# Tried to parse field as object, but found a concrete value

**URL:** <https://discuss.elastic.co/t/tried-to-parse-field-as-object-but-found-a-concrete-value/229134>\
**Category:** Logstash\
**Created:** [April 21, 2020, 10:06pm UTC](https://discuss.elastic.co/t/tried-to-parse-field-as-object-but-found-a-concrete-value/229134 "2020-04-21T22:06:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sirius](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sirius/32/47012_2.png) [@Sirius](https://discuss.elastic.co/u/Sirius)\
**Post date:** [April 21, 2020, 10:06pm UTC](https://discuss.elastic.co/t/tried-to-parse-field-as-object-but-found-a-concrete-value/229134/1 "2020-04-21T22:06:18Z")

</div>

Hi,

I'm running filebeat 7.6.2 with logstash 7.5.1 having missing lines of logs in ES due this warning message ...

> [2020-04-21T21:25:21,105][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"tableau\_json\_log\_test-2020.04", :routing=\>nil, :\_type=\>"\_doc"}, #LogStash::Event:0x2c15edaa], :response=\>{"index"=\>{"\_index"=\>"tableau\_json\_log\_test-2020.04", "\_type"=\>"\_doc", "\_id"=\>"W\_OhnnEBf8OpJ0AbkmlE", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"**object mapping for [v] tried to parse field [v] as object, but found a concrete value**"}}}}

Data sample below it works with line #1 for [v] field structure but no for the #2,, any idea/advise how can I handle when [v] as an object ?

> #1 :  
> {"ts":"2020-03-17T00:00:48.950","pid":18640,"tid":"6540","sev":"info","req":"-","sess":"-","site":"-","user":"-","k":"rotate-log", **"v":** {"new-path":"D:\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\nativeapi\_vizqlserver\_9-2\_2020\_03\_17\_00\_00\_00.txt","old-path":"D:\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\nativeapi\_vizqlserver\_9-2\_2020\_03\_16\_00\_00\_00.txt"}}

> #2 :  
> {"ts":"2020-03-17T00:00:48.949","pid":18640,"tid":"5cb0","sev":"info","req":"-","sess":"-","site":"-","user":"-","k":"msg", **"v"** :"ModelCacheInvalidator notifying dirty model for InvalidatorId=4270"}

I'm using these properties in my input filebeat to read json log files, the rest configuration is the default one.

> json.keys\_under\_root: true  
> json.add\_error\_key: true  
> json.message\_key: log

logstash configuration is:

> input {  
> beats {  
> port =\> 5040  
> ssl =\> true  
> ssl\_key =\> '..../logstash-test.pkcs8.key'  
> ssl\_certificate =\> '..../logstash-test.crt'  
> }  
> }  
> output {  
> if [fields][log\_type] == "tableau\_json\_log\_test" {  
> elasticsearch {  
> hosts =\> ["[https://test1.com:9200](https://test1.com:9200)","[https://test2.com:9200](https://test2.com:9200)","[https://test3.com:9200](https://test3.com:9200)"]  
> index =\> "tableau\_json\_log\_test-%{+YYYY.MM}"  
> ssl =\> true  
> ssl\_certificate\_verification =\> true  
> cacert =\> '.../ca.crt'  
> user =\> 'usr'  
> password =\> 'passwd'  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [April 21, 2020, 10:55pm UTC](https://discuss.elastic.co/t/tried-to-parse-field-as-object-but-found-a-concrete-value/229134/2 "2020-04-21T22:55:47Z")

</div>

This is a `mapping` conflict.  
If you do not use any index template with a index mapping, you might get conflicts.  
Still, in your specific case it would not be enough.

In some documents, it seems `v` is a scalar value (e.g. a `string`).  
In other documents, it contains an `object`.

A way to solve this might be to rename the `v` field to be different depending on `k`.

This is only applicable if the number of different values of `k` is limited (e.g. ~100), otherwise you might risk field explosion.

Using Logstash:

```auto
mutate {
  rename => ["v", "%{[k]}" ]
}

```

Using this mutate, the log #1 becomes:

```auto
{"ts":"2020-03-17T00:00:48.950","pid":18640,"tid":"6540","sev":"info","req":"-","sess":"-","site":"-","user":"-","k":"rotate-log","rotate-log":{"new-path":"D:\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\nativeapi_vizqlserver_9-2_2020_03_17_00_00_00.txt","old-path":"D:\Tableau\Tableau Server\data\tabsvc\logs\vizqlserver\nativeapi_vizqlserver_9-2_2020_03_16_00_00_00.txt"}}

```

Using this mutate, the log #2 becomes:

```auto
{"ts":"2020-03-17T00:00:48.949","pid":18640,"tid":"5cb0","sev":"info","req":"-","sess":"-","site":"-","user":"-","k":"msg","msg":"ModelCacheInvalidator notifying dirty model for InvalidatorId=4270"}

```

---

<div class="post-metadata">

**Author:** ![Sirius](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sirius/32/47012_2.png) [@Sirius](https://discuss.elastic.co/u/Sirius)\
**Post date:** [April 22, 2020, 12:07am UTC](https://discuss.elastic.co/t/tried-to-parse-field-as-object-but-found-a-concrete-value/229134/3 "2020-04-22T00:07:44Z")

</div>

Thanks so much Luca, it resolved the issue !!  
And yes I'm running now over field limited warnings,, I'll be defining a template for mapping those field useful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2020, 12:07am UTC](https://discuss.elastic.co/t/tried-to-parse-field-as-object-but-found-a-concrete-value/229134/4 "2020-05-20T00:07:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
