# Metricbeat default index template causes "No matching token for number\_type \[BIG\_INTEGER\]"

**URL:** <https://discuss.elastic.co/t/metricbeat-default-index-template-causes-no-matching-token-for-number-type-big-integer/148370>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [September 12, 2018, 7:07pm UTC](https://discuss.elastic.co/t/metricbeat-default-index-template-causes-no-matching-token-for-number-type-big-integer/148370 "2018-09-12T19:07:47Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![wes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wes/32/71098_2.png) [@wes](https://discuss.elastic.co/u/wes)\
**Post date:** [September 12, 2018, 7:07pm UTC](https://discuss.elastic.co/t/metricbeat-default-index-template-causes-no-matching-token-for-number-type-big-integer/148370/1 "2018-09-12T19:07:47Z")

</div>

Hi there,  
I've posted about this issue in the past and never received any suggestions. I finally got around to looking at it again and was able to figure out a little more this time, so I'm hoping someone will be able to help me understand what's causing the issue.

It seems to only occur with the system module and the process metricset. I'm using the default module config and the default template. I do have metricbeat shipping to logstash and then to elasticsearch, but logstash is doing no filtering. It is when logstash tries to send the doc to elasticsearch that I get the error:

```
    2018-09-12T18:39:30,230][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. 
   { :status=>400, :action=>["index", 
     {:_id=>"<host>-system-process-18.25.53", :_index=>"<host>-metricbeat-2018.09.12", :_type=>"doc", :_routing=>nil},
     #<LogStash::Event:0x62061ee>], :response=>{"index"=>
         {"_index"=>"<host>-metricbeat-2018.09.12", "_type"=>"doc", "_id"=>"<host>-system-process-18.25.53", "status"=>400, "error"=>
              {"type"=>"mapper_parsing_exception", "reason"=>"failed to parse", "caused_by"=>
                       {"type"=>"illegal_state_exception", "reason"=>"No matching token for number_type [BIG_INTEGER]"}
              }
         }
      }
  }

```

I'll post a sample doc below.

---

<div class="post-metadata">

**Author:** ![wes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wes/32/71098_2.png) [@wes](https://discuss.elastic.co/u/wes)\
**Post date:** [September 12, 2018, 7:13pm UTC](https://discuss.elastic.co/t/metricbeat-default-index-template-causes-no-matching-token-for-number-type-big-integer/148370/2 "2018-09-12T19:13:13Z")

