# Convert a field from string to ip type

**URL:** <https://discuss.elastic.co/t/convert-a-field-from-string-to-ip-type/1865>\
**Category:** Logstash\
**Created:** [June 3, 2015, 6:57pm UTC](https://discuss.elastic.co/t/convert-a-field-from-string-to-ip-type/1865 "2015-06-03T18:57:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Prachi](https://avatars.discourse-cdn.com/v4/letter/p/7ea924/32.png) [@Prachi](https://discuss.elastic.co/u/Prachi)\
**Post date:** [June 3, 2015, 6:57pm UTC](https://discuss.elastic.co/t/convert-a-field-from-string-to-ip-type/1865/1 "2015-06-03T18:57:44Z")

</div>

Hello,

I am trying to upload my text file on Elasticsearch using Logstash. Below is how my config file look like. When I upload my text files on elasticsearch, the src\_ip and dst\_ip fields are by default taken as string type. Can you please tell me how can I convert src\_ip and dst\_ip field in ip type in filter?

Thanks!

input {  
file {  
path =\> "/root/Downloads/new\_logs/\*.txt"  
type =\> "txt\_file"  
start\_position =\> "beginning"  
}  
}  
filter {  
csv {  
columns =\> ["sig\_name", "sig\_sid", "triggertimestampString", "src\_ip", "dst\_ip", "ip\_proto", "customer\_name", "correlated\_ids"]  
separator =\> "| "  
}  
mutate {  
convert =\> {  
"sig\_sid" =\> "integer"  
"ip\_proto" =\> "integer"  
"correlated\_ids" =\>"boolean"  
}  
}  
date {  
match =\> ["triggertimestampString", "YYYY-MM-dd HH:mm:ss.SSS-SS ", "YYYY-MM-dd HH:mm:ss.SS-SS ", "YYYY-MM-dd HH:mm:ss.S-SS "]  
target =\> "ttimestamp"  
}

}  
output {  
elasticsearch {  
action =\> "index"  
index =\> "testI"  
workers =\> 1  
}  
stdout {}  
}

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 3, 2015, 7:16pm UTC](https://discuss.elastic.co/t/convert-a-field-from-string-to-ip-type/1865/2 "2015-06-03T19:16:14Z")

</div>

The conversion is not done within Logstash, but as a manually applied [Elasticsearch mapping](https://www.elastic.co/guide/en/elasticsearch/reference/1.x/mapping-ip-type.html).

This can be done within a template, so that the mapping is automatically applied to each new index created (that matches the pattern). For example, you'd put the lines:

"src\_ip": { "type": "ip"},  
"dst\_ip": { "type": "ip"),

immediately following the line starting with [@version in this example template](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/master/lib/logstash/outputs/elasticsearch/elasticsearch-template.json#L30). You would then need to use the template management directives in the [elasticsearch output plugin](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html) to use your updated template.

---

<div class="post-metadata">

**Author:** ![Prachi](https://avatars.discourse-cdn.com/v4/letter/p/7ea924/32.png) [@Prachi](https://discuss.elastic.co/u/Prachi)\
**Post date:** [June 3, 2015, 8:57pm UTC](https://discuss.elastic.co/t/convert-a-field-from-string-to-ip-type/1865/3 "2015-06-03T20:57:47Z")

</div>

I understand that the conversion doesn't happen within logstash. But I am new to elasticsearch and I don't know other ways of applying mapping to elasticsearch.

Also, can you please tell me more about template? Do I have to create a template? Or it create every time I make new index?

Thank you!

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 3, 2015, 9:32pm UTC](https://discuss.elastic.co/t/convert-a-field-from-string-to-ip-type/1865/4 "2015-06-03T21:32:37Z")

</div>

Once a template is in place, all indices matching the name pattern will get that template. There is one that ships with Logstash (the one linked above). I suggest copying that one, and editing it with the lines I recommended.

Then, in your elasticsearch output block, add:

template =\> "/path/to/your/new/template.json"  
template\_overwrite =\> true

This will only work if you are using the default logstash-YYYY.MM.dd naming pattern. (If you do not have a custom `index =>` directive in your elasticsearch block, then you are using the default).

---

<div class="post-metadata">

**Author:** ![orhiee](https://avatars.discourse-cdn.com/v4/letter/o/eb9ed0/32.png) [@orhiee](https://discuss.elastic.co/u/orhiee)\
**Post date:** [February 2, 2017, 8:16pm UTC](https://discuss.elastic.co/t/convert-a-field-from-string-to-ip-type/1865/5 "2017-02-02T20:16:30Z")

</div>

i have been searching for his, thanks for the info but unfortunately for new people this is not very useful so i am sharing the whole code to help 🙂 (used default template in elastic 5.1.2 as template)

sec\_on-\* is the index name pattern

ID\_RESP\_H & ID\_ORIG\_H is my source &dest ip

#run the below to create template  
PUT /\_template/sec\_on  
{  
"template": "sec\_on-\*",  
"order": 1,  
"settings": {  
"index": {  
"refresh\_interval": "5s"  
}  
},  
"mappings": {  
"_default_": {  
"\_all": {  
"norms": false,  
"enabled": true  
},  
"properties": {  
"ID\_RESP\_H": { "type": "ip"},  
"ID\_ORIG\_H": { "type": "ip"}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:28am UTC](https://discuss.elastic.co/t/convert-a-field-from-string-to-ip-type/1865/6 "2017-07-06T04:28:57Z")

</div>


