# Netflow.flow\_id data type incorrectly set to long instead of unsigned-long

**URL:** <https://discuss.elastic.co/t/netflow-flow-id-data-type-incorrectly-set-to-long-instead-of-unsigned-long/377377>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 22, 2025, 2:17pm UTC](https://discuss.elastic.co/t/netflow-flow-id-data-type-incorrectly-set-to-long-instead-of-unsigned-long/377377 "2025-04-22T14:17:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![vjineo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vjineo/32/142764_2.png) [@vjineo](https://discuss.elastic.co/u/vjineo)\
**Post date:** [April 22, 2025, 2:17pm UTC](https://discuss.elastic.co/t/netflow-flow-id-data-type-incorrectly-set-to-long-instead-of-unsigned-long/377377/1 "2025-04-22T14:17:59Z")

</div>

In /etc/filebeats/fields.yaml file, netflow.flow\_id is set to type long.

```auto
        - name: flow_id
          type: long

```

As per NetFlow standard, it should be unsigned long.

Because of this, events are getting dropped with error:

```auto
(status=400): {\"type\":\"document_parsing_exception\",\"reason\":\"[1:1477] failed to parse field [netflow.flow_id] of type [long] in document with id 'Lba4XZYB_Zr7jpsbS6pn'. 
Preview of field's value: '11133470846251699209'\",\"caused_by\":{\"type\":\"x_content_parse_exception\",\"reason\":\"[1:1497] Numeric value (11133470846251699209) out of range of long (-9223372036854775808 - 9223372036854775807)\\n at [Source

```

Is it possible to fix it? Do we have any workaround for this?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 22, 2025, 2:42pm UTC](https://discuss.elastic.co/t/netflow-flow-id-data-type-incorrectly-set-to-long-instead-of-unsigned-long/377377/2 "2025-04-22T14:42:01Z")

</div>

Hi @vjineo Welcome to the community.

What version are you on?

Looks like a duplicate of this... Please be patient new users it take a few minutes for topics to show up. I will close that one.

> [@Filebeats NetFlow: Events dropped due to out of range of long value](https://discuss.elastic.co/t/filebeats-netflow-events-dropped-due-to-out-of-range-of-long-value/377375):
>
> Most of the events are dropped with below error: {\"type\":\"document\_parsing\_exception\",\"reason\":\"[1:1475] failed to parse field [netflow.flow\_id] of type [long] in document with id 'M7a4XZYB\_Zr7jpsbS6pn'. Preview of field's value: '11133470849011551241'\",\"caused\_by\":{\"type\":\"x\_content\_parse\_exception\",\"reason\":\"[1:1495] Numeric value (11133470849011551241) out of range of long (-9223372036854775808 - 9223372036854775807)\\n As per standard, netflow.flow\_id is unsigned64. But Fi…

Ohhh I think you will need to set that to keyword, I see on the other modules it is set to `keyword`

```auto
        - name: flow_id
          type: keyword

```

It might be worth opening an Issue....

> **[beats/x-pack/filebeat/input/netflow at 66e172ca24ec82f07bcd89da7436479a6e6c20f1...](https://github.com/elastic/beats/tree/66e172ca24ec82f07bcd89da7436479a6e6c20f1/x-pack/filebeat/input/netflow)**
>
> :tropical\_fish: Beats - Lightweight shippers for Elasticsearch &amp; Logstash - elastic/beats

---

<div class="post-metadata">

**Author:** ![vjineo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vjineo/32/142764_2.png) [@vjineo](https://discuss.elastic.co/u/vjineo)\
**Post date:** [April 22, 2025, 4:53pm UTC](https://discuss.elastic.co/t/netflow-flow-id-data-type-incorrectly-set-to-long-instead-of-unsigned-long/377377/3 "2025-04-22T16:53:30Z")

</div>

Thanks @stephenb for the quick reply. I'm on 8.18 version

```auto
ubuntu@ubuntu-ELK:~$ filebeat version
filebeat version 8.18.0 (amd64), libbeat 8.18.0 [b907b0fa1e1b7400d4e222d6b6ca9d1b77c08d97 built 2025-04-09 17:09:00 +0000 UTC]
ubuntu@ubuntu-ELK:~$

```

I'll raise an issue in the Github page that you shared, thanks for confirming.

In the meantime, do we have any workaround for this? I was going through this page:

> **[Load the Elasticsearch index template | Elastic Documentation](https://www.elastic.co/docs/reference/beats/filebeat/filebeat-template)**
>
> Elasticsearch uses index templates to define: Settings that control the behavior of your data stream and backing indices. The settings include the lifecycle...

Thought of taking backup like this:

```auto
(venv) ubuntu@ubuntu-ELK:~$ sudo filebeat export template > filebeat.template.json
(venv) ubuntu@ubuntu-ELK:~$

```

Modify the type to keyword in the template.json and figure out a way to force filebeat to use this.

P.S: Apologies for the double post. I thought I posted in wrong category and then tried to fix it.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 22, 2025, 4:58pm UTC](https://discuss.elastic.co/t/netflow-flow-id-data-type-incorrectly-set-to-long-instead-of-unsigned-long/377377/4 "2025-04-22T16:58:25Z")

</div>

The how to load is just a few lines lower

> **[Load the Elasticsearch index template | Elastic Documentation](https://www.elastic.co/docs/reference/beats/filebeat/filebeat-template#load-template-manually-alternate)**
>
> Elasticsearch uses index templates to define: Settings that control the behavior of your data stream and backing indices. The settings include the lifecycle...

```auto
filebeat export template > filebeat.template.json
<fix>
curl -XPUT -H 'Content-Type: application/json' http://localhost:9200/_index_template/filebeat-8.18.0 -d@filebeat.template.json

```

Try that... you can also just go into Kibana and manually fix the template...

---

<div class="post-metadata">

**Author:** ![vjineo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vjineo/32/142764_2.png) [@vjineo](https://discuss.elastic.co/u/vjineo)\
**Post date:** [April 22, 2025, 6:24pm UTC](https://discuss.elastic.co/t/netflow-flow-id-data-type-incorrectly-set-to-long-instead-of-unsigned-long/377377/5 "2025-04-22T18:24:06Z")

</div>

That worked, thanks a lot @stephenb.

Initially I faced below issue and I couldn't figure out how to solve that:

```auto
ubuntu@ubuntu-ELK:~$ curl -XPUT http://localhost:9200/_data_stream/filebeat-8.18.0
{"error":{"root_cause":[{"type":"resource_already_exists_exception","reason":"data_stream [filebeat-8.18.0] already exists"}],"type":"resource_already_exists_exception","reason":"data_stream [filebeat-8.18.0] already exists"},"status":400}ubuntu@ubuntu-ELK:~$

```

Ended up bringing up fresh instance and it worked. Used below sequence (filebeat started last):

```auto
ubuntu@ubuntu-ELK:~$ sudo sudo filebeat export template > filebeat.template.json
ubuntu@ubuntu-ELK:~$ vim filebeat.template.json
ubuntu@ubuntu-ELK:~$ curl -XPUT -H 'Content-Type: application/json' http://localhost:9200/_index_template/filebeat-8.18.0 -d@filebeat.template.json
{"acknowledged":true}ubuntu@ubuntu-ELK:~$
ubuntu@ubuntu-ELK:~$ sudo filebeat modules enable netflow
Enabled netflow
ubuntu@ubuntu-ELK:~$ sudo sed -i 's/preset: balanced/preset: throughput/g' /etc/filebeat/filebeat.yml
ubuntu@ubuntu-ELK:~$ sudo sed -i 's/enabled: false/enabled: true/g' /etc/filebeat/modules.d/netflow.yml
ubuntu@ubuntu-ELK:~$ sudo sed -i 's/netflow_host: localhost/netflow_host: 0.0.0.0/g' /etc/filebeat/modules.d/netflow.yml
ubuntu@ubuntu-ELK:~$ sudo sed -i 's/netflow_port: 2055/&\n max_message_size: 40KiB/' /etc/filebeat/modules.d/netflow.yml
ubuntu@ubuntu-ELK:~$
ubuntu@ubuntu-ELK:~$ sudo systemctl start filebeat
ubuntu@ubuntu-ELK:~$
ubuntu@ubuntu-ELK:~$ curl -XPUT http://localhost:9200/_data_stream/filebeat-8.18.0
{"acknowledged":true}ubuntu@ubuntu-ELK:~$
ubuntu@ubuntu-ELK:~$

```

---

<div class="post-metadata">

**Author:** ![vjineo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vjineo/32/142764_2.png) [@vjineo](https://discuss.elastic.co/u/vjineo)\
**Post date:** [April 23, 2025, 6:18am UTC](https://discuss.elastic.co/t/netflow-flow-id-data-type-incorrectly-set-to-long-instead-of-unsigned-long/377377/6 "2025-04-23T06:18:18Z")

</div>

I've ILM policy configured and when rollover happened, it changed back to "long".

Verified using below command:

```auto
GET filebeat-*/_mapping/field/netflow.flow_id

```

```auto
 {
  ".ds-filebeat-8.18.0-2025.04.23-000004": {
    "mappings": {
      "netflow.flow_id": {
        "full_name": "netflow.flow_id",
        "mapping": {
          "flow_id": {
            "type": "long"
          }
        }
      }
    }
  }
}

```

Could someone guide me in handling this?

---

<div class="post-metadata">

**Author:** ![vjineo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vjineo/32/142764_2.png) [@vjineo](https://discuss.elastic.co/u/vjineo)\
**Post date:** [April 23, 2025, 7:20am UTC](https://discuss.elastic.co/t/netflow-flow-id-data-type-incorrectly-set-to-long-instead-of-unsigned-long/377377/7 "2025-04-23T07:20:22Z")

</div>

Made the following changes and it seems to work after rollover now:

-Edit '/etc/filebeat/filebeat.yml' and add setting 'setup.template.enabled: false'  
-Executed this

```auto
curl -XPUT -H 'Content-Type: application/json' http://localhost:9200/_index_template/filebeat-8.18.0 -d@filebeat.template.json

```

And this:

```auto
curl -X DELETE "http://localhost:9200/_data_stream/filebeat-8.18.0"

```

And finally this:

```auto
curl -XPUT http://localhost:9200/_data_stream/filebeat-8.18.0

```

Now it is good:

```auto
{
  ".ds-filebeat-8.18.0-2025.04.23-000002": {
    "mappings": {
      "netflow.flow_id": {
        "full_name": "netflow.flow_id",
        "mapping": {
          "flow_id": {
            "type": "keyword"
          }
        }
      }
    }
  },
  ".ds-filebeat-8.18.0-2025.04.23-000001": {
    "mappings": {
      "netflow.flow_id": {
        "full_name": "netflow.flow_id",
        "mapping": {
          "flow_id": {
            "type": "keyword"
          }
        }
      }
    }
  }
}

```
