# Winlogbeat to Logstash to Elasticsearch error

**URL:** <https://discuss.elastic.co/t/winlogbeat-to-logstash-to-elasticsearch-error/57432>\
**Category:** Logstash\
**Created:** [August 7, 2016, 9:48pm UTC](https://discuss.elastic.co/t/winlogbeat-to-logstash-to-elasticsearch-error/57432 "2016-08-07T21:48:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![theflakes](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@theflakes](https://discuss.elastic.co/u/theflakes)\
**Post date:** [August 7, 2016, 9:48pm UTC](https://discuss.elastic.co/t/winlogbeat-to-logstash-to-elasticsearch-error/57432/1 "2016-08-07T21:48:40Z")

</div>

I have a Win2012 R2 Server sending logs to to logstash via Winlogbeat. I see the logs in the logstash.log file but each gets the below error.

:response=\>{"index"=\>{"\_index"=\>"winlogbeat-2016.08.07", "\_type"=\>"wineventlog", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"Failed to parse mapping [_default_]: No handler for type [keyword] declared on field [related\_activity\_id]", "caused\_by"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"No handler for type [keyword] declared on field [related\_activity\_id]"}}}}, :level=\>:warn}

I'm new to the ELK stack and have searched and tried many things to fix this with no luck. I think I have the winlogbeat template imported into elasticsearch ok as I see both the filebeat and the winlogbeat template when I query it on port 9200.

ELK stack is running on Ubuntu 14.04 LTS and using Winlogbeat v1.2.3.

Any help would be very much appreciated.

---

<div class="post-metadata">

**Author:** ![theflakes](https://avatars.discourse-cdn.com/v4/letter/t/839c29/32.png) [@theflakes](https://discuss.elastic.co/u/theflakes)\
**Post date:** [August 7, 2016, 10:19pm UTC](https://discuss.elastic.co/t/winlogbeat-to-logstash-to-elasticsearch-error/57432/2 "2016-08-07T22:19:35Z")

</div>

Figured it out. The filebeat template was causing the problem as it was using the type:keyword that isn't supported in the version of ES I'm running.

> <https://stackoverflow.com/questions/37599410/elasticsearch-no-handler-for-type-keyword-declared-on-field-hostname>

Deleted it and it is now working as expected.

curl -XDELETE localhost:9200/\_template/filebeat

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:44am UTC](https://discuss.elastic.co/t/winlogbeat-to-logstash-to-elasticsearch-error/57432/3 "2017-07-06T04:44:23Z")

</div>


