# Error in elasticsearch logs

**URL:** <https://discuss.elastic.co/t/error-in-elasticsearch-logs/118233>\
**Category:** Elasticsearch\
**Created:** [February 2, 2018, 1:29pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-logs/118233 "2018-02-02T13:29:13Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kaouther\_Mechri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaouther_mechri/32/55329_2.png) [@Kaouther\_Mechri](https://discuss.elastic.co/u/Kaouther_Mechri)\
**Post date:** [February 2, 2018, 1:29pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-logs/118233/1 "2018-02-02T13:29:13Z")

</div>

Hello everyone,

I have this Error in my Elasticsearch logs . Do you have any idea please ?  
ELK 6.1.1  
thanks

[2018-02-02T14:20:03,624][DEBUG][o.e.a.b.TransportShardBulkAction] [logstash-2018.02.02][2] failed to execute bulk item (index) BulkShardRequest [[logstash-2018.02.02][2]] containing [index {[logstash-2018.02.02][doc][MCOsVmEB8wwdOBO9ikMm], source[{"user\_id":85,"current\_file#":8,"p1":8,"session\_id":738,"event\_id":2652584166,"blocking\_session":null,"p3":1,"client\_id":null,"p3text":"blocks","sql\_opcode":3,"session\_state":"WAITING","p2text":"block#","qc\_instance\_id":null,"session\_type":"FOREGROUND","p1text":"file#","sql\_child\_number":0,"sql\_id":"1yug1q2vk1kf0","capture\_overhead":"N","port":46708,"plsql\_object\_id":null,"qc\_session\_id":null,"time\_waited":10939,"plsql\_entry\_subprogram\_id":null,"ecid":null,"plsql\_entry\_object\_id":null,"p2":732732,"wait\_class":"User I/O","force\_matching\_signature":17153010401499426907,"service\_hash":3427055676,"module":"JDBC Thin Client","sample\_id":82480688,"blocking\_session\_serial#":null,"blocking\_session\_status":"NO HOLDER","@version":"1","event":"db file sequential read","seq#":1129,"current\_obj#":59388,"program":"JDBC Thin Client","current\_block#":732732,"plsql\_subprogram\_id":null,"@timestamp":"2018-02-02T13:18:03.029Z","event#":117,"machine":"vm-app6-25.local","wait\_class\_id":1740759767,"flags":0,"session\_serial#":3496,"sql\_plan\_hash\_value":166146652,"action":null,"wait\_time":0,"sample\_time":"2018-02-02T13:18:03.029Z","xid":null,"is\_captured":"N"}]}]  
org.elasticsearch.index.mapper.MapperParsingException: failed to parse [force\_matching\_signature]  
at org.elasticsearch.index.mapper.FieldMapper.parse(FieldMapper.java:302) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.mapper.DocumentParser.parseObjectOrField(DocumentParser.java:485) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.mapper.DocumentParser.parseValue(DocumentParser.java:607) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.mapper.DocumentParser.innerParseObject(DocumentParser.java:407) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.mapper.DocumentParser.parseObjectOrNested(DocumentParser.java:384) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.mapper.DocumentParser.internalParseDocument(DocumentParser.java:93) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.mapper.DocumentParser.parseDocument(DocumentParser.java:67) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.mapper.DocumentMapper.parse(DocumentMapper.java:261) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.shard.IndexShard.prepareIndex(IndexShard.java:708) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.shard.IndexShard.applyIndexOperation(IndexShard.java:686) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.shard.IndexShard.applyIndexOperationOnPrimary(IndexShard.java:667) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.bulk.TransportShardBulkAction.executeIndexRequestOnPrimary(TransportShardBulkAction.java:548) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.bulk.TransportShardBulkAction.executeIndexRequest(TransportShardBulkAction.java:140) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.bulk.TransportShardBulkAction.executeBulkItemRequest(TransportShardBulkAction.java:236) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.bulk.TransportShardBulkAction.performOnPrimary(TransportShardBulkAction.java:123) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.bulk.TransportShardBulkAction.shardOperationOnPrimary(TransportShardBulkAction.java:110) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.bulk.TransportShardBulkAction.shardOperationOnPrimary(TransportShardBulkAction.java:72) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$PrimaryShardReference.perform(TransportReplicationAction.java:1033) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$PrimaryShardReference.perform(TransportReplicationAction.java:1011) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.support.replication.ReplicationOperation.execute(ReplicationOperation.java:104) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$AsyncPrimaryAction.onResponse(TransportReplicationAction.java:358) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$AsyncPrimaryAction.onResponse(TransportReplicationAction.java:298) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$1.onResponse(TransportReplicationAction.java:974) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$1.onResponse(TransportReplicationAction.java:971) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.shard.IndexShardOperationPermits.acquire(IndexShardOperationPermits.java:238) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.shard.IndexShard.acquirePrimaryOperationPermit(IndexShard.java:2211) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.support.replication.TransportReplicationAction.acquirePrimaryShardReference(TransportReplicationAction.java:983) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.support.replication.TransportReplicationAction.access$500(TransportReplicationAction.java:97) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$AsyncPrimaryAction.doRun(TransportReplicationAction.java:319) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.common.util.concurrent.AbstractRunnable.run(AbstractRunnable.java:37) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$PrimaryOperationTransportHandler.messageReceived(TransportReplicationAction.java:294) [elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.support.replication.TransportReplicationAction$PrimaryOperationTransportHandler.messageReceived(TransportReplicationAction.java:281) [elasticsearch-6.1.1.jar:6.1.1]

