I got a whole bunch of negative feedback from my logstash logs:
[2018-04-27T14:07:03,215][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"elastiflow-2018.04.2
7", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x3514da47>], :response=>{"index"=>{"_index"=>"elastiflow-2018.04.27", "_type"=>"doc", "_id"=>"SPlJCGMBQmxOb2YYedF8", "status"=
>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [flow.ip_protocol]", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"U
DP\""}}}}}
[2018-04-27T14:07:03,215][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"elastiflow-2018.04.2
7", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x159805c6>], :response=>{"index"=>{"_index"=>"elastiflow-2018.04.27", "_type"=>"doc", "_id"=>"SflJCGMBQmxOb2YYedF8", "status"=
>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [flow.ip_protocol]", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"T
CP\""}}}}}
[2018-04-27T14:07:03,216][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"elastiflow-2018.04.2
7", :_type=>"doc", :_routing=>nil}, #<LogStash::Event:0x570eb7a7>], :response=>{"index"=>{"_index"=>"elastiflow-2018.04.27", "_type"=>"doc", "_id"=>"SvlJCGMBQmxOb2YYedF8", "status"=
>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [flow.ip_protocol]", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"T
CP\""}}}}}