 2023, 4:37am UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414/1 "2023-11-04T04:37:44Z")

</div>

2023-11-04T10:33:48,353][WARN][logstash.outputs.elasticsearch][main]  
Could not index event to Elasticsearch. {:status=\>400, :action=\>["index",  
{:\_id=\>nil, :\_index=\>"staging-2023.11.04", :\_type=\>"\_doc", :routing=\>nil},  
#LogStash::Event:0x4fdc7ef6], :response=\>{"index"=\>{"\_index"=\>"staging-2023.11.04",  
"\_type"=\>"\_doc", "\_id"=\>"adjhghASjfv4456", "status"=\>400, "error"=\>  
{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field  
[kubernetes.labels.app] of type [text] in document with id 'adjhghASjfv4456'.  
Preview of field's value: '{kubernetes={io/instance=cert-manager, io/component=cainjector,  
io/name=cainjector, io/version=v1.5.4}, value=cainjector}'", "  
caused\_by"=\>{"type"=\>"illegal\_state\_exception",  
"reason"=\>"Can't get text on a START\_OBJECT at 1:1022"}}}}}  
/var/log/logstash$ PUT staging-2023.11.04

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 4, 2023, 9:49am UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414/2 "2023-11-04T09:49:23Z")

</div>

Welcome to the community.

Check you .conf and the template, especially the kubernetes.labels.app field, you are writing the text type for example: "[kubernetes][labels][app]" =\> "pod1" instead of kubernetes.labels. as JSON. Check [ECS](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-kubernetes-processor.html). Also check the template, might be a wrong data type dynamically created during testing.

> **`kubernetes.labels.*`**
> 
> Kubernetes labels map
> 
> **type: object**

---

<div class="post-metadata">

**Author:** ![Sreecharanhope](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sreecharanhope/32/127217_2.png) [@Sreecharanhope](https://discuss.elastic.co/u/Sreecharanhope)\
**Post date:** [November 4, 2023, 10:30am UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414/3 "2023-11-04T10:30:57Z")

</div>

here it is my conf file

input {  
redis {  
host =\> "[elk-XXXX-XXX.amazonaws.com](http://elk-XXXX-XXX.amazonaws.com)"  
id =\> "staging"  
data\_type =\> "list"  
key =\> "staging"  
tags =\> ["staging"]  
}  
}

filter {  
mutate {  
gsub =\> ["message", "\x1B[([0-9]{1,2}(;[0-9]{1,2})?)?[m|K]", ""]  
}  
mutate {  
remove\_field =\> ["@version", "\_score", "\_type"]  
}  
}

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 4, 2023, 3:17pm UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414/4 "2023-11-04T15:17:35Z")

</div>

Can you show the full message? Should be the field named: "kubernetes".

---

<div class="post-metadata">

**Author:** ![Sreecharanhope](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sreecharanhope/32/127217_2.png) [@Sreecharanhope](https://discuss.elastic.co/u/Sreecharanhope)\
**Post date:** [November 5, 2023, 2:38am UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414/5 "2023-11-05T02:38:14Z")

</div>

no we dont have that filed

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2023, 2:38am UTC](https://discuss.elastic.co/t/this-error-seems-to-be-related-to-mapping-issues-in-elasticsearch-below-error-found-in-logstash/346414/6 "2023-12-03T02:38:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
