# MapperParsingException with logstash

**URL:** <https://discuss.elastic.co/t/mapperparsingexception-with-logstash/13545>\
**Category:** Elasticsearch\
**Created:** [September 10, 2013, 11:29pm UTC](https://discuss.elastic.co/t/mapperparsingexception-with-logstash/13545 "2013-09-10T23:29:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rob\_Bos](https://avatars.discourse-cdn.com/v4/letter/r/a6a055/32.png) [@Rob\_Bos](https://discuss.elastic.co/u/Rob_Bos)\
**Post date:** [September 10, 2013, 11:29pm UTC](https://discuss.elastic.co/t/mapperparsingexception-with-logstash/13545/1 "2013-09-10T23:29:38Z")

</div>

I'm sending Windows logs, using nxlog, to a Logstash server with  
Elasticsearch, and a field is failing to autodetect correctly, if I'm  
reading Google searches correctly. ES is generating errors like "Failed to  
parse [@fields.ErrorCode]" [1]. I'm struggling writing a template [2] to  
set that field to 'string', but I don't even know for sure if ES is reading  
the file, or if I've written it right. I would like a sanity check and  
maybe some advice.

I've confirmed through ps that ES is getting path.conf set to  
/etc/elasticsearch, and I've placed the template file as  
templates/template\_1.json. That ES did not error out when I had problems  
with the JSON syntax suggests that it's either failing silently or not  
reading the file at all, so I don't know what's up with that.

[1]: 2013-09-10 16:16:08,065][DEBUG][action.index] [Stacy X] [  
logstash-2013.09.10][1], node[bzY72RjbSFCTMPMPBvHWtQ], [P], s[STARTED]:  
Failed to execute [index {[logstash-2013.09.10][eventlog][utbYay9iRcybQ-  
V5EIflRQ], source[{"@source":"tcp://142.58.129.166:52691/","@tags":[],  
"@fields":{"Keywords":-9223090561878065151,"ProviderGuid":  
"{126CDB97-D346-4894-8A34-658DA5EEA1B6}","Version":0,"Task":0,"OpcodeValue":  
2,"ThreadID":8416,"Domain":"NT AUTHORITY","AccountName":"SYSTEM","UserID":  
"SYSTEM","AccountType":"User","Opcode":"Stop","SnapshotPath":  
"\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy5","ErrorCode":"0x0",  
"TotalDirectories":"49311","TotalFiles":"248624","FilesScoped":"102079",  
"FilesResident":"26182","FilesCachedFirstPass":"21253",  
"FilesMissedSecondPass":"18946","eventlog\_severity":"info",  
"eventlog\_severity\_code":2,"eventlog\_channel":"Application",  
"eventlog\_program":"Microsoft-Windows-System-Restore","nxlog\_input":  
"eventlog","eventlog\_id":8301,"eventlog\_record\_number":24878,"eventlog\_pid":  
5264},"@timestamp":"2013-09-10T22:02:28.000Z","@source\_host":  
"lib4013-2.lib.sfu.ca","@source\_path":"/","@message":"Scoping completed for  
shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy5.","@type":  
"eventlog"}]}]  
org.elasticsearch.index.mapper.MapperParsingException: Failed to parse [  
@fields.ErrorCode]  
at org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(  
AbstractFieldMapper.java:320)  
at org.elasticsearch.index.mapper.object.ObjectMapper.serializeValue  
(ObjectMapper.java:587)  
at org.elasticsearch.index.mapper.object.ObjectMapper.parse(  
ObjectMapper.java:459)  
at org.elasticsearch.index.mapper.object.ObjectMapper.  
serializeObject(ObjectMapper.java:507)  
at org.elasticsearch.index.mapper.object.ObjectMapper.parse(  
ObjectMapper.java:449)  
at org.elasticsearch.index.mapper.DocumentMapper.parse(  
DocumentMapper.java:486)  
at org.elasticsearch.index.mapper.DocumentMapper.parse(  
DocumentMapper.java:430)  
at org.elasticsearch.index.shard.service.InternalIndexShard.  
prepareCreate(InternalIndexShard.java:297)  
at org.elasticsearch.action.index.TransportIndexAction.  
shardOperationOnPrimary(TransportIndexAction.java:211)  
at org.elasticsearch.action.support.replication.  
TransportShardReplicationOperationAction$AsyncShardOperationAction.  
performOnPrimary(TransportShardReplicationOperationAction.java:533)  
at org.elasticsearch.action.support.replication.  
TransportShardReplicationOperationAction$AsyncShardOperationAction$1.run(  
TransportShardReplicationOperationAction.java:431)  
at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)  
at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source  
)  
at java.lang.Thread.run(Unknown Source)  
Caused by: java.lang.NumberFormatException: For input string: "0x0"  
at java.lang.NumberFormatException.forInputString(Unknown Source)  
at java.lang.Long.parseLong(Unknown Source)  
at java.lang.Long.parseLong(Unknown Source)  
at org.elasticsearch.common.xcontent.support.AbstractXContentParser.  
longValue(AbstractXContentParser.java:72)  
at org.elasticsearch.index.mapper.core.LongFieldMapper.  
innerParseCreateField(LongFieldMapper.java:281)  
at org.elasticsearch.index.mapper.core.NumberFieldMapper.  
parseCreateField(NumberFieldMapper.java:182)  
at org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(  
AbstractFieldMapper.java:307)  
... 13 more

