# Convert ip-address of long type to the Dotted decimal notation

**URL:** <https://discuss.elastic.co/t/convert-ip-address-of-long-type-to-the-dotted-decimal-notation/43972>\
**Category:** Logstash\
**Created:** [March 10, 2016, 3:21am UTC](https://discuss.elastic.co/t/convert-ip-address-of-long-type-to-the-dotted-decimal-notation/43972 "2016-03-10T03:21:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![lizhenmxcz](https://avatars.discourse-cdn.com/v4/letter/l/a88e57/32.png) [@lizhenmxcz](https://discuss.elastic.co/u/lizhenmxcz)\
**Post date:** [March 10, 2016, 3:21am UTC](https://discuss.elastic.co/t/convert-ip-address-of-long-type-to-the-dotted-decimal-notation/43972/1 "2016-03-10T03:21:45Z")

</div>

hi, I want use logstash to write the log that contains the ip of long type to the elasticsearch. how can i convert the long type ip to the Dotted decimal notation in the logstash

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 10, 2016, 7:02am UTC](https://discuss.elastic.co/t/convert-ip-address-of-long-type-to-the-dotted-decimal-notation/43972/2 "2016-03-10T07:02:20Z")

</div>

I'm not sure what you mean. You need to convert an integer IP address to dotted decimal form in Logstash? Why? Perhaps an example would be easier to understand.

---

<div class="post-metadata">

**Author:** ![lizhenmxcz](https://avatars.discourse-cdn.com/v4/letter/l/a88e57/32.png) [@lizhenmxcz](https://discuss.elastic.co/u/lizhenmxcz)\
**Post date:** [March 10, 2016, 7:07am UTC](https://discuss.elastic.co/t/convert-ip-address-of-long-type-to-the-dotted-decimal-notation/43972/3 "2016-03-10T07:07:05Z")

</div>

@magnusbaeck, yes, I need to convert an integer IP address to dotted decimal form in Logstash, because the ip store in logs is like '3232241539'. I want to index them use ip type in elasticsearch.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 10, 2016, 7:13am UTC](https://discuss.elastic.co/t/convert-ip-address-of-long-type-to-the-dotted-decimal-notation/43972/4 "2016-03-10T07:13:52Z")

</div>

That's a really weird log format then. I'm pretty sure you need a ruby filter for this (or a custom plugin). See [https://basic70tech.wordpress.com/2007/04/13/32-bit-ip-address-to-dotted-notation-in-ruby/](https://basic70tech.wordpress.com/2007/04/13/32-bit-ip-address-to-dotted-notation-in-ruby/) for examples of how to make that conversion in Ruby.

---

<div class="post-metadata">

**Author:** ![lizhenmxcz](https://avatars.discourse-cdn.com/v4/letter/l/a88e57/32.png) [@lizhenmxcz](https://discuss.elastic.co/u/lizhenmxcz)\
**Post date:** [March 10, 2016, 1:58pm UTC](https://discuss.elastic.co/t/convert-ip-address-of-long-type-to-the-dotted-decimal-notation/43972/5 "2016-03-10T13:58:43Z")

</div>

@magnusbaeck, thank you very much, i have solve it。

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:07am UTC](https://discuss.elastic.co/t/convert-ip-address-of-long-type-to-the-dotted-decimal-notation/43972/6 "2017-07-06T05:07:32Z")

</div>


