# Metricbeat fails to parse field

**URL:** <https://discuss.elastic.co/t/metricbeat-fails-to-parse-field/308446>\
**Category:** Beats\
**Tags:** elastic-stack-monitoring, metricbeat\
**Created:** [June 29, 2022, 9:30am UTC](https://discuss.elastic.co/t/metricbeat-fails-to-parse-field/308446 "2022-06-29T09:30:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cracanut](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cracanut/32/107727_2.png) [@cracanut](https://discuss.elastic.co/u/cracanut)\
**Post date:** [June 29, 2022, 9:30am UTC](https://discuss.elastic.co/t/metricbeat-fails-to-parse-field/308446/1 "2022-06-29T09:30:15Z")

</div>

I'm trying to setup monitoring of our ES cluster via MetricBeat.  
The cluster consists of:

- 1 master & 1 data node (more to be added later)
- running on AWS Ubuntu ARM instances

I'm getting the following error in MetricBeat's logging (abbreviated):

`failed to parse field [elasticsearch.node.stats.os.cgroup.memory.limit.bytes] of type [long] in document with id '5NvEroEBXQqSgbZj8wR7'. Preview of field's value: 'max'\",\"caused_by\":{\"type\":\"illegal_argument_exception\",\"reason\":\"For input string: \\\"max\\\"\"}}, dropping event!","service.name":"metricbeat","ecs.version":"1.6.0"}`

Any ideas what's causing this?

---

<div class="post-metadata">

**Author:** ![matschaffer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matschaffer/32/95396_2.png) [@matschaffer](https://discuss.elastic.co/u/matschaffer)\
**Post date:** [July 4, 2022, 7:25am UTC](https://discuss.elastic.co/t/metricbeat-fails-to-parse-field/308446/2 "2022-07-04T07:25:21Z")

</div>

Hi cracanut!

You're running into [[Stack Monitoring] Mapping for elasticsearch.node.stats.os.cgroup.memory.limit.bytes is incorrect · Issue #31765 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/31765) - we don't have a workaround currently but if you subscribe to that issue you'll get updates once we start working on it.

---

<div class="post-metadata">

**Author:** ![cracanut](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cracanut/32/107727_2.png) [@cracanut](https://discuss.elastic.co/u/cracanut)\
**Post date:** [July 4, 2022, 7:41am UTC](https://discuss.elastic.co/t/metricbeat-fails-to-parse-field/308446/3 "2022-07-04T07:41:11Z")

</div>

Hi Matt,

Thanks a lot. I've subscribed to the GitHub issue, hopefully there's a fix soon.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 1, 2022, 9:41am UTC](https://discuss.elastic.co/t/metricbeat-fails-to-parse-field/308446/4 "2022-08-01T09:41:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