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [February 2, 2018, 1:34pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-logs/118233/2 "2018-02-02T13:34:41Z")

</div>

What is the filed type for `force_matching_signature` in the index mapping?

> org.elasticsearch.index.mapper.MapperParsingException: failed to parse [force\_matching\_signature]  
> at org.elasticsearch.index.mapper.FieldMapper.parse(FieldMapper.java:302) ~[elasticsearch-6.1.1.jar:6.1.1]

---

<div class="post-metadata">

**Author:** ![Kaouther\_Mechri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaouther_mechri/32/55329_2.png) [@Kaouther\_Mechri](https://discuss.elastic.co/u/Kaouther_Mechri)\
**Post date:** [February 2, 2018, 1:49pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-logs/118233/3 "2018-02-02T13:49:30Z")

</div>

It is number but I don't know how to change its type and to which type

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [February 2, 2018, 1:57pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-logs/118233/4 "2018-02-02T13:57:48Z")

</div>

Does `GET logstash-2018.02.02/_mapping` also show it as number?

I'm not on ES6 yet so this is a bit of guess work... I have had fields that should be one type, be something else because the first document indexed in the daily index had a bad format. All subsequent documents failed... That was a fun day...

Anyway, double check what the type is in the specific index.

> "force\_matching\_signature": 17153010401499427000

^^ sure looks like a number to me so can see anything wrong there.

I also ship all logs through Logstash so that I can enforce some rules and mutate fields is need be.

Hope that helps 🙂

---

<div class="post-metadata">

**Author:** ![Kaouther\_Mechri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaouther_mechri/32/55329_2.png) [@Kaouther\_Mechri](https://discuss.elastic.co/u/Kaouther_Mechri)\
**Post date:** [February 2, 2018, 2:02pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-logs/118233/5 "2018-02-02T14:02:45Z")

</div>

> [@A\_B](#):
>
> uble check what the type is in the specific index

thank you for your help . I 've this message in logs .

Caused by: com.fasterxml.jackson.core.JsonParseException: Numeric value (13491499919632766707) out of range of long (-9223372036854775808 - 9223372036854775807)

how ca I check the type . I've never touched to index that's why

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [February 2, 2018, 2:49pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-logs/118233/6 "2018-02-02T14:49:33Z")

</div>

Well, looks like the _type_ is ok. Just the number is too large.

Is that a field you really _need_?

Some possible ways to deal with this. None of them are great but this is what I have done before...

a. drop the `force_matching_signature` filed in Logstash.  
b. truncate the `force_matching_signature` filed in Logstash to make it a valid number.  
c. In ES5 you could change the _type_ and that way get a new mapping in a new index which works ok for me using daily indices. Not sure how that works in ES6 as _types_ have been removed.

Those are all workarounds. It would be good to hear from someone else if there are better longterm solutions 🙂

---

<div class="post-metadata">

**Author:** ![Kaouther\_Mechri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaouther_mechri/32/55329_2.png) [@Kaouther\_Mechri](https://discuss.elastic.co/u/Kaouther_Mechri)\
**Post date:** [February 2, 2018, 2:58pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-logs/118233/7 "2018-02-02T14:58:54Z")

</div>

> [@A\_B](#):
>
> force\_matching\_signature

Oh thanks,

I've dropped the field and it is ok now .

---

<div class="post-metadata">

**Author:** ![Kaouther\_Mechri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaouther_mechri/32/55329_2.png) [@Kaouther\_Mechri](https://discuss.elastic.co/u/Kaouther_Mechri)\
**Post date:** [February 2, 2018, 3:01pm UTC](https://discuss.elastic.co/t/error-in-elasticsearch-logs/118233/8 "2018-02-02T15:01:19Z")

</div>

I h've other errors in my logs :

