[2018-05-31T05:22:35,741][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>"2909338251", :_index=>"logs-endpoint-winevent-sysmon-2018.05.31", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x552c1397>], :response=>{"index"=>{"_index"=>"logs-endpoint-winevent-sysmon-2018.05.31", "_type"=>"doc", "_id"=>"2909338251", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [user] tried to parse field [user] as object, but found a concrete value"}}}}
[2018-05-31T05:22:35,745][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>"3915583766", :_index=>"logs-endpoint-winevent-sysmon-2018.05.31", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x7aeff589>], :response=>{"index"=>{"_index"=>"logs-endpoint-winevent-sysmon-2018.05.31", "_type"=>"doc", "_id"=>"3915583766", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [user] tried to parse field [user] as object, but found a concrete value"}}}}
[2018-05-31T05:22:35,749][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>"972395887", :_index=>"logs-endpoint-winevent-sysmon-2018.05.31", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x1a5c86b>], :response=>{"index"=>{"_index"=>"logs-endpoint-winevent-sysmon-2018.05.31", "_type"=>"doc", "_id"=>"972395887", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [user] tried to parse field [user] as object, but found a concrete value"}}}}
[2018-05-31T05:22:35,758][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>"1068475737", :_index=>"logs-endpoint-winevent-sysmon-2018.05.31", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x508a96b9>], :response=>{"index"=>{"_index"=>"logs-endpoint-winevent-sysmon-2018.05.31", "_type"=>"doc", "_id"=>"1068475737", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [user] tried to parse field [user] as object, but found a concrete value"}}}}
[2018-05-31T05:22:37,287][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>"1346072995", :_index=>"logs-endpoint-winevent-sysmon-2018.05.31", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0xd22f716>], :response=>{"index"=>{"_index"=>"logs-endpoint-winevent-sysmon-2018.05.31", "_type"=>"doc", "_id"=>"1346072995", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [user] tried to parse field [user] as object, but found a concrete value"}}}}
[2018-05-31T05:22:37,484][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>"1346072995", :_index=>"logs-endpoint-winevent-sysmon-2018.05.31", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x3d3fc5e0>], :response=>{"index"=>{"_index"=>"logs-endpoint-winevent-sysmon-2018.05.31", "_type"=>"doc", "_id"=>"1346072995", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [user] tried to parse field [user] as object, but found a concrete value"}}}}
[2018-05-31T05:22:41,424][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>"3546335163", :_index=>"logs-endpoint-winevent-sysmon-2018.05.31", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x109a6a35>], :response=>{"index"=>{"_index"=>"logs-endpoint-winevent-sysmon-2018.05.31", "_type"=>"doc", "_id"=>"3546335163", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [user] tried to parse field [user] as object, but found a concrete value"}}}}
[2018-05-31T05:22:41,509][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>"3546335163", :_index=>"logs-endpoint-winevent-sysmon-2018.05.31", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x3776ba84>], :response=>{"index"=>{"_index"=>"logs-endpoint-winevent-sysmon-2018.05.31", "_type"=>"doc", "_id"=>"3546335163", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"object mapping for [user] tried to parse field [user] as object, but found a concrete value"}}}}
sudo docker logs --follow helk-logstash