[2] [http://pastebin.com/jAW6VBUK](http://pastebin.com/jAW6VBUK)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![mvg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mvg/32/98890_2.png) [@mvg](https://discuss.elastic.co/u/mvg)\
**Post date:** [September 11, 2013, 8:20am UTC](https://discuss.elastic.co/t/mapperparsingexception-with-logstash/13545/2 "2013-09-11T08:20:32Z")

</div>

Did you add or change the index template after you create the index? Index  
templates are taken into account when a new index is being created.  
If you haven't done so create a new index and start indexing into that, the  
index template should add `ErrorCode` as field. Optionally migrate your  
data to this new index.

Also I recommend using the put & delete index template api over using  
static files, using the apis you're more flexible when it comes to changing  
templates.

On 11 September 2013 01:29, Rob Bos [robertbos@gmail.com](mailto:robertbos@gmail.com) wrote:

> I'm sending Windows logs, using nxlog, to a Logstash server with  
> Elasticsearch, and a field is failing to autodetect correctly, if I'm  
> reading Google searches correctly. ES is generating errors like "Failed to  
> parse [@fields.ErrorCode]" [1]. I'm struggling writing a template [2] to  
> set that field to 'string', but I don't even know for sure if ES is reading  
> the file, or if I've written it right. I would like a sanity check and  
> maybe some advice.
> 
> I've confirmed through ps that ES is getting path.conf set to  
> /etc/elasticsearch, and I've placed the template file as  
> templates/template\_1.json. That ES did not error out when I had problems  
> with the JSON syntax suggests that it's either failing silently or not  
> reading the file at all, so I don't know what's up with that.
> 
> [1]: 2013-09-10 16:16:08,065][DEBUG][action.index] [Stacy X]  
> [logstash-2013.09.10][1], node[bzY72RjbSFCTMPMPBvHWtQ], [P], s[STARTED]:  
> Failed to execute [index {[logstash-2013.09.10][eventlog][utbYay9iRcybQ-  
> V5EIflRQ], source[{"@source":"tcp://142.58.129.166:52691/","@tags":,  
> "@fields":{"Keywords":-9223090561878065151,"ProviderGuid":  
> "{126CDB97-D346-4894-8A34-658DA5EEA1B6}","Version":0,"Task":0,  
> "OpcodeValue":2,"ThreadID":8416,"Domain":"NT AUTHORITY","AccountName":  
> "SYSTEM","UserID":"SYSTEM","AccountType":"User","Opcode":"Stop",  
> "SnapshotPath":"\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy5",  
> "ErrorCode":"0x0","TotalDirectories":"49311","TotalFiles":"248624",  
> "FilesScoped":"102079","FilesResident":"26182","FilesCachedFirstPass":  
> "21253","FilesMissedSecondPass":"18946","eventlog\_severity":"info",  
> "eventlog\_severity\_code":2,"eventlog\_channel":"Application",  
> "eventlog\_program":"Microsoft-Windows-System-Restore","nxlog\_input":  
> "eventlog","eventlog\_id":8301,"eventlog\_record\_number":24878,  
