[netflow.event_time_msec] illegal_argument_exception Invalid format #330
Comments
anybody can help me? |
That number Refer to this issue... #205 (comment) |
Thanks. one udp port for one device (cisco asa)? |
I add redis, but didn’t help me. |
This issue will be addressed once the following PRs are merged and released for the... Logstash UDP Input: logstash-plugins/logstash-input-udp#46 |
Unfortunately the Elastic team declined to merge UDP input changes (see... logstash-plugins/logstash-input-udp#46). This leaves no other option than to continue to recommend the workaround of multiple instances of the ElastiFlow pipeline. |
Helo! I use opendistro 0.9.0 and logstash 6.7.1.
After start elastiflow in logstash-plain.log i often see this message.
[2019-05-18T17:29:35,712][WARN ][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"elastiflow-3.4.2-2019.05.18", :_type=>"doc", :routing=>nil}, #LogStash::Event:0x7da036e9], :response=>{"index"=>{"_index"=>"elastiflow-3.4.2-2019.05.18", "_type"=>"doc", "_id"=>"dv3rymoBSwHmamFUPu9T", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse field [netflow.event_time_msec] of type [date] in document with id 'dv3rymoBSwHmamFUPu9T'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"Invalid format: "12893817287834063931" is malformed at "3817287834063931""}}}}}
The text was updated successfully, but these errors were encountered: