# 5.4.1 broke netflow codec!

**URL:** https://discuss.elastic.co/t/5-4-1-broke-netflow-codec/88793
**Category:** Logstash
**Created:** [June 9, 2017, 6:00am UTC](https://discuss.elastic.co/t/5-4-1-broke-netflow-codec/88793 "2017-06-09T06:00:31Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)
#### Post date: [June 9, 2017, 6:00am UTC](https://discuss.elastic.co/t/5-4-1-broke-netflow-codec/88793/1 "2017-06-09T06:00:31Z")

</div>

Hi,

Big problem here. I upgraded from 5.4.0 to 5.4.1 and now I'm having big problems with netflow.

On 5.4.0 I had two netflow v9 devices inputting data, this appeared to work fine though I did not reboot the server after adding the second device.

After upgrading I'm now getting a lot of errors. Both IP's still log some of the netflow packets but the packets containing the actual data (host, source, dst etc) are not there anymore. I tried connecting just one device but no change.

error

```auto
2017-06-09T14:52:31,382][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"netflow-2017.06.09", :_type=>"netflow", :_routing=>nil}, 2017-06-09T05:52:30.000Z 2.2.2.2 %{message}], :response=>{"index"=>{"_index"=>"netflow-2017.06.09", "_type"=>"netflow", "_id"=>"AVyLaUaI6EcdITz9UjqF", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [netflow.application_id]", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"0:0\""}}}}}
[2017-06-09T14:52:41,286][INFO][logstash.filters.translate] refreshing dictionary file
[2017-06-09T14:52:41,586][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"netflow-2017.06.09", :_type=>"netflow", :_routing=>nil}, 2017-06-09T05:49:32.000Z 1.1.1.1 %{message}], :response=>{"index"=>{"_index"=>"netflow-2017.06.09", "_type"=>"netflow", "_id"=>"AVyLaW5V6EcdITz9UjqG", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [netflow.application_id]", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"0:0\""}}}}}
[2017-06-09T14:52:41,634][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"netflow-2017.06.09", :_type=>"netflow", :_routing=>nil}, 2017-06-09T05:49:32.000Z 1.1.1.1 %{message}], :response=>{"index"=>{"_index"=>"netflow-2017.06.09", "_type"=>"netflow", "_id"=>"AVyLaW6a6EcdITz9UjqH", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [netflow.application_id]", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"0:0\""}}}}}
[2017-06-09T14:53:04,996][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"netflow-2017.06.09", :_type=>"netflow", :_routing=>nil}, 2017-06-09T05:49:56.000Z 1.1.1.1 %{message}], :response=>{"index"=>{"_index"=>"netflow-2017.06.09", "_type"=>"netflow", "_id"=>"AVyLacnU6EcdITz9UjqJ", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [netflow.application_id]", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"0:0\""}}}}}
[2017-06-09T14:53:05,158][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"netflow-2017.06.09", :_type=>"netflow", :_routing=>nil}, 2017-06-09T05:49:56.000Z 1.1.1.1 %{message}], :response=>{"index"=>{"_index"=>"netflow-2017.06.09", "_type"=>"netflow", "_id"=>"AVyLacp46EcdITz9UjqK", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [netflow.application_id]", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"0:0\""}}}}}
[2017-06-09T14:53:26,890][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"netflow-2017.06.09", :_type=>"netflow", :_routing=>nil}, 2017-06-09T05:50:17.000Z 1.1.1.1 %{message}], :response=>{"index"=>{"_index"=>"netflow-2017.06.09", "_type"=>"netflow", "_id"=>"AVyLah9f6EcdITz9Ujqk", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [netflow.application_id]", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"0:0\""}}}}}
[2017-06-09T14:53:26,918][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"netflow-2017.06.09", :_type=>"netflow", :_routing=>nil}, 2017-06-09T05:50:17.000Z 1.1.1.1 %{message}], :response=>{"index"=>{"_index"=>"netflow-2017.06.09", "_type"=>"netflow", "_id"=>"AVyLah966EcdITz9Ujql", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [netflow.application_id]", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"0:0\""}}}}}
[2017-06-09T14:53:41,366][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"netflow-2017.06.09", :_type=>"netflow", :_routing=>nil}, 2017-06-09T05:53:40.000Z 2.2.2.2 %{message}], :response=>{"index"=>{"_index"=>"netflow-2017.06.09", "_type"=>"netflow", "_id"=>"AVyLalft6EcdITz9Ujqm", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [netflow.application_id]", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"0:0\""}}}}}
```

config (worked fine with 5.4.0)

[code]input {  
udp {  
port =\> 9995  
type =\> "netflow"  
codec =\> netflow {  
versions =\> [9]  
}  
}  
}

filter {  
mutate {  
add\_field =\> {  
"[netflow][ipv4\_dst\_host]" =\> "%{[netflow][ipv4\_dst\_addr]}"  
"[netflow][ipv4\_src\_host]" =\> "%{[netflow][ipv4\_src\_addr]}"  
}  
}

if ([netflow][l4\_dst\_port]) {  
mutate {  
add\_field =\> {  
"[netflow][l4\_dst\_port\_translation]" =\> "%{[netflow][l4\_dst\_port]}"  
}  
}  
}

translate {  
dictionary\_path =\> '/etc/logstash/port\_translation.yaml'  
field =\> "[netflow][l4\_dst\_port\_translation]"  
override =\> true  
destination =\> "[netflow][l4\_dst\_port\_translation]"  
}

dns {  
action =\> 'replace'  
reverse =\> "[netflow][ipv4\_dst\_host]"  
}

dns {  
action =\> 'replace'  
reverse =\> "[netflow][ipv4\_src\_host]"  
}  
}

output {  
if [type] == "netflow" {  
elasticsearch {  
hosts =\> localhost  
index =\> "netflow-%{+YYYY.MM.dd}"  
}  
}  
}  
[/code]

Please help. For my project its essential I have netflow from multiple locations (all v9) working.

---

<div class="post-metadata">

### Author: ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)
#### Post date: [June 9, 2017, 6:32am UTC](https://discuss.elastic.co/t/5-4-1-broke-netflow-codec/88793/2 "2017-06-09T06:32:39Z")

</div>

Why would you need to upgrade Logstash to 5.4.1 while 5.4.0 is working fine? There's no need to upgrade LS along with ES.

---

<div class="post-metadata">

### Author: ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)
#### Post date: [June 9, 2017, 7:39am UTC](https://discuss.elastic.co/t/5-4-1-broke-netflow-codec/88793/3 "2017-06-09T07:39:34Z")

</div>

Should be on the user guide then.

Reinstalled 5.4.0, lets see how it goes.

---

<div class="post-metadata">

### Author: ![Sjaak01](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@Sjaak01](https://discuss.elastic.co/u/Sjaak01)
#### Post date: [June 9, 2017, 8:09am UTC](https://discuss.elastic.co/t/5-4-1-broke-netflow-codec/88793/4 "2017-06-09T08:09:50Z")

</div>

5.4.0 appears to be working.

Near mental breakdown moment hehe...

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 7, 2017, 8:10am UTC](https://discuss.elastic.co/t/5-4-1-broke-netflow-codec/88793/5 "2017-07-07T08:10:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
