# Veeam Logstash Grok

**URL:** <https://discuss.elastic.co/t/veeam-logstash-grok/311774>\
**Category:** Logstash\
**Created:** [August 9, 2022, 8:01pm UTC](https://discuss.elastic.co/t/veeam-logstash-grok/311774 "2022-08-09T20:01:05Z")\
**Posts on this page:** 1\
**Showing post:** 19

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 10, 2022, 10:57pm UTC](https://discuss.elastic.co/t/veeam-logstash-grok/311774/19 "2022-08-10T22:57:30Z")

</div>

Read [this](https://discuss.elastic.co/t/getting-illegal-state-exception-error-while-pushing-logs-to-elasticsearch/290029/2) thread to understand what that error is telling you.

You most likely indexed some documents that contain [event][original] (so [event] is an object) since with ECS compatability enabled logstash stores a copy of the [message] field there.

Quickest fix will be to use a different fieldname in your dissect.

---

_[View the full topic](https://discuss.elastic.co/t/veeam-logstash-grok/311774)._