> "eventlog\_pid":5264},"@timestamp":"2013-09-10T22:02:28.000Z",  
> "@source\_host":"lib4013-2.lib.sfu.ca","@source\_path":"/","@message":"Scoping  
> completed for shadowcopy  
> \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy5.","@type":"eventlog"  
> }]}]  
> org.elasticsearch.index.mapper.MapperParsingException: Failed to parse [  
> @fields.ErrorCode]  
> at org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(  
> AbstractFieldMapper.java:320)  
> at org.elasticsearch.index.mapper.object.ObjectMapper.  
> serializeValue(ObjectMapper.java:587)  
> at org.elasticsearch.index.mapper.object.ObjectMapper.parse(  
> ObjectMapper.java:459)  
> at org.elasticsearch.index.mapper.object.ObjectMapper.  
> serializeObject(ObjectMapper.java:507)  
> at org.elasticsearch.index.mapper.object.ObjectMapper.parse(  
> ObjectMapper.java:449)  
> at org.elasticsearch.index.mapper.DocumentMapper.parse(  
> DocumentMapper.java:486)  
> at org.elasticsearch.index.mapper.DocumentMapper.parse(  
> DocumentMapper.java:430)  
> at org.elasticsearch.index.shard.service.InternalIndexShard.  
> prepareCreate(InternalIndexShard.java:297)  
> at org.elasticsearch.action.index.TransportIndexAction.  
> shardOperationOnPrimary(TransportIndexAction.java:211)  
> at org.elasticsearch.action.support.replication.  
> TransportShardReplicationOperationAction$AsyncShardOperationAction.  
> performOnPrimary(TransportShardReplicationOperationAction.java:533)  
> at org.elasticsearch.action.support.replication.  
> TransportShardReplicationOperationAction$AsyncShardOperationAction$1.run(  
> TransportShardReplicationOperationAction.java:431)  
> at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown  
> Source)  
> at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown  
> Source)  
> at java.lang.Thread.run(Unknown Source)  
> Caused by: java.lang.NumberFormatException: For input string: "0x0"  
> at java.lang.NumberFormatException.forInputString(Unknown Source)  
> at java.lang.Long.parseLong(Unknown Source)  
> at java.lang.Long.parseLong(Unknown Source)  
> at org.elasticsearch.common.xcontent.support.  
> AbstractXContentParser.longValue(AbstractXContentParser.java:72)  
> at org.elasticsearch.index.mapper.core.LongFieldMapper.  
> innerParseCreateField(LongFieldMapper.java:281)  
> at org.elasticsearch.index.mapper.core.NumberFieldMapper.  
> parseCreateField(NumberFieldMapper.java:182)  
> at org.elasticsearch.index.mapper.core.AbstractFieldMapper.parse(  
> AbstractFieldMapper.java:307)  
> ... 13 more
> 
> [2] [{ "template\_1": { "template": "\*", "mappings": { "\_default\_" - Pastebin.com](http://pastebin.com/jAW6VBUK)
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
Met vriendelijke groet,

Martijn van Groningen

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 2:17am UTC](https://discuss.elastic.co/t/mapperparsingexception-with-logstash/13545/3 "2017-07-06T02:17:08Z")

</div>


