# Elastic-agent to logstash mapper\_parsing\_exception with windows system integration

**URL:** <https://discuss.elastic.co/t/elastic-agent-to-logstash-mapper-parsing-exception-with-windows-system-integration/330300>\
**Category:** Elastic Agent\
**Tags:** fleet\
**Created:** [April 19, 2023, 11:58am UTC](https://discuss.elastic.co/t/elastic-agent-to-logstash-mapper-parsing-exception-with-windows-system-integration/330300 "2023-04-19T11:58:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![irivas95](https://avatars.discourse-cdn.com/v4/letter/i/839c29/32.png) [@irivas95](https://discuss.elastic.co/u/irivas95)\
**Post date:** [April 19, 2023, 11:58am UTC](https://discuss.elastic.co/t/elastic-agent-to-logstash-mapper-parsing-exception-with-windows-system-integration/330300/1 "2023-04-19T11:58:33Z")

</div>

Hi,  
I am trying to send windows events via an elastic-agent (8.6.0) (with fleet in 8.6.0) to logstash (8.6.0).  
the eleastic-agent is configured with an agent policy that has a system integration configured as follows:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/4/54ae35cbbcee1b183412781b828fe488f763214c.png)

and the pipeline:

```auto
input {
  elastic_agent {
    port => "5047"
    ssl => true
    ssl_key => '/etc/pki/logstash.pkcs8.key'
    ssl_certificate => '/etc/pki/logstash.crt'
  }
}

filter {
  if ([input][type] =~ "winlog") {
    mutate {
      remove_field => ["[winlog][logon][id]",
                       "[winlog][provider_guid]",
                       "[winlog][record_id]",
                       "[winlog][event_data][LogonType]",
                       "[winlog][event_data][AccessList]",
                       "[winlog][event_data][AccessMask]",
                       "[winlog][event_data][HandleId]",
                       "[winlog][event_data][ElevatedToken]",
                       "[winlog][event_data][ResourceAttributes]",
                       "[winlog][event_data][ImpersonationLevel]",
                       "[winlog][event_data][KeyType]",
                       "[winlog][event_data][SamAccountName]",
                       "[winlog][event_data][KeyLength]",
                       "[winlog][event_data][Operation]",
                       "[winlog][event_data][Binary]",
                       "[winlog][event_data][NewState]",
                       "[winlog][event_data][SubjectLogonId]",
                       "[winlog][event_data][CountNew]",
                       "[winlog][event_data][CountOld]",
                       "[winlog][event_data][DwordVal]",
                       "[winlog][event_data][DriverNameLength]",
                       "[winlog][event_data][FailureNameLength]",
                       "[winlog][event_data][ExtraStringLength]",
                       "[winlog][event_data][AddressLength]",
                       "[winlog][event_data][ProcessNameLength]",
                       "[winlog][keywords]",
                       "[winlog][process][thread][id]",
                       "[host][os][family]",
                       "[host][os][type]",
                       "[host][os][platform]"
                      ]
    }
  }
}

output {
  elasticsearch {
    hosts => ["https://host1:9200","https://host2:9200","https://host3:9200"]
    user => 'user'
    password => "${PASSWORD}"
    cacert => '/etc/pki/ca.crt'
    ilm_rollover_alias => "win-logs"
    ilm_pattern => "{now/d}-000001"
    ilm_policy => "20-days-default"
  }
}

```

when i enable the system and security options, i get the following error in logstash:

```auto
"error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [data_stream.dataset] of type [constant_keyword] in document. Preview of field's value: 'system.system'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"[constant_keyword] field [data_stream.dataset] only accepts values that are equal to the value defined in the mappings [system.security], but got [system.system]"}}}}

```

Could someone help me to understand what could cause this error or/and how to solve it?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Julia\_Bardi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julia_bardi/32/79463_2.png) [@Julia\_Bardi](https://discuss.elastic.co/u/Julia_Bardi)\
**Post date:** [May 8, 2023, 11:54am UTC](https://discuss.elastic.co/t/elastic-agent-to-logstash-mapper-parsing-exception-with-windows-system-integration/330300/2 "2023-05-08T11:54:11Z")

</div>

Hello,

From the error message it seems like the system.security data stream only accepts "system.security" as dataset name, and it received "system.system".  
Do you see these settings in the agent policy Advanced options of the data streams?

The System integration docs are here: [System | Elastic docs](https://docs.elastic.co/integrations/system)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2023, 11:54am UTC](https://discuss.elastic.co/t/elastic-agent-to-logstash-mapper-parsing-exception-with-windows-system-integration/330300/3 "2023-06-05T11:54:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
