# Unable to index into elasticsearch due to Byte range being out of range

**URL:** <https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857>\
**Category:** Elasticsearch\
**Created:** [March 16, 2023, 1:25pm UTC](https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857 "2023-03-16T13:25:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [March 16, 2023, 1:25pm UTC](https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857/1 "2023-03-16T13:25:43Z")

</div>

Hi,

I have a log that shows the interface usage (eth0/eth1) at a particular time , it logs in bytes and while logstash is able to parse it , elasticsearch seems to be rejecting it . Any workaround for this ? , in the component template , i gave the mapping as. "bytes\_written" -\> "numeric/byte"

here's a sample log

```auto
1 1678945972 <REDACTED> eth0 <REDACTED> 36248274 37294982749 56653568 82227069534

```

Here's what the sample logstash output shows

```auto
[2023-03-16T13:04:54,826][WARN][logstash.outputs.elasticsearch][interface_logger_log][8acbe052951cec868f387d4444fb955dc087a4bb4c48c6852ef35b8cee41737d] Could not index event to Elasticsearch. status: 400, action: ["create", {:_id=>nil, :_index=>interfacelogger_lines", :routing=>nil}, {"num_packets_written"=>"3230996", "bytes_written"=>"3577587849", "interface_logger_version"=>"1", "@timestamp"=>2023-03-16T09:45:34.000Z, "bytes_read"=>"632120356", "interface_ip"=>"$REDACTED", "num_packets_read"=>"2566696", "interface"=>"eth0"}], response: {"create"=>{"_index"=>"logstash_interface_logger_lines-000001", "_id"=>"gHmF6oYBVK7ZTxZd_N8N", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [bytes_written] of type [byte] in document with id 'gHmF6oYBVK7ZTxZd_N8N'. Preview of field's value: '3577587849'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"Value [3577587849] is out of range for an integer"}}}}
```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 16, 2023, 1:40pm UTC](https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857/2 "2023-03-16T13:40:00Z")

</div>

This is a mapping issue, the field is mapped as a `byte` but the value is higher than what an byte field would support, this should be mapped as `long`.

> [@Shreesh\_Narayanan](#):
>
> in the component template , i gave the mapping as. "bytes\_written" -\> "numeric/byte"

The `byte` here is the _byte_ data type, it only supports values between _-128_ and _127_, this is your issue, the field should be mapped as `long`, you can check the numeric data types in [this documentation](https://www.elastic.co/guide/en/elasticsearch/reference/current/number.html).

The solution is to change the mapping and recreate the index.

---

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [March 16, 2023, 2:13pm UTC](https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857/3 "2023-03-16T14:13:44Z")

</div>

Okay , wil try this and report back. Thanks a bunch

---

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [March 17, 2023, 9:44am UTC](https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857/4 "2023-03-17T09:44:05Z")

</div>

this worked 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 14, 2023, 9:44am UTC](https://discuss.elastic.co/t/unable-to-index-into-elasticsearch-due-to-byte-range-being-out-of-range/327857/5 "2023-04-14T09:44:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
