# Filebeat Cisco module field type randomly changing

**URL:** <https://discuss.elastic.co/t/filebeat-cisco-module-field-type-randomly-changing/268012>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 22, 2021, 7:57pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-field-type-randomly-changing/268012 "2021-03-22T19:57:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![JackScripter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackscripter/32/85911_2.png) [@JackScripter](https://discuss.elastic.co/u/JackScripter)\
**Post date:** [March 22, 2021, 7:57pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-field-type-randomly-changing/268012/1 "2021-03-22T19:57:40Z")

</div>

Hi !

We use 2 filebeat modules (cisco + checkpoint) running on the same server, so it's basically a syslog server. I configured filebeat to use a custom index. For some reason, some field type are mapped incorrectly, especially source.bytes and destination.bytes. Here's the output of same field but on different day:

```auto
GET /myindex-2021.03.13-000005/_mapping/field/destination.bytes
{
  "myindex-2021.03.13-000005" : {
    "mappings" : {
      "destination.bytes" : {
        "full_name" : "destination.bytes",
        "mapping" : {
          "bytes" : {
            "type" : "text",
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          }
        }
      }
    }
  }
}

```

On another day:

```auto
GET /myindex-2021.03.14-000006/_mapping/field/destination.bytes
{
  "myindex-2021.03.14-000006" : {
    "mappings" : {
      "destination.bytes" : {
        "full_name" : "destination.bytes",
        "mapping" : {
          "bytes" : {
            "type" : "long"
          }
        }
      }
    }
  }
}

```

Elasticsearch, Filebeat and Kibana runs on 7.11.2. I already tried to force mapping on the index by doing:

```auto
PUT %3Cmyindex-%7Bnow%2Fd%7D-000001%3E
{
  "aliases": {
    "myalias": {
      "is_write_index": true
    }
  },
  "mappings": {
    "properties": {
      "destination.bytes": {"type": "integer"}
    }
  }
}

```

It worked for the first created index, but after that, the field started again to change.  
One other thing is, our dashboards are still showing the correct value of aggregate functions (ex: `source.bytes + destination.bytes`), but when we try to edit, no field name is shown.

Do you know what can cause this issue ?

Thank you in advance !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2021, 9:58pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-field-type-randomly-changing/268012/2 "2021-04-19T21:58:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
