# Failed to parse field \[msg.RequestPort\] of type \[long\]

**URL:** <https://discuss.elastic.co/t/failed-to-parse-field-msg-requestport-of-type-long/312080>\
**Category:** Logs\
**Created:** [August 15, 2022, 9:05am UTC](https://discuss.elastic.co/t/failed-to-parse-field-msg-requestport-of-type-long/312080 "2022-08-15T09:05:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ayarosh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayarosh/32/109647_2.png) [@ayarosh](https://discuss.elastic.co/u/ayarosh)\
**Post date:** [August 15, 2022, 9:05am UTC](https://discuss.elastic.co/t/failed-to-parse-field-msg-requestport-of-type-long/312080/1 "2022-08-15T09:05:11Z")

</div>

Filebeat cannot parse and drop the logs when receives the different type of input.  
`"RequestPort":"-"` (it usually contains the long type number)

Error:

```auto
{\"type\":\"mapper_parsing_exception\",\"reason\":\"failed to parse field [msg.RequestPort] of type [long] in document with id 'DOCUMENT_ID'. Preview of field's value: '-'\",\"caused_by\":{\"type\":\"illegal_argument_exception\",\"reason\":\"For input string: \\\"-\\\"\"}}, dropping event!"

```

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [August 15, 2022, 10:39am UTC](https://discuss.elastic.co/t/failed-to-parse-field-msg-requestport-of-type-long/312080/2 "2022-08-15T10:39:14Z")

</div>

Hi @ayarosh,

this looks like the target index in Elasticsearch doesn't have a well-defined mapping for the `msg.RequestPort` field. This caused Elasticsearch to [guess it](https://www.elastic.co/guide/en/elasticsearch/reference/current/dynamic-field-mapping.html) as `long` based on the first document it received, which contained that field. If you want to be able to ingest the string `"-"` as a valid value, you'd have to define the field to be of the `keyword` type in the index template that is applied to the index.

---

<div class="post-metadata">

**Author:** ![ayarosh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayarosh/32/109647_2.png) [@ayarosh](https://discuss.elastic.co/u/ayarosh)\
**Post date:** [August 15, 2022, 10:59am UTC](https://discuss.elastic.co/t/failed-to-parse-field-msg-requestport-of-type-long/312080/3 "2022-08-15T10:59:55Z")

</div>

I'm using the ingest pipeline for parsing json logs.

```auto
{
  "processors": [
    {
      "json": {
        "field": "message",
        "target_field": "msg"
      }
    },
    {
      "date_index_name": {
        "field": "@timestamp",
        "index_name_prefix": "index",
        "date_rounding": "d"
      }
    }
  ]
}

```

Is there any way to replace the dash with zero value?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [August 15, 2022, 11:45am UTC](https://discuss.elastic.co/t/failed-to-parse-field-msg-requestport-of-type-long/312080/4 "2022-08-15T11:45:29Z")

</div>

Yes, the [`set` processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/set-processor.html) can set a value conditionally if the appropriate `if` property is given. In your case it could be something like (careful, untested 😇):

```json
{
  "processors": [
    {
      "json": {
        "field": "message",
        "target_field": "msg"
      }
    },
    {
      "date_index_name": {
        "field": "@timestamp",
        "index_name_prefix": "index",
        "date_rounding": "d"
      }
    },
    {
      "set": {
        "field": "msg.RequestPort",
        "value": 0,
        "if": "ctx?.msg?.RequestPort == '-'"
      }
    }
  ]
}

```

Hope this helps?

---

<div class="post-metadata">

**Author:** ![ayarosh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ayarosh/32/109647_2.png) [@ayarosh](https://discuss.elastic.co/u/ayarosh)\
**Post date:** [August 15, 2022, 12:14pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-msg-requestport-of-type-long/312080/5 "2022-08-15T12:14:41Z")

</div>

Thanks Felix!  
I solved my problem; the new logs is coming with 0 port.  
I'm not losing them anymore.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 12, 2022, 12:15pm UTC](https://discuss.elastic.co/t/failed-to-parse-field-msg-requestport-of-type-long/312080/6 "2022-09-12T12:15:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
