# Why the host mapping is not wokring

**URL:** <https://discuss.elastic.co/t/why-the-host-mapping-is-not-wokring/209140>\
**Category:** Logstash\
**Created:** [November 23, 2019, 4:50am UTC](https://discuss.elastic.co/t/why-the-host-mapping-is-not-wokring/209140 "2019-11-23T04:50:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![SathishPrakasam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sathishprakasam/32/46290_2.png) [@SathishPrakasam](https://discuss.elastic.co/u/SathishPrakasam)\
**Post date:** [November 23, 2019, 4:50am UTC](https://discuss.elastic.co/t/why-the-host-mapping-is-not-wokring/209140/1 "2019-11-23T04:50:24Z")

</div>

Hi Team,

Need clarification on why this mapping is not working.  
Logstash field,  
"host" =\> "[vzon-pdm-prod.gnm.dns.denc.nka.net](http://vzon-pdm-prod.gnm.dns.denc.nka.net)"

Template mapping:  
"host": {"type": "keyword" }

Its throwing below error while sending mapping to Elastic,

Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"lsh-usa\_verizon\_core2a\_8650sdm\_v4-2019.11.23", :\_type=\>"\_doc", :\_routing=\>nil}, #LogStash::Event:0x7986175f], :response=\>{"index"=\>{"\_index"=\>"lsh-usa\_verizon\_core2a\_8650sdm\_v4-2019.11.23", "\_type"=\>"\_doc", "\_id"=\>"B7aMlm4BIqQPqzL49rWu", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to find type parsed [string] for [host]"}}}}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 23, 2019, 2:56pm UTC](https://discuss.elastic.co/t/why-the-host-mapping-is-not-wokring/209140/2 "2019-11-23T14:56:03Z")

</div>

If you use

```
output { stdout { codec => rubydebug } }

```

what do the [host] and [logtime] fields look like?

---

<div class="post-metadata">

**Author:** ![SathishPrakasam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sathishprakasam/32/46290_2.png) [@SathishPrakasam](https://discuss.elastic.co/u/SathishPrakasam)\
**Post date:** [November 25, 2019, 7:29am UTC](https://discuss.elastic.co/t/why-the-host-mapping-is-not-wokring/209140/3 "2019-11-25T07:29:17Z")

</div>

Hi Badger,

"host" =\> "[vzon-pdm-prod.gnm.dns.denc.nka.net](http://vzon-pdm-prod.gnm.dns.denc.nka.net))"  
I got rid of the host issue, am able to send host to the elastic.

However date mapping is giving me trouble,

logtime from grok stdout debug:

"logtime" =\> "2019-11-20 17:31:46"

Grok mapping:  
{TIMESTAMP\_ISO8601:logtime}

Date parsing:  
date  
{  
match =\> ["logtime" ,"yyyy-MM-dd HH-mm-ss"]  
timezone =\> UTC  
target =\> "logtime"  
}  
Template mapping:  
"logtime": {"type": "date", "format" : "yyyy-MM-dd HH-mm-ss"}

Error while sending to elastic:

[2019-11-25T01:23:07,800][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"lsh-new-tempindexfor8650sdm\_v4-2019.11.25", :\_type=\>"sdmmapping", :\_routing=\>nil}, #LogStash::Event:0x5e4e0083], :response=\>{"index"=\>{"\_index"=\>"lsh-new-tempindexfor8650sdm\_v4-2019.11.25", "\_type"=\>"sdmmapping", "\_id"=\>"z99xoW4BoNYXwHJfTgZZ", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [logtime] of type [date] in document with id 'z99xoW4BoNYXwHJfTgZZ'", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Invalid format: "2019-11-20 17:31:46" is malformed at "-11-20 17:31:46""}}}}}

A quick help reply on this will be great help for me please 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 25, 2019, 3:09pm UTC](https://discuss.elastic.co/t/why-the-host-mapping-is-not-wokring/209140/4 "2019-11-25T15:09:23Z")

</div>

You have used a date filter to convert [logtime] to a LogStash::Timestamp. I don't think you need a template for the field once you have done that. elasticsearch will by default convert it to a date.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 23, 2019, 3:10pm UTC](https://discuss.elastic.co/t/why-the-host-mapping-is-not-wokring/209140/5 "2019-12-23T15:10:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
