# Winlogbeat event\_data.param17 format change with MapperParsingException

**URL:** <https://discuss.elastic.co/t/winlogbeat-event-data-param17-format-change-with-mapperparsingexception/83742>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [April 26, 2017, 5:27pm UTC](https://discuss.elastic.co/t/winlogbeat-event-data-param17-format-change-with-mapperparsingexception/83742 "2017-04-26T17:27:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kim-Kruse-Hansen](https://avatars.discourse-cdn.com/v4/letter/k/f1d935/32.png) [@Kim-Kruse-Hansen](https://discuss.elastic.co/u/Kim-Kruse-Hansen)\
**Post date:** [April 26, 2017, 5:27pm UTC](https://discuss.elastic.co/t/winlogbeat-event-data-param17-format-change-with-mapperparsingexception/83742/1 "2017-04-26T17:27:10Z")

</div>

Hi

I am using Winlogbeat 5.x to collect Windows Logs. Lately I have been having an issue with a particular field in the event\_data. Specically event\_data.param17. This field is used by various event sources to contain data of different kinds. Sometimes it a date field and something is a filename field and so on.

Today I had a lot of exceptions where ElasticSearch thought is a date field. However it actually contained a SID field like "S-1-5-11". This caused a lot of MapperParsingException. These exception caused the whole cluster to stop for minutes of a time. It restarted itself , but it is very annoying to have indexing stop.

I have the 5.0.2 winlogbeat template installed. So I assumed that all fields would be a keyword type field. However in todays index , this particular was of type date. The rest of the param field was keyword as expected.

Anyone seen this ? Known problem ?

Regards  
Kim

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [April 26, 2017, 6:23pm UTC](https://discuss.elastic.co/t/winlogbeat-event-data-param17-format-change-with-mapperparsingexception/83742/2 "2017-04-26T18:23:53Z")

</div>

The template was setup to mark those fields as keyword, but we didn't disable the [date detection](https://github.com/elastic/beats/blob/5.3/winlogbeat/winlogbeat.template-es2x.json#L12) in the template so you get this problem. It's fixed in Winlogbeat 5.3+.

> <https://github.com/elastic/beats/issues/3389>

---

<div class="post-metadata">

**Author:** ![Kim-Kruse-Hansen](https://avatars.discourse-cdn.com/v4/letter/k/f1d935/32.png) [@Kim-Kruse-Hansen](https://discuss.elastic.co/u/Kim-Kruse-Hansen)\
**Post date:** [April 26, 2017, 7:05pm UTC](https://discuss.elastic.co/t/winlogbeat-event-data-param17-format-change-with-mapperparsingexception/83742/3 "2017-04-26T19:05:31Z")

</div>

Hi Andrew

Excellent, I will install updated templates , thnx for speedy assistance

Regards  
Kim

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2017, 5:40pm UTC](https://discuss.elastic.co/t/winlogbeat-event-data-param17-format-change-with-mapperparsingexception/83742/4 "2017-05-17T17:40:29Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
