elastic/elasticsearch · error · IllegalArgumentException

Invalid MAC address format

Error message

Invalid MAC address format

What it means

CefParser.toMACAddress inserts ':' separators into a bare hex string (if length is 12 or 16) and then matches MAC_ADDRESS_PATTERN. If the matcher does not match, the value is rejected. Applies to any CEF extension mapped to DataType.MACAddressType (smac, dmac, amac, etc.). No exception cause is attached.

Source

Thrown at modules/ingest-common/src/main/java/org/elasticsearch/ingest/common/CefParser.java:566

                        newTime = newTime.with(field, accessor.get(field));
                    }
                }
                accessor = newTime.withZoneSameLocal(timezone);
            }
            return DateFormatters.from(accessor, Locale.ROOT, timezone).withZoneSameInstant(timezone);
        } catch (DateTimeParseException ignored) {
            throw new IllegalArgumentException("Value is not a valid timestamp: " + value);
        }
    }

    // visible for testing
    String toMACAddress(String v) throws IllegalArgumentException {
        // Insert separators if necessary
        String macWithSeparators = insertMACSeparators(v);
        // Validate MAC address format
        Matcher matcher = MAC_ADDRESS_PATTERN.matcher(macWithSeparators);
        if (matcher.matches() == false) {
            throw new IllegalArgumentException("Invalid MAC address format");
        }
        return macWithSeparators;
    }

    // visible for testing
    String toIP(String v) {
        try {
            return NetworkAddress.format(InetAddresses.forString(v));
        } catch (IllegalArgumentException e) {
            throw new IllegalArgumentException("Invalid IP address format", e);
        }
    }

    private static String insertMACSeparators(String v) {
        // Check that the length is correct for a MAC address without separators.
        // And check that there isn't already a separator in the string.
        if ((v.length() != EUI48_HEX_LENGTH && v.length() != EUI64_HEX_LENGTH)
            || v.charAt(2) == ':'

View on GitHub (pinned to db6a809a66)

Solutions

  1. Verify the source field actually contains a MAC in one of the four supported formats.
  2. Add a grok/regex pre-processor to normalize MAC values into colon-separated form.
  3. Route failures to an on_failure pipeline.
  4. If the value is sometimes absent rather than malformed, set ignore_empty_values on the cef processor to drop empty-string entries.

Example fix

// before — partial / malformed MAC
//   field: 'CEF:0|v|p|1.0|1|n|3|smac=0011223344 next=...'
//
// after — full 6-byte MAC in any supported layout
//   field: 'CEF:0|v|p|1.0|1|n|3|smac=00:11:22:33:44:55 next=...'
Defensive patterns

Strategy: validation

Validate before calling

// Mirror CefParser's accepted MAC shapes: colon/hyphen/dot separated EUI-48 or EUI-64, or 12/16 hex chars.
private static final Pattern MAC = Pattern.compile(
    "(?:[0-9A-Fa-f]{2}[:-]){5}[0-9A-Fa-f]{2}|" +
    "(?:[0-9A-Fa-f]{4}\\.){2}[0-9A-Fa-f]{4}|" +
    "(?:[0-9A-Fa-f]{2}[:-]){7}[0-9A-Fa-f]{2}|" +
    "(?:[0-9A-Fa-f]{4}\\.){3}[0-9A-Fa-f]{4}|" +
    "[0-9A-Fa-f]{12}|[0-9A-Fa-f]{16}");
boolean isLikelyMac(String v) { return v != null && MAC.matcher(v).matches(); }

Try / catch

{
  "on_failure": [
    { "set": { "field": "ingest.error", "value": "cef-bad-mac" } },
    { "redirect": { "pipeline": "quarantine" } }
  ]
}

Prevention

When it happens

Trigger: A MAC-typed extension value such as '00:11:22:33:44', 'ZZ:ZZ:ZZ:ZZ:ZZ:ZZ', 'aa-bb-cc-dd-ee', or 'not-a-mac'. Both the EUI-48 and EUI-64 forms (colon/hyphen/dot separated, or 12/16 hex chars unseparated) are accepted; anything else throws.

Common situations: Producer emits a partial or placeholder MAC ('00:00:00:00:00:00' is valid and does NOT throw, but 'unknown' or a stripped value does); a normalization step upstream trims characters; IPv6 address mistakenly mapped to a MAC field.

Related errors


AI-assisted analysis of elastic/elasticsearch@db6a809a66 (2026-08-12). Data as JSON: /api/errors/b80e65abf35f514c. Report an issue: GitHub.