# NMAP Codec Plugin - Logstash Configuration and Index Template Issues

**URL:** <https://discuss.elastic.co/t/nmap-codec-plugin-logstash-configuration-and-index-template-issues/376547>\
**Category:** Logstash\
**Created:** [March 29, 2025, 2:07am UTC](https://discuss.elastic.co/t/nmap-codec-plugin-logstash-configuration-and-index-template-issues/376547 "2025-03-29T02:07:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ljonesa](https://avatars.discourse-cdn.com/v4/letter/l/f1d935/32.png) [@ljonesa](https://discuss.elastic.co/u/ljonesa)\
**Post date:** [March 29, 2025, 2:07am UTC](https://discuss.elastic.co/t/nmap-codec-plugin-logstash-configuration-and-index-template-issues/376547/1 "2025-03-29T02:07:10Z")

</div>

Hello, I have been trying to take an Nmap scan's XML output into Elasticsearch and I have come across a few issues.

Below is my Logstash configuration file.

```auto
input {
 file {
   mode => "tail"
   path => "/usr/share/logstash/ingest_data/*"
 }
 http {
    host => "10.0.30.135"
    port => 8000
    codec => nmap
    ssl => false
 }
}

filter {
}

output {
 elasticsearch {
   index => "logstash-%{+YYYY.MM.dd}"
   hosts=> "${ELASTIC_HOSTS}"
   
   user=> "${ELASTIC_USER}"
   password=> "${ELASTIC_PASSWORD}"
   cacert=> "certs/ca/ca.crt"
 }
}

```

I know that I need a template to properly map the files, and I made an API request to create an index template and a component template:

Component:

```auto
PUT _component_template/nmap_host
{
  "template": {
    "mappings": {
      "properties" : {
          "addresses" : {
            "properties" : {
              "address" : {
                "type": "text"
              },
              "type" : {
                "type" : "text"
              }
            }
          },
          "ip" : {
            "type" : "text"
            }
          }
        }
      }
    }
  }
}

```

Index:

```auto
PUT _index_template/nmap_index
{
    "index_patterns": ["nmap-*"],
    "template" : {
        "settings" : {
            "number_of_shards" : 1
        },
        "mappings": {
            "_source": {
                "enabled": true
            }
        },
        "properties": {
            "host_name" : {
                "type": "keyword"
            },
            "created_at" : {
                "type" : "date"
            }
        }
    },
    "aliases" : {
        "testdata" : { }
    },
"priority": 500,
"composed_of": ["nmap_host"],
"version": 0
}

```

The component PUT request goes through, but my Index request returns the following:

```auto
{
  "error": {
    "root_cause": [
      {
        "type": "x_content_parse_exception",
        "reason": "[1:226] [template] unknown field [properties]"
      }
    ],
    "type": "x_content_parse_exception",
    "reason": "[1:240] [index_template] failed to parse field [template]",
    "caused_by": {
      "type": "x_content_parse_exception",
      "reason": "[1:226] [template] unknown field [properties]"
    }
  },
  "status": 400
}

```

Thanks in advance for any assistance!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 29, 2025, 5:11am UTC](https://discuss.elastic.co/t/nmap-codec-plugin-logstash-configuration-and-index-template-issues/376547/2 "2025-03-29T05:11:14Z")

</div>

Your template is wrong, the `template` object can have 3 nested objects, `settings`, `mappings` and `aliases`, in your configuration it has a object named `properties` that should be inside `mappings`, you are closing the `mappings` before.

It needs to be something like this:

```auto
{
    "index_patterns": ["nmap-*"],
    "template" : {
        "settings" : {
            "number_of_shards" : 1
        },
        "mappings": {
            "_source": {
                "enabled": true
            },
            "properties": {
                "host_name" : { "type": "keyword" },
                "created_at" : { "type" : "date" }
            }
        },
        "aliases" : {
            "testdata" : { }
        }
    },
    "priority": 500,
    "composed_of": ["nmap_host"],
    "version": 0
}

```

---

<div class="post-metadata">

**Author:** ![ljonesa](https://avatars.discourse-cdn.com/v4/letter/l/f1d935/32.png) [@ljonesa](https://discuss.elastic.co/u/ljonesa)\
**Post date:** [March 29, 2025, 8:23pm UTC](https://discuss.elastic.co/t/nmap-codec-plugin-logstash-configuration-and-index-template-issues/376547/3 "2025-03-29T20:23:16Z")

</div>

Thank you for the help! this ended up working!
