elastic / elastic/integrations
[Elastic Agent]: Document parsing exception
- Dominant language
- Handlebars
- Stars
- 333
- Forks
- 647
- Avg merge
- 3d 4h
- Merged PRs (30d)
- 209
Description
### Integration Name
Elastic Agent [packages/elastic_agent]
### Dataset Name
_No response_
### Integration Version
2.9.4
### Agent Version
9.5.2
### Agent Output Type
elasticsearch
### Elasticsearch Version
9.5.2
### OS Version and Architecture
Windows 11
### Software/API Version
_No response_
### Error Message
[1:1207] object mapping for [component] tried to parse field [component] as object, but found a concrete value",
"stack_trace": "o.e.i.m.DocumentParsingException: [1:1207] object mapping for [component] tried to parse field [component] as object, but found a concrete value\n\tat o.e.i.m.DocumentParser.throwOnConcreteValue(DocumentParser.java:383)\n\tat o.e.i.m.DocumentParser.parseObjectOrNested(DocumentParser.java:337)\n\t... 45 more\n
### Event Original
[event_original.txt](https://github.com/user-attachments/files/31456095/event_original.txt)
### What did you do?
Just enable elastic_agent logs ingestion
### What did you see?
When analyzing Streams output the dataset logs-elastic_agent-windows_ORG is with degraded quality due to the error exposed
### What did you expect to see?
No errors
### Anything else?
_No response_
Contributor guide
Research direction
Start by reading event_original.txt and inspecting the packages/elastic_agent integration configuration to trace how the component field is emitted. Reproduce the logs-elastic_agent-windows_ORG ingestion failure on the stated versions, then verify that the dataset indexes without the DocumentParsingException.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- elasticsearch, handlebars
- Domain
- observability-sre
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 38/100