Hello eveybody,
I am using Logstash to parse my firewall logs, and in some logs I am getting that errors:
[2020-11-03T16:07:22,361][WARN ][logstash.outputs.elasticsearch][main][f05eea78ee20871f68357cbab5919471405decdd543eeae8c79baf8bd6c2af6a] Could not index event to Elasticsearch. {:status=>400,
"reason"=>"failed to parse field [slotlevel] of type [integer] in document with id 'KZeljnUBd54xy33-9Zlx'
"reason"=>"Numeric value (4294967295) out of range of int (-2147483648 - 2147483647)\n at
I understand from that logs that the value of the field slotlevel
is much bigger than what we can store in an int
type.
Can you tell me please what type I can use in grok
to solve that problem.
In my case I am using this filter to parse that log:
(slotlevel=%{NUMBER:slotlevel:int} )?
Thanks for your help