# Wireshark and 7.0

**URL:** <https://discuss.elastic.co/t/wireshark-and-7-0/181685>\
**Category:** Elasticsearch\
**Created:** [May 18, 2019, 3:10pm UTC](https://discuss.elastic.co/t/wireshark-and-7-0/181685 "2019-05-18T15:10:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Starblazer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/starblazer/32/45475_2.png) [@Starblazer](https://discuss.elastic.co/u/Starblazer)\
**Post date:** [May 18, 2019, 3:10pm UTC](https://discuss.elastic.co/t/wireshark-and-7-0/181685/1 "2019-05-18T15:10:54Z")

</div>

Hello!

Working with this post:  
[https://www.elastic.co/blog/analyzing-network-packets-with-wireshark-elasticsearch-and-kibana](https://www.elastic.co/blog/analyzing-network-packets-with-wireshark-elasticsearch-and-kibana)

and it appears that with 7.0 the template JSON file isn't supported anymore... and I'm at a loss.

Every single time I try to post it, I get this error message..

```
{
  "error": {
    "root_cause": [
      {
        "type": "mapper_parsing_exception",
        "reason": "Root mapping definition has unsupported parameters: [pcap_file : {dynamic=false, properties={layers={properties={udp={properties={udp_udp_srcport={type=integer}, udp_udp_dstport={type=integer}}}, ip={properties={ip_ip_src={type=ip}, ip_ip_dst={type=ip}}}, frame={properties={frame_frame_len={type=long}, frame_frame_protocols={type=keyword}}}}}, timestamp={type=date}}}]"
      }
    ],
    "type": "mapper_parsing_exception",
    "reason": "Failed to parse mapping [_doc]: Root mapping definition has unsupported parameters: [pcap_file : {dynamic=false, properties={layers={properties={udp={properties={udp_udp_srcport={type=integer}, udp_udp_dstport={type=integer}}}, ip={properties={ip_ip_src={type=ip}, ip_ip_dst={type=ip}}}, frame={properties={frame_frame_len={type=long}, frame_frame_protocols={type=keyword}}}}}, timestamp={type=date}}}]",
    "caused_by": {
      "type": "mapper_parsing_exception",
      "reason": "Root mapping definition has unsupported parameters: [pcap_file : {dynamic=false, properties={layers={properties={udp={properties={udp_udp_srcport={type=integer}, udp_udp_dstport={type=integer}}}, ip={properties={ip_ip_src={type=ip}, ip_ip_dst={type=ip}}}, frame={properties={frame_frame_len={type=long}, frame_frame_protocols={type=keyword}}}}}, timestamp={type=date}}}]"
    }
  },
  "status": 400
}

```

and I've been working on this for a few hours.... anything I'm missing other than a whole rewrite?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 18, 2019, 3:36pm UTC](https://discuss.elastic.co/t/wireshark-and-7-0/181685/2 "2019-05-18T15:36:15Z")

</div>

I think you need to remove the type name from the template. So remove this key: `pcap_file`.

HTH

---

<div class="post-metadata">

**Author:** ![apple-fan-pl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/apple-fan-pl/32/46398_2.png) [@apple-fan-pl](https://discuss.elastic.co/u/apple-fan-pl)\
**Post date:** [May 18, 2019, 4:07pm UTC](https://discuss.elastic.co/t/wireshark-and-7-0/181685/3 "2019-05-18T16:07:20Z")

</div>

Same AP here....

To sort this thing out, we need to understand how WireAir collects traffic.  
WireShark (+ KDEShit) uses thing called `caps` (`pcap`, `ncpcap` etc)....  
These caps sits on the interfaces and capture packets.

Problem here is that although WireShark runs OK, ES seems not to cooperate. Why? IDK. No-one knows - not even the developers of ES

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2019, 4:11pm UTC](https://discuss.elastic.co/t/wireshark-and-7-0/181685/4 "2019-06-15T16:11:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
