# Transfer Docker log with gelf：Could not index event to Elasticsearch

**URL:** <https://discuss.elastic.co/t/transfer-docker-log-with-gelf-could-not-index-event-to-elasticsearch/139852>\
**Category:** Logstash\
**Created:** [July 13, 2018, 12:37am UTC](https://discuss.elastic.co/t/transfer-docker-log-with-gelf-could-not-index-event-to-elasticsearch/139852 "2018-07-13T00:37:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![CCH0124](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cch0124/32/36436_2.png) [@CCH0124](https://discuss.elastic.co/u/CCH0124)\
**Post date:** [July 13, 2018, 12:37am UTC](https://discuss.elastic.co/t/transfer-docker-log-with-gelf-could-not-index-event-to-elasticsearch/139852/1 "2018-07-13T00:37:29Z")

</div>

Logstash has the following error

```auto
[2018-07-13T00:28:09,022][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"filebeat-gelf-docker-2018.07.13", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x44cb3a00>], :response=>{"index"=>{"_index"=>"filebeat-gelf-docker-2018.07.13", "_type"=>"doc", "_id"=>"vswJkWQBs0A5FeImsam8", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [host] tried to parse field [host] as object, but found a concrete value"}}}}

```

Logstash configuration

```auto
input {
        gelf {
                type => docker
                host => "0.0.0.0"
                port => 12201
        }

}

#filter{
# if [tag] == "nginx" {

# }
#}
## Add your filters / logstash plugins configuration here

output {
        elasticsearch {
                hosts => "elasticsearch:9200"
                manage_template => false
                index => "filebeat-gelf-docker-%{+YYYY.MM.dd}"
        }
}

```

docker logging  
There is a gelf port configured in logstahs

```auto
...
   wordpress:
     image: wordpress:latest
     ports:
       - "8000:80"
     environment:
       WORDPRESS_DB_HOST: db:3306
       WORDPRESS_DB_USER: wordpress
       WORDPRESS_DB_PASSWORD: wordpress
     logging:
       driver: gelf
       options:
         gelf-address: "udp://0.0.0.0:12201"
         tag: wordpress
     depends_on:
       - db
     restart: always
     networks:
       - mysql
       - proxy
...

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 13, 2018, 2:59pm UTC](https://discuss.elastic.co/t/transfer-docker-log-with-gelf-could-not-index-event-to-elasticsearch/139852/2 "2018-07-13T14:59:12Z")

</div>

This has come up several times before, including as recently as yesterday. Please google the error message ("object mapping for [host] tried to parse field [host] as object, but found a concrete value").

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2018, 2:59pm UTC](https://discuss.elastic.co/t/transfer-docker-log-with-gelf-could-not-index-event-to-elasticsearch/139852/3 "2018-08-10T14:59:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
