# Append a string to a field after mutate convert filter

**URL:** <https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327>\
**Category:** Logstash\
**Created:** [June 19, 2023, 6:15am UTC](https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327 "2023-06-19T06:15:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [June 19, 2023, 6:15am UTC](https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327/1 "2023-06-19T06:15:54Z")

</div>

Hi I have the following log pattern

[19/Jun/2023:11:27:35 +0530] | 503 | 1188 ms | **299 B** | 172.31.40.179 | - | - | - | "GET /3dcomment/monitoring/healthcheck HTTP/1.1"

I have applied grok to fetch the bytes field i.e 299 B  
I am applying mutate convert filter to convert it to int. But after converting it to int i am losing the 'B' part of the value. is there any way i can add it to the field while keeping it in int?  
I have converted it to int because if it is a string i am not able to apply appropriate filters on it while creating the visualizations  
Here is my logstash pipeline filter module

```auto
filter {
  if [3dxp_tag] == "3dxp_apache"
  {
      grok {
        match => { "message" => ["\[%{HTTPDATE:date}\] \| %{NUMBER:response} \| (?<duration>%{NUMBER} %{WORD}) \| (?<bytes>%{NUMBER} %{WORD}|%{DATA}) \| %{IP:remoteip} \| (%{IP:clientip}|%{DATA:clientip}) \| (%{WORD:token}|%{DATA:token}) \| (?<tag1>%{NUMBER} %{WORD}|%{DATA}) \| \"(?<method>%{WORD}) (?<url>%{URIPATHPARAM}) (?:HTTP/%{NUMBER:http_version})\""] }
    }
      mutate {
        convert => {
          "bytes" => "int"
        }
      }
 }

```

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 19, 2023, 2:53pm UTC](https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327/2 "2023-06-19T14:53:00Z")

</div>

> [@Neelam\_Zanvar](#):
>
> But after converting it to int i am losing the 'B' part of the value.

I don't think you'll be able to keep the 'B' on an int type field. But if you need both you could create another field using a [`copy` filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-copy) so you can use the int field for your visualizations as well as the original string.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [June 20, 2023, 3:13pm UTC](https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327/3 "2023-06-20T15:13:46Z")

</div>

As Carly said, you can have:

- string: "299 B", no numeric calculation or play with runtime field in ES
- int:299, mathematic calculation like min, max, avg
- int:299, and the extra string field "unit": "B"

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [June 21, 2023, 7:14am UTC](https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327/4 "2023-06-21T07:14:11Z")

</div>

sure, the 3rd option seems good. Thanks for the quick response as always 👍

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2023, 7:14am UTC](https://discuss.elastic.co/t/append-a-string-to-a-field-after-mutate-convert-filter/336327/5 "2023-07-19T07:14:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
