# Logstash could not index event to Elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch/254234>\
**Category:** Logstash\
**Created:** [November 4, 2020, 9:33am UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch/254234 "2020-11-04T09:33:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [November 4, 2020, 9:33am UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch/254234/1 "2020-11-04T09:33:11Z")

</div>

Hello eveybody,  
I am using Logstash to parse my firewall logs, and in some logs I am getting that errors:

```auto
[2020-11-03T16:07:22,361][WARN][logstash.outputs.elasticsearch][main][f05eea78ee20871f68357cbab5919471405decdd543eeae8c79baf8bd6c2af6a] Could not index event to Elasticsearch. {:status=>400, 
"reason"=>"failed to parse field [slotlevel] of type [integer] in document with id 'KZeljnUBd54xy33-9Zlx'
"reason"=>"Numeric value (4294967295) out of range of int (-2147483648 - 2147483647)\n at 

```

I understand from that logs that the value of the field `slotlevel` is much bigger than what we can store in an `int` type.

Can you tell me please what type I can use in `grok` to solve that problem.

In my case I am using this filter to parse that log:

```auto
(slotlevel=%{NUMBER:slotlevel:int} )?

```

Thanks for your help

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 5, 2020, 3:37am UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch/254234/2 "2020-11-05T03:37:22Z")

</div>

You can use the `int` there, but you may need to change the mapping for the field in Elasticsearch to use [`long`](https://www.elastic.co/guide/en/elasticsearch/reference/7.9/number.html) instead.

---

<div class="post-metadata">

**Author:** ![TheHunter1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thehunter1/32/80190_2.png) [@TheHunter1](https://discuss.elastic.co/u/TheHunter1)\
**Post date:** [November 5, 2020, 1:31pm UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch/254234/3 "2020-11-05T13:31:13Z")

</div>

Oh thank you, so the problem is in the mapping and not in the grok filter.  
If I change the `integer` to `long` by running `PUT _template/firewall` again in the Dev Tool on Kibana I won't have a problem in my index ? or there is another solution to change the mapping ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 5, 2020, 9:44pm UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch/254234/4 "2020-11-05T21:44:31Z")

</div>

That will only apply for new indices, but it's the right way to do it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2020, 9:44pm UTC](https://discuss.elastic.co/t/logstash-could-not-index-event-to-elasticsearch/254234/5 "2020-12-03T21:44:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
