# Logstash error "out of range for an integer"

**URL:** <https://discuss.elastic.co/t/logstash-error-out-of-range-for-an-integer/357152>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [April 10, 2024, 1:32pm UTC](https://discuss.elastic.co/t/logstash-error-out-of-range-for-an-integer/357152 "2024-04-10T13:32:58Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Karthick\_D](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karthick_d/32/127089_2.png) [@Karthick\_D](https://discuss.elastic.co/u/Karthick_D)\
**Post date:** [April 10, 2024, 1:32pm UTC](https://discuss.elastic.co/t/logstash-error-out-of-range-for-an-integer/357152/1 "2024-04-10T13:32:58Z")

</div>

Getting this error on logatsh-plain.log

[2024-04-10T13:22:24,797][WARN][logstash.outputs.elasticsearch][geoip][2a0f384086e1f5f8eba88bc1849f4a5149188de0fdacb6e00d827adfb445e001] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-syslog-2024.04.10", :routing=\>nil}, {"message"=\>"\<189\>date=2024-04-10 time=16:22:23 devname="SIN" devid="F3211" eventtime=1712755342941122066 tz="+0300" logid="0000000020" type="traffic" subtype="forward" level="notice" vd="SINFGFWCORP" srcip=10.XX.XX.1 srcport=7635 srcintf="npu0\_vlink1" srcintfrole="undefined" dstip=10.XX.XX.20 dstport=514 dstintf="SIN" dstintfrole="wan" srccountry="Reserved" dstcountry="Reserved" sessionid=2763 proto=17 action="accept" policyid=3 policytype="policy" poluuid="b2d647ea-f912-51eb-5107-61d7234edaa0" policyname="Root VDOM - Fortiguard access" service="SYSLOG" trandisp="snat" transip=10.XX.XX.11 transport=7635 appid=16283 app="Syslog" appcat="Network.Service" apprisk="elevated" applist="g-default" duration=1426684 sentbyte=24592153638 rcvdbyte=0 sentpkt=24543119 rcvdpkt=0 shapingpolicyid=5 shapingpolicyname="SEEF to SINDC Traffic" shapersentname="guarantee-25Mb" shaperdropsentbyte=0 shaperrcvdname="guarantee-25Mb" shaperdroprcvdbyte=0 sentdelta=2482165 rcvddelta=0 durationdelta=144 sentpktdelta=2517 rcvdpktdelta=0", "observer\_hostname"=\>"SIN", "application\_risk"=\>"elevated", "@timestamp"=\>2024-04-10T13:22:24.534Z, "tag1"=\>"fortigatekv", "destination\_packets"=\>"0", "event\_severity"=\>"notice", "event\_duration"=\>"1426684", "Inputtag"=\>"syslog", "destination\_ip"=\>"10.XX.XX..20", "event\_created"=\>"2024-04-10T16:22:23.000Z", "observer\_ingress\_zone"=\>"wan", "destination\_bytes"=\>"0", "source\_bytes"=\>"24592153638", "virtual\_domain\_name"=\>"SI", "network\_protocol"=\>"UDP", "observer\_name"=\>"Fortigate", "observer\_egress\_zone"=\>"undefined", "destination\_port"=\>"514", "source\_port"=\>"7635", "source\_interface"=\>"npu0\_vlink1", "observer\_product"=\>"Fortigate Firewall", "event\_action"=\>"accept", "src\_ip"=\>"10.XX.XX.1", "src\_hostname"=\>"Server", "source\_nat\_port"=\>"7635", "event\_log\_size"=\>1044, "source\_packets"=\>"24543119", "source\_nat\_ip"=\>"10.XX.XX.1", "application\_list"=\>"g-default", "@version"=\>"1", "engine\_id"=\>"1554", "observer\_ip"=\>"10.XX.XX.1", "event\_log\_count"=\>1, "config\_version"=\>"v7.1", "policy\_id"=\>"3", "observer\_type"=\>"Firewall", "log\_type"=\>"traffic", "clientkey"=\>"ProACT", "fingerprint"=\>"8b261b40f08eb2ad974269b9064fc937", "event\_category"=\>"forward", "observer\_vendor"=\>"Fortigate", "observer\_category"=\>"Firewall", "network\_application"=\>"Syslog", "engine\_log\_id"=\>"0000000020", "network\_service"=\>"SYSLOG", "destination\_interface"=\>"SINFS-V252", "source\_ip"=\>"10.198.250.1", "policy\_name"=\>"Root VDOM - Fortiguard access", "application\_category"=\>"Network.Service", "event\_start"=\>"1712755342941122066", "observer\_id"=\>"FG4H1ETB21900708", "application\_id"=\>"16283"}], :response=\>{"index"=\>{"\_index"=\>"logstash-syslog-2024.04.10", "\_type"=\>"\_doc", "\_id"=\>"mKIsyI4BV74eTaBKhYF-", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [source\_bytes] of type [integer] in document with id 'mKIsyI4BV74eTaBKhYF-'. Preview of field's value: '24592153638'", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Value [24592153638] is out of range for an integer"}}}}}  
q^C

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 10, 2024, 4:03pm UTC](https://discuss.elastic.co/t/logstash-error-out-of-range-for-an-integer/357152/2 "2024-04-10T16:03:48Z")

</div>

> [@Karthick\_D](#):
>
> "reason"=\>"failed to parse field [source\_bytes] of type [integer] in document with id 'mKIsyI4BV74eTaBKhYF-'. Preview of field's value: '24592153638'", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Value [24592153638] is out of range for an integer"}}}}}

Most likely [source\_bytes] is mapped as an [integer](https://www.elastic.co/guide/en/elasticsearch/reference/current/number.html) in elasticsearch. That can contain values from -2^31 to 2^31-1 (+ or - 2 billion). A number over 24 billion cannot be contained in that.

Change the mapping of the index to make source\_bytes a long rather than an integer. You will need to re-index the data into the index with the new mapping.