</div>

"{  
"process": {  
"cwd": "/",  
"memory": {  
"size": 1452826624,  
"share": 10043392,  
"rss": {  
"pct": 0.0435,  
"bytes": 171515904  
}  
},  
"cmdline": "python ",  
"pgid": 28183,  
"name": "python",  
"cpu": {  
"start\_time": "2018-09-06T19:49:01.000Z",  
"total": {  
"pct": 0.018,  
"value": 7302460,  
"norm": {  
"pct": 0.009  
}  
}  
},  
"pid": 28183,  
"state": "sleeping",  
"cgroup": {  
"blkio": {  
"path": "/docker/e657e814a24e3f4e0fd6a3b9d7aa472bb6ab34fe02eb1713395c12edf9c4ac76",  
"total": {  
"ios": 126,  
"bytes": 4886528  
},  
"id": "e657e814a24e3f4e0fd6a3b9d7aa472bb6ab34fe02eb1713395c12edf9c4ac76"  
},  
"path": "/docker/e657e814a24e3f4e0fd6a3b9d7aa472bb6ab34fe02eb1713395c12edf9c4ac76",  
"cpu": {  
"path": "/docker/e657e814a24e3f4e0fd6a3b9d7aa472bb6ab34fe02eb1713395c12edf9c4ac76",  
"cfs": {  
"shares": 1024,  
"period": {  
"us": 100000  
},  
"quota": {  
"us": 0  
}  
},  
"rt": {  
"runtime": {  
"us": 0  
},  
"period": {  
"us": 0  
}  
},  
"id": "e657e814a24e3f4e0fd6a3b9d7aa472bb6ab34fe02eb1713395c12edf9c4ac76",  
"stats": {  
"periods": 0,  
"throttled": {  
"ns": 0,  
"periods": 0  
}  
}  
},  
"id": "e657e814a24e3f4e0fd6a3b9d7aa472bb6ab34fe02eb1713395c12edf9c4ac76",  
"memory": {  
"path": "/docker/e657e814a24e3f4e0fd6a3b9d7aa472bb6ab34fe02eb1713395c12edf9c4ac76",  
"mem": {  
"limit": {  
"bytes": 18446744073709552000  
},  
"failures": 0,  
"usage": {  
"max": {  
"bytes": 1217224704  
},  
"bytes": 1069215744  
}  
},  
"stats": {  
"inactive\_anon": {  
"bytes": 40960  
},  
"cache": {  
"bytes": 106225664  
},  
"rss\_huge": {  
"bytes": 448790528  
},  
"mapped\_file": {  
"bytes": 0  
},  
"swap": {  
"bytes": 0  
},  
"unevictable": {  
"bytes": 0  
},  
"pages\_in": 20764330,  
"active\_anon": {  
"bytes": 963096576  
},  
"hierarchical\_memory\_limit": {  
"bytes": 18446744073709552000  
},  
"pages\_out": 23720547,  
"page\_faults": 75011826,  
"inactive\_file": {  
"bytes": 24784896  
},  
"hierarchical\_memsw\_limit": {  
"bytes": 0  
},  
"rss": {  
"bytes": 962990080  
},  
"major\_page\_faults": 79,  
"active\_file": {  
"bytes": 81293312  
}  
},  
"memsw": {  
"limit": {  
"bytes": 0  
},  
"failures": 0,  
"usage": {  
"max": {  
"bytes": 0  
},  
"bytes": 0  
}  
},  
"kmem\_tcp": {  
"limit": {  
"bytes": 18446744073709552000  
},  
"failures": 0,  
"usage": {  
"max": {  
"bytes": 0  
},  
"bytes": 0  
}  
},  
"kmem": {  
"limit": {  
"bytes": 18446744073709552000  
},  
"failures": 0,  
"usage": {  
"max": {  
"bytes": 0  
},  
"bytes": 0  
}  
},  
"id": "e657e814a24e3f4e0fd6a3b9d7aa472bb6ab34fe02eb1713395c12edf9c4ac76"  
},  
"cpuacct": {  
"percpu": {  
"1": 15846032178493,  
"2": 20804833010822  
},  
"path": "/docker/e657e814a24e3f4e0fd6a3b9d7aa472bb6ab34fe02eb1713395c12edf9c4ac76",  
"total": {  
"ns": 36650865189315  
},  
"id": "e657e814a24e3f4e0fd6a3b9d7aa472bb6ab34fe02eb1713395c12edf9c4ac76",  
"stats": {  
"user": {  
"ns": 18788480000000  
},  
"system": {  
"ns": 3041680000000  
}  
}  
}  
},  
"fd": {  
"limit": {  
"hard": 1048576,  
"soft": 524288  
},  
"open": 23  
},  
"username": "root",  
"ppid": 28138  
}  
}"

---

<div class="post-metadata">

**Author:** ![wes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wes/32/71098_2.png) [@wes](https://discuss.elastic.co/u/wes)\
**Post date:** [September 12, 2018, 7:34pm UTC](https://discuss.elastic.co/t/metricbeat-default-index-template-causes-no-matching-token-for-number-type-big-integer/148370/3 "2018-09-12T19:34:59Z")

</div>

I have been able to narrow it down further to five fields under system.process.cgroup.memory: kmem, kmem\_top, mem, memsw, and stats. All of these track values in bytes and the values are too big for the long type. So I assume I need to convert this template to use doubles, but it seems like this should not have been so difficult to discover, and IMO, perhaps the default template should just use doubles for bytes.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 17, 2018, 3:44pm UTC](https://discuss.elastic.co/t/metricbeat-default-index-template-causes-no-matching-token-for-number-type-big-integer/148370/4 "2018-09-17T15:44:28Z")

</div>

Sounds like a similar problem as [https://github.com/elastic/beats/issues/5854#issuecomment-359185591](https://github.com/elastic/beats/issues/5854#issuecomment-359185591).

---

<div class="post-metadata">

**Author:** ![wes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wes/32/71098_2.png) [@wes](https://discuss.elastic.co/u/wes)\
**Post date:** [September 17, 2018, 4:18pm UTC](https://discuss.elastic.co/t/metricbeat-default-index-template-causes-no-matching-token-for-number-type-big-integer/148370/5 "2018-09-17T16:18:26Z")

</div>

It does seem very similar, although their error messages are a little more explicit.

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [September 17, 2018, 4:44pm UTC](https://discuss.elastic.co/t/metricbeat-default-index-template-causes-no-matching-token-for-number-type-big-integer/148370/6 "2018-09-17T16:44:30Z")

</div>

Yeah I noticed the errors were different. I wonder if something changed in Elasticsearch (like Jackson is now converting the value to a BigInteger) to cause a different error for the same problem.

But I think you can work-around the issue with the same (or similar) processors to drop the invalid values on the Metricbeat side. Long term I think this this one value `18446744073709552000` which means "no limit" needs to be handled by Metricbeat.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2018, 6:44pm UTC](https://discuss.elastic.co/t/metricbeat-default-index-template-causes-no-matching-token-for-number-type-big-integer/148370/7 "2018-10-15T18:44:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
