# Nmap plugin/module? still working

**URL:** <https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479>\
**Category:** Logstash\
**Created:** [April 3, 2020, 10:00pm UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479 "2020-04-03T22:00:43Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [April 3, 2020, 10:00pm UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479/1 "2020-04-03T22:00:44Z")

</div>

anyone had any luck getting the nmap scan xml codec/plugin to work with v7?

i've got it reading the data in with the plugin, but the template wont import.. and the data is pretty rough around the edges.

any suggestions would be appreciated

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [April 4, 2020, 12:43am UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479/2 "2020-04-04T00:43:41Z")

</div>

Hi,

Can you be more precise about the error ? How do you import the template ?

by the way i didnt knew about this plugin are we talking about this [https://github.com/logstash-plugins/logstash-codec-nmap/tree/v0.0.21](https://github.com/logstash-plugins/logstash-codec-nmap/tree/v0.0.21) ?

---

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [April 4, 2020, 2:42am UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479/3 "2020-04-04T02:42:24Z")

</div>

i found it here: [https://www.elastic.co/guide/en/logstash/current/plugins-codecs-nmap.html](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-nmap.html) which links to : [https://github.com/logstash-plugins/logstash-codec-nmap](https://github.com/logstash-plugins/logstash-codec-nmap)

i'm using the template straight off the github with this command:

` curl -XPUT -H 'Content-Type: application/json' http://192.168.1.60:9200/_template/nmap_template -d@elasticsearch_nmap_template.json`

result/error i get:  
`{"error":{"root_cause":[{"type":"mapper_parsing_exception","reason":"Root mapping definition has unsupported parameters: [nmap_port : {properties={addresses={properties={addr={index=not_analyzed, type=string}, type={index=not_analyzed, type=string}}}, address={index=not_analyzed, type=string}, geoip={properties={timezone={index=not_analyzed, type=string}, area_code={index=not_analyzed, type=string}, ip={type=ip}, latitude={type=double}, continent_code={index=not_analyzed, type=string}, city_name={type=string}, country_code2={index=not_analyzed, type=string}, country_name={index=not_analyzed, type=string}, dma_code={type=integer}, country_code3={index=not_analyzed, type=string}, location={type=geo_point}, ...LOTS LOTS MORE... run_stats={properties={elapsed={type=double}, summary={index=not_analyzed, type=string}, end_time={index=not_analyzed, type=string}, exit_status={index=not_analyzed, type=string}}}, type={index=not_analyzed, type=string}, version={index=not_analyzed, type=string}, tags={index=not_analyzed, type=string}}}]"}},"status":400}`

---

<div class="post-metadata">

**Author:** ![ken-crozier](https://avatars.discourse-cdn.com/v4/letter/k/87869e/32.png) [@ken-crozier](https://discuss.elastic.co/u/ken-crozier)\
**Post date:** [April 5, 2020, 6:13pm UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479/4 "2020-04-05T18:13:01Z")

</div>

I have the same issue ... running logstash 7.6.2

```auto
{"error":{"root_cause":[{"type":"mapper_parsing_exception","reason":"Root mapping definition has unsupported parameters: [nmap_port : {properties={addresses={properties={addr={index=not_analyzed, type=string}, type={index=not_analyzed, type=string}}}, address={index=not_analyzed, type=string}, geoip={properties={timezone={index=not_analyzed, type=string}, area_code={index=not_analyzed, type=string}, ip={type=ip}, latitude={type=double}, continent_code={index=not_analyzed, type=string}, city_name={type=string}, country_code2={index=not_analyzed, type=string}, country_name={index=not_analyzed, type=string}, dma_code={type=integer}, country_code3={index=not_analyzed, type=string}, location={type=geo_point}, region_name={index=not_analyzed, type=string}, real_region_name={index=not_analyzed, type=string},

```

---

<div class="post-metadata">

**Author:** ![ken-crozier](https://avatars.discourse-cdn.com/v4/letter/k/87869e/32.png) [@ken-crozier](https://discuss.elastic.co/u/ken-crozier)\
**Post date:** [April 5, 2020, 7:02pm UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479/5 "2020-04-05T19:02:08Z")

</div>

there's also this guide ....

> **[Using Nmap + Logstash to Gain Insight Into Your Network](https://www.elastic.co/blog/using-nmap-logstash-to-gain-insight-into-your-network)**
>
> Using the new Logstash Nmap codec we show how you can gain new insight into the internals of your network.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [April 6, 2020, 3:28pm UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479/6 "2020-04-06T15:28:48Z")

</div>

Hi,

I took a look into the mapping and it looks like it needs to be updated

I might dive into it but you could try to re-create it with new standards.

---

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [April 6, 2020, 8:40pm UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479/7 "2020-04-06T20:40:12Z")

</div>

i found a little linux termal program that converts the xml to json.. so i just wrote a little script that runs through and converts all my xml scans to json. then i have a logstash pipeline that takes those into ES. its not an ideal solution but it does work.

> **[picatz/nmap2json](https://github.com/picatz/nmap2json)**
>
> 🗺 Convert nmap XML output to beautiful JSON. Contribute to picatz/nmap2json development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [April 7, 2020, 8:17am UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479/8 "2020-04-07T08:17:58Z")

</div>

Hi,

Glad you made it works ! I had take a look at this plugin a while ago for similar purpose and i was considering using this too.

---

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [April 7, 2020, 3:07pm UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479/9 "2020-04-07T15:07:26Z")

</div>

the nmap2json works well. it converts the xml to json, then you just run it through logstash for more enrichment. i'm integrating the shodan API now. lookingglass will be next. i wish there was a better way, but its good enough.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [April 8, 2020, 2:38pm UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479/10 "2020-04-08T14:38:38Z")

</div>

Dont hesitate to use prune plugin while dealign with json sometimes alot of useless fields can be removed easily 😉

[https://www.elastic.co/guide/en/logstash/current/plugins-filters-prune.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-prune.html)

---

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [April 8, 2020, 3:22pm UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479/11 "2020-04-08T15:22:21Z")

</div>

thank you, i was not aware of this filter. i'll check it out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2020, 3:22pm UTC](https://discuss.elastic.co/t/nmap-plugin-module-still-working/226479/12 "2020-05-06T15:22:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
