# Correct src\_ip field datatype to 'ip'

**URL:** <https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100>\
**Category:** Elasticsearch\
**Created:** [October 26, 2018, 5:47am UTC](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100 "2018-10-26T05:47:02Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![CamTheMan](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CamTheMan](https://discuss.elastic.co/u/CamTheMan)\
**Post date:** [October 26, 2018, 5:47am UTC](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100/1 "2018-10-26T05:47:02Z")

</div>

Hello,  
I have only recently discovered the field datatype 'ip' I have most of the my IP addresses labeled as 'src\_ip' looking at the current data type it's a 'string'.

1. Can i force the change somehow?
2. How do i fix it?

Deep down I realise the answer will be re-index the data. Unfortunately I can't just delete all the indexes on a production system. Is there a way to reindex the current data from elastic itself - Is the process documented anywhere.

Thanks  
Cam

---

<div class="post-metadata">

**Author:** ![xavierfacq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavierfacq/32/8744_2.png) [@xavierfacq](https://discuss.elastic.co/u/xavierfacq)\
**Post date:** [October 26, 2018, 7:52am UTC](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100/2 "2018-10-26T07:52:56Z")

</div>

Hi,

AFAIK, you need to reindex your data with a new mapping. You can use the following API:

[https://www.elastic.co/guide/en/elasticsearch/reference/6.4/docs-reindex.html](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/docs-reindex.html)

bye,  
Xavier

---

<div class="post-metadata">

**Author:** ![CamTheMan](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CamTheMan](https://discuss.elastic.co/u/CamTheMan)\
**Post date:** [October 28, 2018, 11:00pm UTC](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100/3 "2018-10-28T23:00:51Z")

</div>

So knowing that I need to reindex my data, what else do I need to do to achieve the correct mapping moving forward?

1. I feel I need to update the 'index template' and assign src\_ip as type 'ip'.  
Whats the best way to go about this?

- Should I update the default 'dynamic template' ?
- Should I overwrite the default template?
- Should I overwrite the logstash template?
- Should I append to the logstash template with an ordering of "1"?

Considering that I have 4 current index patterns, eg. logstash-_, firewall-_, syslog-_, docker-_

I'm tempted to set the default index-template. Does this have any repercussions?

So to correct the fieldtype is this the order of events?

- Update default index-template
- Reindex data using 'reindex API'

Anything else?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![xavierfacq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavierfacq/32/8744_2.png) [@xavierfacq](https://discuss.elastic.co/u/xavierfacq)\
**Post date:** [October 29, 2018, 10:27am UTC](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100/4 "2018-10-29T10:27:52Z")

</div>

Hi,

I would suggest to modify only templates you need. If they all depend of the default one, why not, but you have to be careful. Mabye you can test on the logstash one in a first time ?

The plan is:

- update your templates
- create new index and verify the mapping
- call the reindex API

Hope it helps

---

<div class="post-metadata">

**Author:** ![CamTheMan](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CamTheMan](https://discuss.elastic.co/u/CamTheMan)\
**Post date:** [October 30, 2018, 5:42am UTC](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100/5 "2018-10-30T05:42:11Z")

</div>

So I'm attempting to use a dynamic template, this is it here:

```
GET /_template/mylogstash
    {
  "my_logstash": {
    "order": 1000,
    "index_patterns": [
      "logstash-*",
      "firewall-*"
    ],
    "settings": {},
    "mappings": {
      "_default_": {
        "dynamic_templates": [
          {
            "dest_ip": {
              "path_match": "dest_ip",
              "mapping": {
                "type": "ip"
              }
            }
          },
          {
            "dst_ip": {
              "path_match": "dst_ip",
              "mapping": {
                "type": "ip"
              }
            }
          },
          {
            "src_ip": {
              "path_match": "src_ip",
              "mapping": {
                "type": "ip"
              }
            }
          }
        ]
      }
    },
    "aliases": {}
  }
}

