# Correct src\_ip field datatype to 'ip'

**URL:** <https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100>\
**Category:** Elasticsearch\
**Created:** [October 26, 2018, 5:47am UTC](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100 "2018-10-26T05:47:02Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![CamTheMan](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CamTheMan](https://discuss.elastic.co/u/CamTheMan)\
**Post date:** [November 19, 2018, 2:29am UTC](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100/8 "2018-11-19T02:29:56Z")

</div>

I actually had to fix some things regarding 'host.keyword' disappearing and not 'aggreagatable' which i had to fix with an another template update, documented here:

> [@Changing the analyzer type fields are no longer aggregatable](https://discuss.elastic.co/t/changing-the-analyzer-type-fields-are-no-longer-aggregatable/156554):
>
> Hi All, I changed the index mapping for my index, and now I can't perform visualisations on the fields! Example index template: PUT /\_template/my\_logstash { "order": 1000, "index\_patterns": ["logstash-\*", "docker-\*", "syslog-\*", "ironport-\*", "radius-\*", "firewall-\*"], "settings": { "analysis": { "analyzer": { "keyword\_lowercase": { "tokenizer": "keyword", "filter": ["lowercase"] }, "whitespace\_lowercase": { "tokenizer": "whitespace", "filter…

---

_[View the full topic](https://discuss.elastic.co/t/correct-src-ip-field-datatype-to-ip/154100)._
