# Convert type of custom fields added via metricbeat processors

**URL:** <https://discuss.elastic.co/t/convert-type-of-custom-fields-added-via-metricbeat-processors/217352>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [January 31, 2020, 10:54am UTC](https://discuss.elastic.co/t/convert-type-of-custom-fields-added-via-metricbeat-processors/217352 "2020-01-31T10:54:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![naveenbangalore](https://avatars.discourse-cdn.com/v4/letter/n/e56c9b/32.png) [@naveenbangalore](https://discuss.elastic.co/u/naveenbangalore)\
**Post date:** [January 31, 2020, 10:54am UTC](https://discuss.elastic.co/t/convert-type-of-custom-fields-added-via-metricbeat-processors/217352/1 "2020-01-31T10:54:24Z")

</div>

I have added the following processor in system.yml module of metricbeat.  
These custom fields flow to elastisearch as objects, but I am looking to pass them as strings.  
I tried using the "convert" processor without any luck. Is there a way to achieve this?

```
  processors:
  - add_fields:
      target: ''
      fields:
        module: Infra
        sub_module: System
```

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [January 31, 2020, 1:55pm UTC](https://discuss.elastic.co/t/convert-type-of-custom-fields-added-via-metricbeat-processors/217352/2 "2020-01-31T13:55:34Z")

</div>

Hi!

Could you share the resulted events? According to the [docs](https://www.elastic.co/guide/en/beats/metricbeat/current/add-fields.html)  
`to store the fields as top-level fields, set target: ''`, so what do you want to see as string and it isn't?

C.

---

<div class="post-metadata">

**Author:** ![naveenbangalore](https://avatars.discourse-cdn.com/v4/letter/n/e56c9b/32.png) [@naveenbangalore](https://discuss.elastic.co/u/naveenbangalore)\
**Post date:** [February 3, 2020, 4:54am UTC](https://discuss.elastic.co/t/convert-type-of-custom-fields-added-via-metricbeat-processors/217352/3 "2020-02-03T04:54:26Z")

</div>

Hi @ChrsMark,  
Let me set the context properly. As in the initial question, I am looking to add the fields "module" and "sub\_module" as custom text fields via Metricbeat. I have an existing index which is created by Logstash that has these two fields as text. I have made appropriate changes to Metricbeat to align with the index name created by Logstash so that both indices come under a single index pattern, which would eventually help me in building visualizations as per my needs.  
I have attached the screenshot from Kibana about this conflict for more clarity. In the attachment, indices of the format "or\_field\_reserve-XXXXXX" are created by Logstash and "or\_field\_reserve\_metric-XXXX.XX.XX-XXXXXX are created by Metricbeat. Below is the mapping of the field "module" from Logstash and Metricbeat.

Logstash:

```
"module" : {
 "type" : "text",
 "norms" : false,
 "fields" : {
   "keyword" : {
      "type" : "keyword",
      "ignore_above" : 256
   }
   }
}

```

Metricbeat:

```
"module": {
"type": "keyword",
"ignore_above": 1024
}

```

 ![Metricbeat_add_fields_error](https://us1.discourse-cdn.com/elastic/original/3X/b/8/b8fa25c12f5b41938a44906a712b65e314e85091.jpeg)

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [February 3, 2020, 9:23am UTC](https://discuss.elastic.co/t/convert-type-of-custom-fields-added-via-metricbeat-processors/217352/4 "2020-02-03T09:23:45Z")

</div>

Hi!

I tried with your example:

```auto
processors:
  - add_fields:
      target: ''
      fields:
        module: Infra
        sub_module: System

```

and here is what I see:

 ![Screenshot 2020-02-03 at 11.10.48](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8e19e293bb04f5200caf040d511f7242307032e6.png)

Consequently the processor itself works as expected, since it stores the fields as strings. So I guess that in your case, the thing that you have Logstash indexing the same field causes this confusion in ES.

Since it tends to be an Elasticsearch specific question I would suggest that you could point it to the respective Elasticsearch forum? wdyt?

---

<div class="post-metadata">

**Author:** ![naveenbangalore](https://avatars.discourse-cdn.com/v4/letter/n/e56c9b/32.png) [@naveenbangalore](https://discuss.elastic.co/u/naveenbangalore)\
**Post date:** [February 3, 2020, 9:45am UTC](https://discuss.elastic.co/t/convert-type-of-custom-fields-added-via-metricbeat-processors/217352/5 "2020-02-03T09:45:35Z")

</div>

Hi @ChrsMark,  
I have applied a workaround for now by updating the mapping in the index template created by metricbeat. By adding the below in the metricbeat mapping, I was able to align the fields flowing from both sources. Could you please share the mapping for the fields created by your replication? You can find it under "Management-\> Index Management--\>Index templates--\> --\> Mappings or from the dev tools using query in Kibana.

```
"module" : {
  "type" : "text",
  "norms" : false,
  "fields" : {
	"keyword" : {
	  "type" : "keyword",
	  "ignore_above" : 256
	}
  }
},
"sub_module" : {
  "type" : "text",
  "norms" : false,
  "fields" : {
	"keyword" : {
	  "type" : "keyword",
	  "ignore_above" : 256
	}
  }
```

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [February 3, 2020, 11:08am UTC](https://discuss.elastic.co/t/convert-type-of-custom-fields-added-via-metricbeat-processors/217352/6 "2020-02-03T11:08:10Z")

</div>

Hey!

Here it is:

```auto
    "module" : {
        "type" : "keyword",
        "ignore_above" : 1024
    },
    "sub_module" : {
        "type" : "keyword",
        "ignore_above" : 1024
    },  

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2020, 11:09am UTC](https://discuss.elastic.co/t/convert-type-of-custom-fields-added-via-metricbeat-processors/217352/7 "2020-03-02T11:09:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
