# Analyzing network packets with Wireshark, Elasticsearch, and Kibana

**URL:** <https://discuss.elastic.co/t/analyzing-network-packets-with-wireshark-elasticsearch-and-kibana/227482>\
**Category:** Kibana\
**Created:** [April 10, 2020, 10:43am UTC](https://discuss.elastic.co/t/analyzing-network-packets-with-wireshark-elasticsearch-and-kibana/227482 "2020-04-10T10:43:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![elify](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elify/32/46234_2.png) [@elify](https://discuss.elastic.co/u/elify)\
**Post date:** [April 10, 2020, 10:43am UTC](https://discuss.elastic.co/t/analyzing-network-packets-with-wireshark-elasticsearch-and-kibana/227482/1 "2020-04-10T10:43:18Z")

</div>

> **[Analyzing network packets with Wireshark, Elasticsearch, and Kibana](https://www.elastic.co/blog/analyzing-network-packets-with-wireshark-elasticsearch-and-kibana)**
>
> Learn how to architect a real-time data pipeline for network packet analysis using Wireshark, Filebeat, Logstash, Ingest Pipelines, Elasticsearch, and Kibana.

Hello,  
I tried this document. I got some mistakes.  
Firtstly, I tried mapping in document.

 ![Screenshot_1](https://us1.discourse-cdn.com/elastic/original/3X/7/4/74cd8ee1adef7b6995bd55926b114de6fcdf54df.png)

Then I got this error;

```auto
  {
            "error" : {
            "root_cause" : [
            {
        "type" : "mapper_parsing_exception",
        "reason" : "Root mapping definition has unsupported parameters: [pcap_file : {dynamic=false, properties={layers={properties={udp={properties={udp_udp_srcport={type=integer}, udp_udp_dstport={type=integer}}}, ip={properties={ip_ip_src={type=ip}, ip_ip_dst={type=ip}}}, frame={properties={frame_frame_len={type=long}, frame_frame_protocols={type=keyword}}}}}, timestamp={type=date}}}]"
        }
        ],
        "type" : "mapper_parsing_exception",
        "reason" : "Failed to parse mapping [_doc]: Root mapping definition has unsupported parameters: [pcap_file : {dynamic=false, properties={layers={properties={udp={properties={udp_udp_srcport={type=integer}, udp_udp_dstport={type=integer}}}, ip={properties={ip_ip_src={type=ip}, ip_ip_dst={type=ip}}}, frame={properties={frame_frame_len={type=long}, frame_frame_protocols={type=keyword}}}}}, timestamp={type=date}}}]",
        "caused_by" : {
        "type" : "mapper_parsing_exception",
        "reason" : "Root mapping definition has unsupported parameters: [pcap_file : {dynamic=false, properties={layers={properties={udp={properties={udp_udp_srcport={type=integer}, udp_udp_dstport={type=integer}}}, ip={properties={ip_ip_src={type=ip}, ip_ip_dst={type=ip}}}, frame={properties={frame_frame_len={type=long}, frame_frame_protocols={type=keyword}}}}}, timestamp={type=date}}}]"
        }
        },
        "status" : 400
        }

```

After I tried curl part

 ![Screenshot_2](https://us1.discourse-cdn.com/elastic/original/3X/4/c/4c2165be42a19fa0ee90e19542f376f782b8219d.png)

I solved these errors like this;

 ![Screenshot_3](https://us1.discourse-cdn.com/elastic/original/3X/3/8/3831dbc314444eb4049a038df8a213301ee131b3.png)

This caused other problems. How can I solve?

---

<div class="post-metadata">

**Author:** ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)\
**Post date:** [April 10, 2020, 1:00pm UTC](https://discuss.elastic.co/t/analyzing-network-packets-with-wireshark-elasticsearch-and-kibana/227482/2 "2020-04-10T13:00:58Z")

</div>

Hey @elify, welcome to the discussion boards!

The blog post you're following is ~2.5 years old, and the example does not work on more modern versions of Elasticsearch. The mapping includes a custom type, and support for this was deprecated in `7.0`.

Try this instead:

```auto
PUT _template/packets
{
  "index_patterns": "packets-*",
  "mappings": {
      "dynamic": "false",
      "properties": {
        "timestamp": {
          "type": "date"
        },
        "layers": {
          "properties": {
            "frame": {
              "properties": {
                "frame_frame_len": {
                  "type": "long"
                },
                "frame_frame_protocols": {
                  "type": "keyword"
                }
              }
            },
            "ip": {
              "properties": {
                "ip_ip_src": {
                  "type": "ip"
                },
                "ip_ip_dst": {
                  "type": "ip"
                }
              }
            },
            "udp": {
              "properties": {
                "udp_udp_srcport": {
                  "type": "integer"
                },
                "udp_udp_dstport": {
                  "type": "integer"
                }
              }
            }
          }
        }
      }
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2020, 1:01pm UTC](https://discuss.elastic.co/t/analyzing-network-packets-with-wireshark-elasticsearch-and-kibana/227482/3 "2020-05-08T13:01:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
