# Can't properly map array of IPv4 from Logstash to ES

**URL:** <https://discuss.elastic.co/t/cant-properly-map-array-of-ipv4-from-logstash-to-es/49349>\
**Category:** Elasticsearch\
**Created:** [May 5, 2016, 9:40pm UTC](https://discuss.elastic.co/t/cant-properly-map-array-of-ipv4-from-logstash-to-es/49349 "2016-05-05T21:40:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![esamudio](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@esamudio](https://discuss.elastic.co/u/esamudio)\
**Post date:** [May 5, 2016, 9:40pm UTC](https://discuss.elastic.co/t/cant-properly-map-array-of-ipv4-from-logstash-to-es/49349/1 "2016-05-05T21:40:10Z")

</div>

I'm having trouble getting Elasticsearch to accept my array of IPv4 as IPv4 instead of strings.  
I have a string with many IPs separated by spaces. I can easily turn that field into an array of IPs by using the split function in either the ruby or mutate filters.

The problem is that even though I already have the field "ip\_addresses" mapped to be of type "ip", Elasticsearch does not parse the field and gives error message:  
"Mixing up field types: class org.elasticsearch.index.mapper.core.LongFieldMapper$LongFieldType != class org.elasticsearch.index.mapper.ip.IpFieldMapper$IpFieldType on field ip\_addresses"

If I try to map it as type long, it fails with the same error because of String/Long mismatch. If I don't map them at all, dynamic mapping sets the type of the field to String.

Here's the rubydebug picture of the field I'm trying to push up to ES:  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/d/df6cc3a81ce6d72f957978d9ed2a4ed28ba3a9ff.png)  
Here's the exact error message:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/3/300a18b694a37f1a7d862ea7a2abc73df06f265a.png)  
Here's my previously defined mapping for that field:  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/01f40c127afd2414c8d6d6e6cfe4e92bf663757c.png)

The only somewhat relevant source of information I found is here: [http://stackoverflow.com/questions/29770043/how-can-i-store-and-search-multiple-ipv4-and-ipv6-subnets-in-elasticsearch](http://stackoverflow.com/questions/29770043/how-can-i-store-and-search-multiple-ipv4-and-ipv6-subnets-in-elasticsearch)

And according to documentation on arrays:

> In Elasticsearch, there is no dedicated array type. Any field can contain zero or more values by default, however, all values in the array must be of the same datatype.

GIven that any field can be made into an array, how can I properly have an array of type ip?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 5, 2016, 10:22pm UTC](https://discuss.elastic.co/t/cant-properly-map-array-of-ipv4-from-logstash-to-es/49349/2 "2016-05-05T22:22:07Z")

</div>

Please don't post pictures of text, they are difficult to read and some people may not be even able to see them 🙂

That aside, as you saw in the docs you cannot map an array, it just works. So I am not sure this would work beyond a string or an integer. Let me move this to the Elasticsearch category as it seems more suited to that =.

---

<div class="post-metadata">

**Author:** ![esamudio](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@esamudio](https://discuss.elastic.co/u/esamudio)\
**Post date:** [May 5, 2016, 10:42pm UTC](https://discuss.elastic.co/t/cant-properly-map-array-of-ipv4-from-logstash-to-es/49349/3 "2016-05-05T22:42:32Z")

</div>

Oh ok, sorry about the pictures. I mentioned what's on the pictures already so that was more for reference in case I wasn't very clear. Thanks for moving it to the appropriate category!

---

<div class="post-metadata">

**Author:** ![LetMeR00t](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@LetMeR00t](https://discuss.elastic.co/u/LetMeR00t)\
**Post date:** [June 13, 2016, 4:10pm UTC](https://discuss.elastic.co/t/cant-properly-map-array-of-ipv4-from-logstash-to-es/49349/4 "2016-06-13T16:10:20Z")

</div>

Hello,

I have the same kind of problem and I would like to know if you find a solution since the last reply?

Thank you

---

<div class="post-metadata">

**Author:** ![esamudio](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@esamudio](https://discuss.elastic.co/u/esamudio)\
**Post date:** [June 13, 2016, 4:21pm UTC](https://discuss.elastic.co/t/cant-properly-map-array-of-ipv4-from-logstash-to-es/49349/5 "2016-06-13T16:21:59Z")

</div>

There is an issue on the matter: [https://github.com/elastic/elasticsearch/issues/18740](https://github.com/elastic/elasticsearch/issues/18740)

---

<div class="post-metadata">

**Author:** ![LetMeR00t](https://avatars.discourse-cdn.com/v4/letter/l/9de0a6/32.png) [@LetMeR00t](https://discuss.elastic.co/u/LetMeR00t)\
**Post date:** [June 14, 2016, 6:46am UTC](https://discuss.elastic.co/t/cant-properly-map-array-of-ipv4-from-logstash-to-es/49349/6 "2016-06-14T06:46:36Z")

</div>

Thank you for the reply.

Well, my problem was resolved by another way. In fact, I have this error (Mixed up fields type) because the elasticsearch type was wrong (it's was something like array\_%{array\_name}), the "%{array\_name}" was not interpreted by Elasticsearch (for a good reason).  
Resolving this issue remove the error... Strange but it works now.

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:44pm UTC](https://discuss.elastic.co/t/cant-properly-map-array-of-ipv4-from-logstash-to-es/49349/7 "2017-07-05T22:44:06Z")

</div>


