# PFSense Data and ECS - Data Fetch Failure

**URL:** <https://discuss.elastic.co/t/pfsense-data-and-ecs-data-fetch-failure/222525>\
**Category:** SIEM\
**Tags:** docker\
**Created:** [March 6, 2020, 11:15pm UTC](https://discuss.elastic.co/t/pfsense-data-and-ecs-data-fetch-failure/222525 "2020-03-06T23:15:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![somm15](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@somm15](https://discuss.elastic.co/u/somm15)\
**Post date:** [March 6, 2020, 11:15pm UTC](https://discuss.elastic.co/t/pfsense-data-and-ecs-data-fetch-failure/222525/1 "2020-03-06T23:15:43Z")

</div>

Hello,  
I am ingesting my PFSense logs and net flow using Filebeat.  
Filebeat feeds LogStash and it does the enrichment with select parts of the code from there:

> **[3ilson/pfelk](https://github.com/3ilson/pfelk/tree/master/conf.d)**
>
> pfSense + ELK. Contribute to 3ilson/pfelk development by creating an account on GitHub.

It works pretty well, each data type in its own index.  
Netflow data (filebeat net flow) to filebeat-\*  
PFsense logs to pf-\* (so should not be take into account by the SIEM yet)

However, going to the "network" or "host" tab of the SIEM always returns:  
"Data Fetch Failure"

The complete message is (or a variation with host.name):  
[illegal\_argument\_exception] Text fields are not optimised for operations that require per-document field data like aggregations and sorting, so these operations are disabled by default. Please use a keyword field instead. Alternatively, set fielddata=true on [source.ip] in order to load field data by uninverting the inverted index. Note that this can use significant memory.

For a reason, it appears that my fields are created as multi-fields with source.ip being text and source.ip.keyword being ... keyword.

I understand that I need source.ip to be keyword for the SIEM.  
How can I change this default behavior?

Thanks in advance,

---

<div class="post-metadata">

**Author:** ![somm15](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@somm15](https://discuss.elastic.co/u/somm15)\
**Post date:** [March 10, 2020, 9:29am UTC](https://discuss.elastic.co/t/pfsense-data-and-ecs-data-fetch-failure/222525/2 "2020-03-10T09:29:07Z")

</div>

Note to myself and other if it can help.  
I didn't load the templates in elastic.  
So you should manually load them.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2020, 9:29am UTC](https://discuss.elastic.co/t/pfsense-data-and-ecs-data-fetch-failure/222525/3 "2020-04-07T09:29:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
