# Packetbeat compatibable with Elastic 2.4

**URL:** https://discuss.elastic.co/t/packetbeat-compatibable-with-elastic-2-4/68595
**Category:** Beats
**Created:** [December 9, 2016, 6:54pm UTC](https://discuss.elastic.co/t/packetbeat-compatibable-with-elastic-2-4/68595 "2016-12-09T18:54:16Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)
#### Post date: [December 9, 2016, 6:54pm UTC](https://discuss.elastic.co/t/packetbeat-compatibable-with-elastic-2-4/68595/1 "2016-12-09T18:54:16Z")

</div>

Is any of the versions of packetbeat compatible with Elasticsearch 2.4

I am getting a lot of "can't contain '." in the field name" I am running the de\_dot filter but was hoping I am just running the wrong version of packetbeat (1.3)

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [December 9, 2016, 7:16pm UTC](https://discuss.elastic.co/t/packetbeat-compatibable-with-elastic-2-4/68595/2 "2016-12-09T19:16:53Z")

</div>

Both Packetbeat 1.x and Packetbeat 5.x should be compatible with ES 2.4. What protocol and what field contains a dot in the field name?

---

<div class="post-metadata">

### Author: ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)
#### Post date: [December 9, 2016, 7:29pm UTC](https://discuss.elastic.co/t/packetbeat-compatibable-with-elastic-2-4/68595/3 "2016-12-09T19:29:20Z")

</div>

can't be, in ELK 2.X they disallowed fields with dot's in the field name. (1.X and 5.X it was re-enabled)

I know when I upgraded from 1.3 last year i had to disable packetbeat cause of this. I am just now getting back to it to trouble shoot a production issue

I am working on getting the exact field. but I am logging alot so I will have to write another config to get the raw data

---

<div class="post-metadata">

### Author: ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)
#### Post date: [December 9, 2016, 7:57pm UTC](https://discuss.elastic.co/t/packetbeat-compatibable-with-elastic-2-4/68595/4 "2016-12-09T19:57:34Z")

</div>

Ok pulled this from the logs, sorry had to blank alot of the data but here are the important parts of the capture.

as you can see the cookie being parsed is creating fields with "." in them.

```auto
 "request_headers"=>{"accept"=>"text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8",
 "accept-encoding"=>"gzip", 
"accept-language"=>"ko,zh;q=0.8,en;q=0.6", 
"akamai-origin-hop"=>"",
 "cache-control"=>"no-cache, max-age=0",
 "connection"=>"Keep-Alive", 
"cookie"=>{"__cmbdomtm"=>"0", 
"__cmbtpvtm"=>"2326",
 "_sp_id.2b02"=>"XXXXXXX", 
"cart"=>"XXXXX", 
"cm.byogokaotfnub9vbngntuq4o.aotfnuuzhwwomen"=>"XXXXXX", "cm.byokzxaotfnub9vyupntuq4o.aotfnujuhfurla"=>"XXXXX",
 "cm.byoyduaotfnub9vyrrntvk3r.aotfnuu$h"=>"XXXXX", 

```

```auto
"@version"=>"1", 
"host"=>"hd1pxx24lx", 
"dst_index"=>"infra_packetbeat", 
"tags"=>["beats_input_raw_event", 
"_grokparsefailure"],
 "filename"=>"redirect.jsp", 
"kafka"=>{"msg_size"=>12708, 
"topic"=>"logstash", 
"consumer_group"=>"logstash", 
"partition"=>4, 
"offset"=>594050844, 
"key"=>nil}, 
"indextime"=>"2016-12-09T19:47:41Z"}, 
"type"]}>>], 
:response=>{"create"=>{"_index"=>"infra_packetbeat-2016.12.09", 
"_type"=>"http", "_id"=>"AVjlIJGVcnKzVuhX5iTY", 
"status"=>400, 
"error"=>{"type"=>"mapper_parsing_exception", "reason"=>"Field name [_sp_id.2b02] cannot contain '.'"}}}, :level=>:warn}

```

---

<div class="post-metadata">

### Author: ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)
#### Post date: [December 9, 2016, 7:58pm UTC](https://discuss.elastic.co/t/packetbeat-compatibable-with-elastic-2-4/68595/5 "2016-12-09T19:58:44Z")

</div>

The worst part is that that DE\_DOT is not catching those fields even with nested turned on and it is fulling up my system  
☹

Probably try to turn off cookie parsing but that is the feature I really want .☹

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [December 9, 2016, 8:17pm UTC](https://discuss.elastic.co/t/packetbeat-compatibable-with-elastic-2-4/68595/6 "2016-12-09T20:17:23Z")

</div>

What is the configuration you use for the de\_dot filter? By default it only works on the top level fields. You have to set the [fields](https://www.elastic.co/guide/en/logstash/current/plugins-filters-de_dot.html#plugins-filters-de_dot-fields) to get it to work on sub-fields.

---

<div class="post-metadata">

### Author: ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)
#### Post date: [December 9, 2016, 8:27pm UTC](https://discuss.elastic.co/t/packetbeat-compatibable-with-elastic-2-4/68595/7 "2016-12-09T20:27:20Z")

</div>

I have nested set which seems the only option to deal with that

```auto
filter{
  de_dot{
	nested => true
  }
}

```

---

<div class="post-metadata">

### Author: ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)
#### Post date: [December 9, 2016, 8:51pm UTC](https://discuss.elastic.co/t/packetbeat-compatibable-with-elastic-2-4/68595/8 "2016-12-09T20:51:31Z")

</div>

You could configure Elasticsearch 2.4 to allow dots in field names. See [https://www.elastic.co/guide/en/elasticsearch/reference/2.4/dots-in-names.html#\_enabling\_support\_for\_dots\_in\_field\_names](https://www.elastic.co/guide/en/elasticsearch/reference/2.4/dots-in-names.html#_enabling_support_for_dots_in_field_names)

---

<div class="post-metadata">

### Author: ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)
#### Post date: [December 9, 2016, 8:54pm UTC](https://discuss.elastic.co/t/packetbeat-compatibable-with-elastic-2-4/68595/9 "2016-12-09T20:54:40Z")

</div>

well that works as a solution but can't be implemented quickly as I have a 30TB in the cluster. ☹

but will add that option so I have it

THANKS! That solves a lot of issues. funny I never came across it.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 30, 2016, 6:55pm UTC](https://discuss.elastic.co/t/packetbeat-compatibable-with-elastic-2-4/68595/10 "2016-12-30T18:55:01Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
