# Make create-fields index out of range error

**URL:** <https://discuss.elastic.co/t/make-create-fields-index-out-of-range-error/116131>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 18, 2018, 8:24pm UTC](https://discuss.elastic.co/t/make-create-fields-index-out-of-range-error/116131 "2018-01-18T20:24:17Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zachary\_Buckholz](https://avatars.discourse-cdn.com/v4/letter/z/f1d935/32.png) [@Zachary\_Buckholz](https://discuss.elastic.co/u/Zachary_Buckholz)\
**Post date:** [January 18, 2018, 8:24pm UTC](https://discuss.elastic.co/t/make-create-fields-index-out-of-range-error/116131/1 "2018-01-18T20:24:17Z")

</div>

I am attempting to remake a haproxy filebeat module I did last year manually using the recommended process from [https://www.elastic.co/guide/en/beats/devguide/current/filebeat-modules-devguide.html](https://www.elastic.co/guide/en/beats/devguide/current/filebeat-modules-devguide.html)

make create-fileset MODULE={module} FILESET={fileset}

This first step worked fine, but then I tried to use the make create-fields command to generate a fields.yml

make create-fields MODULE={module} FILESET={fileset}

$ make create-fields MODULE=haproxy FILESET=haproxy\_log  
panic: runtime error: index out of range

goroutine 1 [running]:  
main.newField(0xc4200763b1, 0xd, 0x0, 0x0, 0x0, 0x0, 0x0)  
/home/z/go/src/github.com/elastic/beats/filebeat/scripts/generator/fields/main.go:80 +0x19a  
main.getElementsFromPatterns(0xc420064810, 0x3, 0x3, 0x3, 0xa00005de300, 0x38, 0x38, 0xc420080380)  
/home/z/go/src/github.com/elastic/beats/filebeat/scripts/generator/fields/main.go:122 +0xc2  
main.(\*processors).processFields(0xc420080380, 0x2, 0x4, 0xc420080380, 0x0, 0x0)  
/home/z/go/src/github.com/elastic/beats/filebeat/scripts/generator/fields/main.go:175 +0x58  
main.(\*pipeline).toFieldsYml(0xc4200802c0, 0x0, 0x7ffd11d32291, 0x7, 0x7ffd11d322a3, 0xb, 0xc4200802c0)  
/home/z/go/src/github.com/elastic/beats/filebeat/scripts/generator/fields/main.go:282 +0x66  
main.main()  
/home/z/go/src/github.com/elastic/beats/filebeat/scripts/generator/fields/main.go:327 +0x267  
exit status 2  
make: \*\*\* [create-fields] Error 1

The pipeline.json is pretty straight forward. I am not sure what's going on, it appears to be a []byte array and I think it's related to using the geo\_point field type.

Hopefully someone can point me in the right direction.  
Thanks

{  
"description": "HAProxy Logging",  
"on\_failure": [  
{  
"set": {  
"field": "haproxy.ingest.error",  
"value": "{{ \_ingest.on\_failure\_message }}"  
}  
}  
],  
"processors": [  
{  
"grok": {  
"field": "message",  
"patterns": [  
"%{HAPROXYHTTP}",  
"%{HAPROXYTCP}",  
"%{SYSLOGTIMESTAMP:syslog\_timestamp} %{IPORHOST:syslog\_server} %{SYSLOGPROG}: %{IP:client\_ip}:%{INT:client\_port} \[%{HAPROXYDATE:accept\_date}\] %{NOTSPACE:backend\_name}/%{NOTSPACE:server\_name} %{GREEDYDATA:error}"  
]  
}  
},  
{  
"geoip": {  
"field": "client\_ip",  
"target\_field": "geoip"  
}  
}  
]  
}

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 18, 2018, 10:10pm UTC](https://discuss.elastic.co/t/make-create-fields-index-out-of-range-error/116131/2 "2018-01-18T22:10:06Z")

</div>

@Zachary_Buckholz Great to see you use our new generator which was just merged a few days ago. For the error I think @kvch is best to answer.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [January 19, 2018, 8:41am UTC](https://discuss.elastic.co/t/make-create-fields-index-out-of-range-error/116131/3 "2018-01-19T08:41:11Z")

</div>

I am happy to see that you are using the new generator!  
It seems to me that the script is not prepared for having patterns without fields names e.g `%{HAPROXYHTTP}`. I am opening a PR to fix it.  
Thanks for the report.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [January 19, 2018, 9:02am UTC](https://discuss.elastic.co/t/make-create-fields-index-out-of-range-error/116131/4 "2018-01-19T09:02:37Z")

</div>

I also noticed that you escape using `\`. You must use `\\`, otherwise it cannot be escaped properly in Filebeat.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [January 19, 2018, 9:28am UTC](https://discuss.elastic.co/t/make-create-fields-index-out-of-range-error/116131/5 "2018-01-19T09:28:54Z")

</div>

I opened the PR: [https://github.com/elastic/beats/pull/6110](https://github.com/elastic/beats/pull/6110)  
Please, let me know if you are still facing issues with the generator.

---

<div class="post-metadata">

**Author:** ![Zachary\_Buckholz](https://avatars.discourse-cdn.com/v4/letter/z/f1d935/32.png) [@Zachary\_Buckholz](https://discuss.elastic.co/u/Zachary_Buckholz)\
**Post date:** [January 19, 2018, 2:46pm UTC](https://discuss.elastic.co/t/make-create-fields-index-out-of-range-error/116131/6 "2018-01-19T14:46:32Z")

</div>

Thanks guys I will give it a try this afternoon.

---

<div class="post-metadata">

**Author:** ![Zachary\_Buckholz](https://avatars.discourse-cdn.com/v4/letter/z/f1d935/32.png) [@Zachary\_Buckholz](https://discuss.elastic.co/u/Zachary_Buckholz)\
**Post date:** [January 19, 2018, 3:53pm UTC](https://discuss.elastic.co/t/make-create-fields-index-out-of-range-error/116131/7 "2018-01-19T15:53:01Z")

</div>

It did not error out, but it didn't give me a fields.yml I was expecting to see. It's a starting point I can further edit manually. Maybe my understanding of the feature is incorrect, but I was expecting to see all the HAPROXYHTTP, HAPROXYTCP, SYSLOG timestamp, and most importantly the geo\_point.

I got the following

module/haproxy/haproxy\_log/\_meta/fields.yml

- name: syslog\_timestamp  
description: Please add description  
example: Please add example  
type: text
- name: syslog\_server  
description: Please add description  
example: Please add example  
type: keyword
- name: client\_ip  
description: Please add description  
example: Please add example
- name: client\_port  
description: Please add description  
example: Please add example
- name: accept\_date  
description: Please add description  
example: Please add example
- name: backend\_name  
description: Please add description  
example: Please add example
- name: server\_name  
description: Please add description  
example: Please add example
- name: error  
description: Please add description  
example: Please add example  
type: text

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [January 24, 2018, 3:12pm UTC](https://discuss.elastic.co/t/make-create-fields-index-out-of-range-error/116131/8 "2018-01-24T15:12:10Z")

</div>

What would be the expected output?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2018, 3:12pm UTC](https://discuss.elastic.co/t/make-create-fields-index-out-of-range-error/116131/9 "2018-02-21T15:12:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
