# Shodan query returns an ugly result i cant seem to fix

**URL:** <https://discuss.elastic.co/t/shodan-query-returns-an-ugly-result-i-cant-seem-to-fix/226778>\
**Category:** Logstash\
**Created:** [April 6, 2020, 8:47pm UTC](https://discuss.elastic.co/t/shodan-query-returns-an-ugly-result-i-cant-seem-to-fix/226778 "2020-04-06T20:47:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [April 6, 2020, 8:47pm UTC](https://discuss.elastic.co/t/shodan-query-returns-an-ugly-result-i-cant-seem-to-fix/226778/1 "2020-04-06T20:47:22Z")

</div>

hi, i'm querying [shodan.io](http://shodan.io) with some ip addresses.. every so often i get this message :  
`[2020-04-06T20:37:51,625][WARN][logstash.outputs.elasticsearch][darkwebrdp-hospitals] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"darkwebrdp-hospitals", :_type=>"_doc", :routing=>nil}, #<LogStash::Event:0x5e471612>], :response=>{"index"=>{"_index"=>"dw-clinic", "_type"=>"_doc", "_id"=>"sSk2UXEBT27AkRjbsxsZ", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [shodan.body.data.ssl.cert.serial] of type [long] in document with id 'sSk2UXEBT27AkRjbsxsZ'. Preview of field's value: '5839668960810396903895068807565469154'", "caused_by"=>{"type"=>"i_o_exception", "reason"=>"Numeric value (5839668960810396903895068807565469154) out of range of long (-9223372036854775808 - 9223372036854775807)\n at [Source: org.elasticsearch.common.bytes.BytesReference$MarkSupportingStreamInputWrapper@21da2d84; line: 1, column: 11107]"}}}}}`

i think i get it.. that field "shodan.body.data.ssl.cert.serial" is too long for a long type variable.. and its freaking out..

i've tried converting it to a string, i've tried removing it entirely (i dont need it), i've tried replacing any value in there with "na", i've tried replacing that value with 0.. nothing works.

i've tried both:  
[shodan.body.data.ssl.cert.serial]  
[shodan][body][data][ssl][cert][serial]

i'm out of ideas.. any suggestions would be appreciated

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 7, 2020, 3:24pm UTC](https://discuss.elastic.co/t/shodan-query-returns-an-ugly-result-i-cant-seem-to-fix/226778/2 "2020-04-07T15:24:01Z")

</div>

> [@stcdarrell](#):
>
> i've tried both:  
> [shodan.body.data.ssl.cert.serial]  
> [shodan][body][data][ssl][cert][serial]

It is possible that one of the field names contains a period. For example, it could be

```
[shodan][body][data][ssl.cert][serial]

```

or

```
[shodan][body][data][ssl][cert.serial]

```

I suggest you add

```
output { stdout { codec => rubydebug } }

```

which will allow you to see the actual structure of the field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2020, 3:24pm UTC](https://discuss.elastic.co/t/shodan-query-returns-an-ugly-result-i-cant-seem-to-fix/226778/3 "2020-05-05T15:24:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
