# Filebeats NetFlow: Events dropped due to out of range of long value

**URL:** <https://discuss.elastic.co/t/filebeats-netflow-events-dropped-due-to-out-of-range-of-long-value/377375>\
**Category:** Elasticsearch\
**Created:** [April 22, 2025, 2:03pm UTC](https://discuss.elastic.co/t/filebeats-netflow-events-dropped-due-to-out-of-range-of-long-value/377375 "2025-04-22T14:03:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vjineo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vjineo/32/142764_2.png) [@vjineo](https://discuss.elastic.co/u/vjineo)\
**Post date:** [April 22, 2025, 2:03pm UTC](https://discuss.elastic.co/t/filebeats-netflow-events-dropped-due-to-out-of-range-of-long-value/377375/1 "2025-04-22T14:03:50Z")

</div>

Most of the events are dropped with below error:

```auto
{\"type\":\"document_parsing_exception\",\"reason\":\"[1:1475] failed to parse field [netflow.flow_id] of type [long] in document with id 'M7a4XZYB_Zr7jpsbS6pn'. Preview of field's value: '11133470849011551241'\",\"caused_by\":{\"type\":\"x_content_parse_exception\",\"reason\":\"[1:1495] Numeric value (11133470849011551241) out of range of long (-9223372036854775808 - 9223372036854775807)\\n

```

As per standard, netflow.flow\_id is unsigned64. But Filebeat incorrectly uses 'long' type for that field.

Need a way to either modify it to 'unsigned long' on Filebeat or elasticsearch. Tried configuring processor to convert this to string and write it in a new field and then drop the old field. Even after doing that, I'm still seeing lots of events dropped messages in /var/log/filebeat/\*ndjson file.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 22, 2025, 2:42pm UTC](https://discuss.elastic.co/t/filebeats-netflow-events-dropped-due-to-out-of-range-of-long-value/377375/2 "2025-04-22T14:42:41Z")

</div>

Closed Dup Of

> [@Netflow.flow\_id data type incorrectly set to long instead of unsigned-long](https://discuss.elastic.co/t/netflow-flow-id-data-type-incorrectly-set-to-long-instead-of-unsigned-long/377377):
>
> In /etc/filebeats/fields.yaml file, netflow.flow\_id is set to type long. - name: flow\_id type: long As per NetFlow standard, it should be unsigned long. Because of this, events are getting dropped with error: (status=400): {\"type\":\"document\_parsing\_exception\",\"reason\":\"[1:1477] failed to parse field [netflow.flow\_id] of type [long] in document with id 'Lba4XZYB\_Zr7jpsbS6pn'. Preview of field's value: '11133470846251699209'\",\"caused\_by\":{\"type\":\"x\_content\_parse…

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 22, 2025, 2:42pm UTC](https://discuss.elastic.co/t/filebeats-netflow-events-dropped-due-to-out-of-range-of-long-value/377375/3 "2025-04-22T14:42:47Z")

</div>