[2018-02-02T16:00:07,827][DEBUG][o.e.a.s.TransportSearchAction] [elacticsearch.unealgroupe.fr] [packetbeat-6.1.2-2018.02.02][2], node[A3reGyDmStmJEmFIUy8nbQ], [P], s[STARTED], a[id=JGoQKyNI  
SIagg\_dSdGapEQ]: Failed to execute [SearchRequest{searchType=QUERY\_THEN\_FETCH, indices=[\*], indicesOptions=IndicesOptions[id=39, ignore\_unavailable=true, allow\_no\_indices=true, expand\_wildc  
ards\_open=true, expand\_wildcards\_closed=false, allow\_aliases\_to\_multiple\_indices=true, forbid\_closed\_indices=true, ignore\_aliases=false], types=[], routing='null', preference='null', reques  
tCache=null, scroll=null, maxConcurrentShardRequests=5, batchedReduceSize=512, preFilterShardSize=32, source={"size":0,"query":{"bool":{"must":[{"range":{"@timestamp":{"from":1517582707482,  
"to":1517583607482,"include\_lower":true,"include\_upper":true,"format":"epoch\_millis","boost":1.0}}},{"bool":{"must":[{"query\_string":{"query":"beat.name:"vm-mule-25"","fields":[],"type":"  
best\_fields","default\_operator":"or","max\_determinized\_states":10000,"enable\_position\_increments":true,"fuzziness":"AUTO","fuzzy\_prefix\_length":0,"fuzzy\_max\_expansions":50,"phrase\_slop":0,"  
escape":false,"auto\_generate\_synonyms\_phrase\_query":true,"fuzzy\_transpositions":true,"boost":1.0}}],"adjust\_pure\_negative":true,"boost":1.0}}],"adjust\_pure\_negative":true,"boost":1.0}},"agg  
regations":{"3287e740-1b15-11e7-b09e-037021c4f8df":{"filter":{"match\_all":{"boost":1.0}},"aggregations":{"timeseries":{"date\_histogram":{"field":"@timestamp","time\_zone":"Europe/Berlin","in  
terval":"10s","offset":0,"order":{"\_key":"asc"},"keyed":false,"min\_doc\_count":0,"extended\_bounds":{"min":1517582707482,"max":1517583607482}},"aggregations":{"32880e50-1b15-11e7-b09e-037021c  
4f8df":{"avg":{"field":"system.load.15"}}}}}}}}}] lastShard [true]  
org.elasticsearch.transport.RemoteTransportException: [elacticsearch.unealgroupe.fr][192.168.9.160:9300][indices:data/read/search[phase/query]]  
Caused by: org.elasticsearch.common.util.concurrent.EsRejectedExecutionException: rejected execution of org.elasticsearch.common.util.concurrent.TimedRunnable@320c90ed on QueueResizingEsThr  
eadPoolExecutor[search, queue capacity = 1000, min queue capacity = 1000, max queue capacity = 1000, frame size = 2000, targeted response rate = 1s, task execution EWMA = 24.2ms, adjustment  
amount = 50, QueueResizingEsThreadPoolExecutor[search, queue capacity = 1000, org.elasticsearch.common.util.concurrent.QueueResizingEsThreadPoolExecutor@2aab4d97[Running, pool size = 4, ac  
tive threads = 4, queued tasks = 1271, completed tasks = 71276]]]  
at org.elasticsearch.common.util.concurrent.EsAbortPolicy.rejectedExecution(EsAbortPolicy.java:48) ~[elasticsearch-6.1.1.jar:6.1.1]  
at java.util.concurrent.ThreadPoolExecutor.reject(ThreadPoolExecutor.java:823) ~[?:1.8.0\_131]  
at java.util.concurrent.ThreadPoolExecutor.execute(ThreadPoolExecutor.java:1369) ~[?:1.8.0\_131]  
at org.elasticsearch.common.util.concurrent.EsThreadPoolExecutor.doExecute(EsThreadPoolExecutor.java:94) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.common.util.concurrent.QueueResizingEsThreadPoolExecutor.doExecute(QueueResizingEsThreadPoolExecutor.java:93) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.common.util.concurrent.EsThreadPoolExecutor.execute(EsThreadPoolExecutor.java:89) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.search.SearchService.lambda$rewriteShardRequest$0(SearchService.java:988) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.action.ActionListener$1.onResponse(ActionListener.java:60) ~[elasticsearch-6.1.1.jar:6.1.1]  
at org.elasticsearch.index.query.Rewriteable.rewriteAndFetch(Rewriteable.java:113) ~[elasticsearch-6.1.1.jar:6.1.1]

---

<div class="post-metadata">

**Author:** ![Kaouther\_Mechri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaouther_mechri/32/55329_2.png) [@Kaouther\_Mechri](https://discuss.elastic.co/u/Kaouther_Mechri)\
**Post date:** [February 7, 2018, 10:55am UTC](https://discuss.elastic.co/t/error-in-elasticsearch-logs/118233/9 "2018-02-07T10:55:52Z")

</div>

Hello

It was an overload problem .

thanks to all

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2018, 10:56am UTC](https://discuss.elastic.co/t/error-in-elasticsearch-logs/118233/10 "2018-03-07T10:56:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
