# Convert strings with different data units (MB,GB,TB) to byte

**URL:** <https://discuss.elastic.co/t/convert-strings-with-different-data-units-mb-gb-tb-to-byte/55064>\
**Category:** Elasticsearch\
**Created:** [July 8, 2016, 3:35pm UTC](https://discuss.elastic.co/t/convert-strings-with-different-data-units-mb-gb-tb-to-byte/55064 "2016-07-08T15:35:39Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![beelastic](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@beelastic](https://discuss.elastic.co/u/beelastic)\
**Post date:** [July 8, 2016, 3:35pm UTC](https://discuss.elastic.co/t/convert-strings-with-different-data-units-mb-gb-tb-to-byte/55064/1 "2016-07-08T15:35:39Z")

</div>

Hello!  
i use grok to parse a log file with different data units, the fields are saved as strings, JSON example:

```
"totalserved": "4.4 MB",
"totalrequested": "4.4 MB",
"cacheserved": "4.4 MB",
"internetserved": "0 GB",
"peersserved": "4.5 GB"

```

Now i want them to be automatically recognized by elasticsearch as bytes (not MB or GB) and not as a string.  
Is this possible?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 8, 2016, 3:51pm UTC](https://discuss.elastic.co/t/convert-strings-with-different-data-units-mb-gb-tb-to-byte/55064/2 "2016-07-08T15:51:56Z")

</div>

I don't believe it's doable in elasticsearch today.  
Could be a nice mapper to have like the date type mapper we have.

May I suggest that you open a feature request and see what the team answers?

Also you can probably build your own plugin to achieve that.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [July 8, 2016, 3:56pm UTC](https://discuss.elastic.co/t/convert-strings-with-different-data-units-mb-gb-tb-to-byte/55064/3 "2016-07-08T15:56:21Z")

</div>

Better than that with elasticsearch 5.0 you'll be able to write an ingest plugin which can convert something like that in a value in bytes.

---

<div class="post-metadata">

**Author:** ![beelastic](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@beelastic](https://discuss.elastic.co/u/beelastic)\
**Post date:** [July 8, 2016, 3:58pm UTC](https://discuss.elastic.co/t/convert-strings-with-different-data-units-mb-gb-tb-to-byte/55064/4 "2016-07-08T15:58:14Z")

</div>

Thank you very much for your answer 🙂

I am trying now to parse out the units for every field and then calculate the bytes into a new field. I am excited to see if it works!

---

<div class="post-metadata">

**Author:** ![jprante](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jprante/32/44941_2.png) [@jprante](https://discuss.elastic.co/u/jprante)\
**Post date:** [July 8, 2016, 4:16pm UTC](https://discuss.elastic.co/t/convert-strings-with-different-data-units-mb-gb-tb-to-byte/55064/5 "2016-07-08T16:16:58Z")

</div>

ICU has a `MeasureFormat` [http://icu-project.org/apiref/icu4j/com/ibm/icu/text/MeasureFormat.html](http://icu-project.org/apiref/icu4j/com/ibm/icu/text/MeasureFormat.html)  
with a parse method.

This can work with [http://icu-project.org/apiref/icu4j/com/ibm/icu/util/MeasureUnit.html#MEGABYTE](http://icu-project.org/apiref/icu4j/com/ibm/icu/util/MeasureUnit.html#MEGABYTE) and [http://icu-project.org/apiref/icu4j/com/ibm/icu/util/MeasureUnit.html#GIGABYTE](http://icu-project.org/apiref/icu4j/com/ibm/icu/util/MeasureUnit.html#GIGABYTE) and much more.

I can add this as an analyzer / token filter to my ICU plugin at [https://github.com/jprante/elasticsearch-icu](https://github.com/jprante/elasticsearch-icu)

---

<div class="post-metadata">

**Author:** ![Glen\_Smith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glen_smith/32/111656_2.png) [@Glen\_Smith](https://discuss.elastic.co/u/Glen_Smith)\
**Post date:** [July 8, 2016, 5:41pm UTC](https://discuss.elastic.co/t/convert-strings-with-different-data-units-mb-gb-tb-to-byte/55064/6 "2016-07-08T17:41:14Z")

</div>

You could manage it in Logstash. Here's an example from something I did; your approach would have to vary slightly (might actually be easier, since this example is for strings with units appended without any whitespace.

```auto
# split the "store" into number, units prefix, and units base
    grok {
        # would like to put store_units_prefix and store_units_base in @metadata, too
        match => { "store" => "^%{BASE10NUM:[@metadata][store_number]:float}(?<store_units_prefix>[kKmMgGtT])(?<store_units_base>[b])$" }
    }
    mutate {
        add_field => {
            "[@metadata][store_units_prefix]" => "%{store_units_prefix}"
            "[@metadata][store_units_base]" => "%{store_units_base}"
        }
        remove_field => ["store_units_prefix", "store_units_base"]
    }
    if [@metadata][store_units_prefix] == "k" or [@metadata][store_units_prefix] == "K" {
        mutate { add_field => { "[@metadata][store_multiplier]" => 1024 } }
    } else if [@metadata][store_units_prefix] == "m" or [@metadata][store_units_prefix] == "M" {
        mutate { add_field => { "[@metadata][store_multiplier]" => 1048576 } }
    } else if [@metadata][store_units_prefix] == "g" or [@metadata][store_units_prefix] == "G" {
        mutate { add_field => { "[@metadata][store_multiplier]" => 1073741824 } }
    } else if [@metadata][store_units_prefix] == "t" or [@metadata][store_units_prefix] == "T" {
        mutate { add_field => { "[@metadata][store_multiplier]" => 1099511627776 } }
    }
# I don't know how to specify type in mutate.add_field, so I convert it
    mutate {
        convert => { "[@metadata][store_multiplier]" => "integer" }
    }
# create a new field with the size in bytes
    ruby {
        code => "event['store_size'] = event['@metadata']['store_number']*event['@metadata']['store_multiplier']"
    }

```

---

<div class="post-metadata">

**Author:** ![beelastic](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@beelastic](https://discuss.elastic.co/u/beelastic)\
**Post date:** [July 8, 2016, 6:15pm UTC](https://discuss.elastic.co/t/convert-strings-with-different-data-units-mb-gb-tb-to-byte/55064/7 "2016-07-08T18:15:16Z")

</div>

Thank you for sharing your configuration 🙂 This is exactly what i am  
coding right now - glad to hear that This Works!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:36pm UTC](https://discuss.elastic.co/t/convert-strings-with-different-data-units-mb-gb-tb-to-byte/55064/8 "2017-07-05T22:36:57Z")

</div>


