# Converting string to ip datatype

**URL:** <https://discuss.elastic.co/t/converting-string-to-ip-datatype/207890>\
**Category:** Logstash\
**Created:** [November 14, 2019, 12:40pm UTC](https://discuss.elastic.co/t/converting-string-to-ip-datatype/207890 "2019-11-14T12:40:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bibin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bibin/32/75358_2.png) [@bibin](https://discuss.elastic.co/u/bibin)\
**Post date:** [November 14, 2019, 12:40pm UTC](https://discuss.elastic.co/t/converting-string-to-ip-datatype/207890/1 "2019-11-14T12:40:54Z")

</div>

Hi team ES...  
Can anyone help me how to convert a string to ip datatype ,I have already indexed huge data... As I am new to ES ,i couldn't understand solutions to similar situation

sample data  
//  
current format  
_ **string** _ ,date,string,sting,integer,string  
// 10.8.1.18,01-08-2019 00:00:21,CURRENT,Idea/Vodafone,325 KB/s  
10.8.1.18,01-08-2019 00:30:19,CURRENT,Idea/Vodafone,401 KB/s  
10.8.1.18,01-08-2019 01:00:17,CURRENT,Idea/Vodafone,607 KB/s  
10.8.1.18,01-08-2019 01:30:16,CURRENT,Idea/Vodafone,627 KB/s  
10.8.1.18,01-08-2019 02:00:17,CURRENT,Idea/Vodafone,549 KB/s //

required format  
**ip** ,date,string,sting,integer,string

my logstash config file content is

// input {  
file {  
path =\> "/home/bibin/logs/_/_/speed.csv"  
max\_open\_files =\> 17000  
start\_position =\> "beginning"  
sincedb\_path =\> "/home/bibin/ALL/since\_speed.db"  
}  
}  
filter {  
#10.8.1.18,05-07-2019 14:00:13,CURRENT,Idea/Vodafone,0 KB/s  
#10.8.1.18,05-07-2019 14:30:22,CURRENT,Idea/Vodafone,254 KB/s  
dissect {  
mapping =\> {  
"message" =\> "%{ip},%{occured\_instant},%{time\_slot},%{provider},%{speed} %{unit}"  
}  
}  
date {  
match =\> ["occured\_instant", "dd-MM-yyyy HH:mm:ss"]  
target =\> "occured\_date"  
}  
mutate {  
convert =\> {  
"speed" =\> "integer"  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> "192.168.0.12:9200"  
index =\> "speed"  
document\_type =\> "speed\_bbb"  
}  
stdout {}

---

<div class="post-metadata">

**Author:** ![baz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/baz/32/5183_2.png) [@baz](https://discuss.elastic.co/u/baz)\
**Post date:** [November 14, 2019, 3:52pm UTC](https://discuss.elastic.co/t/converting-string-to-ip-datatype/207890/2 "2019-11-14T15:52:52Z")

</div>

Welcome @bibin, I have moved your post to the logstash category as it fits better there. They will be able to help you, thank you for posting!

Baz.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 14, 2019, 5:49pm UTC](https://discuss.elastic.co/t/converting-string-to-ip-datatype/207890/3 "2019-11-14T17:49:39Z")

</div>

I would say this is an elasticsearch question. You need an index template that [sets](https://www.elastic.co/guide/en/elasticsearch/reference/current/ip.html) the type of the field on the document.

---

<div class="post-metadata">

**Author:** ![bibin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bibin/32/75358_2.png) [@bibin](https://discuss.elastic.co/u/bibin)\
**Post date:** [November 20, 2019, 9:14am UTC](https://discuss.elastic.co/t/converting-string-to-ip-datatype/207890/4 "2019-11-20T09:14:54Z")

</div>

Hi Badger,  
As per reference to es docs,I have created a new index "facebook" in my ES with datatype **ip** with following mapping and it was successful...  
//  
PUT /facebook/\_mapping  
{  
"properties": {  
"@timestamp": {  
"type": "date"  
},  
"@version": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"host": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
**"ip": {**  
**"type": "ip"**  
**},**  
"message": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"my\_field": {  
"type": "text",  
"fielddata": true  
},  
"occured\_date": {  
"type": "date"  
},  
"occured\_instant": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"path": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"provider": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"speed": {  
"type": "long"  
},  
"tags": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"time\_slot": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
},  
"unit": {  
"type": "text",  
"fields": {  
"keyword": {  
"type": "keyword",  
"ignore\_above": 256  
}  
}  
}  
}  
}  
//

and showed response as true...  
//  
{  
"acknowledged" : true  
}  
//

But when I tried to index data into this new index ...  
10.8.0.100,12-11-2019 01:00:41,CURRENT,Idea/Vodafone,73 KB/s  
10.8.0.100,12-11-2019 01:30:12,CURRENT,Idea/Vodafone,0 KB/s

its is showing below mentioned error...

//  
Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"facebook", :\_type=\>"face\_docs", :routing=\>nil}, #LogStash::Event:0x390714f], :response=\>{"index"=\>{"\_index"=\>"facebook", "\_type"=\>"face\_docs", "\_id"=\>"aR6dh24BNAK6JMz4EyQN", "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Rejecting mapping update to [facebook] as the final mapping would have more than 1 type: [\_doc, face\_docs]"}}}}  
//

Can anyone help me why I am getting above error when trying to index documents with datatype **ip** to it..?

---

<div class="post-metadata">

**Author:** ![chandu5565](https://avatars.discourse-cdn.com/v4/letter/c/c57346/32.png) [@chandu5565](https://discuss.elastic.co/u/chandu5565)\
**Post date:** [November 20, 2019, 11:41am UTC](https://discuss.elastic.co/t/converting-string-to-ip-datatype/207890/5 "2019-11-20T11:41:51Z")

</div>

In the output of your elasticsearch remove the document\_type that should work. Where as each index can have only one mapping type.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 20, 2019, 2:22pm UTC](https://discuss.elastic.co/t/converting-string-to-ip-datatype/207890/6 "2019-11-20T14:22:43Z")

</div>

For more details on the removal of types see [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/removal-of-types.html).

---

<div class="post-metadata">

**Author:** ![bibin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bibin/32/75358_2.png) [@bibin](https://discuss.elastic.co/u/bibin)\
**Post date:** [November 27, 2019, 4:27am UTC](https://discuss.elastic.co/t/converting-string-to-ip-datatype/207890/7 "2019-11-27T04:27:48Z")

</div>

Thanks chandu5565 for the help.It was successfully indexed by removing document\_type from elasticsearch output. Hatsoff for the help.

I assume that as I have **already specified mapping manually** in the setting file,there is no need to specify **document\_type** in the elasticsearch output part.

I am satisfied by the solution and was successful...!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2019, 4:27am UTC](https://discuss.elastic.co/t/converting-string-to-ip-datatype/207890/8 "2019-12-25T04:27:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