```

Even using a regular non-dynamic template, Kibana? fails to set the type as 'ip'  
Example: normal template:

```
{
"order": 1000,
"index_patterns": [
  "logstash-*",
  "firewall-*"
],
"mappings": {
  "_default_": {
    "properties": {
      "@timestamp": {
        "type": "date"
      },
      "dest_ip": {
        "type": "ip"
      },
      "dst_ip": {
        "type": "ip"
      },
      "src_ip": {
        "type": "ip"
      },
      "zsrc_ip": {
        "type": "ip"
      },      
      "@version": {
        "type": "keyword"
      }
    }
  }
},
"aliases": {}
}

```

It's inserted into Elastic no worries. And I index some test data into an index where the fieldname does not exist yet.  
I then search for the data, I see the new field name is not known, and Kibana asks me to refresh field list, I refresh the field list, at which point kibana reports the field name eg. 'dst\_ip' as a string.

What am I doing wrong? I want kibana to recognise this as type: 'ip'

---

<div class="post-metadata">

**Author:** ![xavierfacq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xavierfacq/32/8744_2.png) [@xavierfacq](https://discuss.elastic.co/u/xavierfacq)\
**Post date:** [October 30, 2018, 10:05am UTC](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100/6 "2018-10-30T10:05:56Z")

</div>

Sorry but I'm not very aware of the version 6.x and default templating... ☹

---

<div class="post-metadata">

**Author:** ![CamTheMan](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CamTheMan](https://discuss.elastic.co/u/CamTheMan)\
**Post date:** [October 31, 2018, 11:07pm UTC](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100/7 "2018-10-31T23:07:37Z")

</div>

I got the template working.  
This was the template I used:

```
PUT /_template/mylogstash
{
"order": 1000,
"index_patterns": [
  "logstash-*",
  "docker-*",
  "syslog-*",
  "ironport-*",
  "firewall-*"
],
"mappings": {
  "doc": {
    "dynamic": "true",
    "properties": {
      "host": {
        "type": "keyword"
      },
      "program": {
        "type": "keyword"
      },
      "logsource": {
        "type": "keyword"
      },
      "bytes": {
        "type": "integer"
      },
      "bytes_in": {
        "type": "integer"
      },
      "bytes_out": {
        "type": "integer"
      },
      "dest_port": {
        "type": "integer"
      },
      "src_port": {
        "type": "integer"
      },
      "dest_ip": {
        "type": "ip"
      },
      "src_ip": {
        "type": "ip"
      },
      "geoip": {
        "properties": {
          "ip": {
            "type": "ip"
          },
          "location": {
            "type": "geo_point"
          },
          "latitude": {
            "type": "half_float"
          },
          "longitude": {
            "type": "half_float"
          }
        }
      }
    }
  }
}
}

```

Not sure if i'm going to re-index my data, as the indexes roll over daily. Just the 'conflict' in Kibana makes me sad.

---

<div class="post-metadata">

**Author:** ![CamTheMan](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CamTheMan](https://discuss.elastic.co/u/CamTheMan)\
**Post date:** [November 19, 2018, 2:29am UTC](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100/8 "2018-11-19T02:29:56Z")

</div>

I actually had to fix some things regarding 'host.keyword' disappearing and not 'aggreagatable' which i had to fix with an another template update, documented here:

> [@Changing the analyzer type fields are no longer aggregatable](https://discuss.elastic.co/t/changing-the-analyzer-type-fields-are-no-longer-aggregatable/156554):
>
> Hi All, I changed the index mapping for my index, and now I can't perform visualisations on the fields! Example index template: PUT /\_template/my\_logstash { "order": 1000, "index\_patterns": ["logstash-\*", "docker-\*", "syslog-\*", "ironport-\*", "radius-\*", "firewall-\*"], "settings": { "analysis": { "analyzer": { "keyword\_lowercase": { "tokenizer": "keyword", "filter": ["lowercase"] }, "whitespace\_lowercase": { "tokenizer": "whitespace", "filter…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 17, 2018, 2:29am UTC](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100/9 "2018-12-17T02:29:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
