# Filebeat: failed to parse rx\_queue: strconv.ParseInt: parsing "0000AC00": invalid syntax

**URL:** <https://discuss.elastic.co/t/filebeat-failed-to-parse-rx-queue-strconv-parseint-parsing-0000ac00-invalid-syntax/352893>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 8, 2024, 8:57pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-parse-rx-queue-strconv-parseint-parsing-0000ac00-invalid-syntax/352893 "2024-02-08T20:57:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Daniel314](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel314/32/21668_2.png) [@Daniel314](https://discuss.elastic.co/u/Daniel314)\
**Post date:** [February 8, 2024, 8:57pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-parse-rx-queue-strconv-parseint-parsing-0000ac00-invalid-syntax/352893/1 "2024-02-08T20:57:01Z")

</div>

Hi,

I'm using the UDP input in filebeat for collecting logs, and I'm seeing it periodically errors like this:

2024-02-08T12:48:19.399-0700 WARN [input.udp] map[file.line:251 file.name:udp/input.go function:github.com/elastic/beats/v7/filebeat/input/udp.(\*inputMetrics).poll] failed to get udp stats from /proc: failed to parse rx\_queue: strconv.ParseInt: parsing "0000E000": invalid syntax {"ecs.version": "1.6.0"}

This is with Filebeat version 8.12.0  
I didn't experience this error with Filebeat version 7.17 (I don't recall which subversion).

I've manually created a go program and copy/pasted the offending values into strings and cannot re-create the error outside of Filebeat. These errors occur multiples of 60 seconds apart (I assume with the UDP statistics collection interval). Most of the time it's 2 minutes between error reports, but I've seen intervals as high as 14 minutes between errors. Over the course of 104 hours, I've seen 3000+ errors like this logged.

Given that the strings look like valid hexadecimal values, I suspect some type of data corruption is happening, but have no guesses as to what. After restarting filebeat, I saw the first of these errors within 5 minutes.

Thoughts?  
Thanks,

- Daniel

---

<div class="post-metadata">

**Author:** ![Daniel314](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel314/32/21668_2.png) [@Daniel314](https://discuss.elastic.co/u/Daniel314)\
**Post date:** [February 9, 2024, 10:01pm UTC](https://discuss.elastic.co/t/filebeat-failed-to-parse-rx-queue-strconv-parseint-parsing-0000ac00-invalid-syntax/352893/2 "2024-02-09T22:01:31Z")

</div>

This appears to have been addressed in Filebat v8.12.1

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2024, 12:02am UTC](https://discuss.elastic.co/t/filebeat-failed-to-parse-rx-queue-strconv-parseint-parsing-0000ac00-invalid-syntax/352893/3 "2024-03-09T00:02:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
