# Elasticsearch - JSON date payload being converted to type long, cannot use for range queries

**URL:** <https://discuss.elastic.co/t/elasticsearch-json-date-payload-being-converted-to-type-long-cannot-use-for-range-queries/119552>\
**Category:** Elasticsearch\
**Created:** [February 12, 2018, 9:36pm UTC](https://discuss.elastic.co/t/elasticsearch-json-date-payload-being-converted-to-type-long-cannot-use-for-range-queries/119552 "2018-02-12T21:36:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![BruceLeroy](https://avatars.discourse-cdn.com/v4/letter/b/8edcca/32.png) [@BruceLeroy](https://discuss.elastic.co/u/BruceLeroy)\
**Post date:** [February 12, 2018, 9:36pm UTC](https://discuss.elastic.co/t/elasticsearch-json-date-payload-being-converted-to-type-long-cannot-use-for-range-queries/119552/1 "2018-02-12T21:36:43Z")

</div>

Hi!

I create a mapping like:  
\> {

> ```
> "test3" : {
> "mappings" : {
> "doc" : {
> "properties" : {
> "alerttype" : {
> "type" : "text"
> },
> "devicename" : {
> "type" : "text"
> },
> "eventtime" : {
> "type" : "date"
> },
> "text" : {
> "type" : "text"
> },
> "timestamp" : {
> "type" : "date",
> "format" : "epoch_second"
> }
> }
> }
> }
> }
> }
> 
> ```

But after my payload is posted, the mapping shows a second "timestamp" entry, that looks like:

> },  
> "timestamp" : {  
> "type" : "long"  
> }

At the bottom of the mapping, my original mapping still exists:

> ```
> },
> "timestamp" : {
> "type" : "date",
> "format" : "epoch_second"
> }
> 
> ```

So, when I try a query like:  
{"query":{"range":{"timestamp":{"from":"1518468475","lte":"now"}}}}

Looking at the above query, I don't suspect this can work. Maybe I'll try using actual dates. Perhaps some conversion will happen on the backend?

But my main point here - how do I force my json epoch seconds to stay as a type 'date'? Or do I just not worry about it, and use them as long ints?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 12, 2018, 10:05pm UTC](https://discuss.elastic.co/t/elasticsearch-json-date-payload-being-converted-to-type-long-cannot-use-for-range-queries/119552/2 "2018-02-12T22:05:26Z")

</div>

This can not happen. I mean the way you described it can not happen. You should see rejection or something.

Could you provide a full recreation script as described in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will help to better understand what you are doing. Please, try to keep the example as simple as possible.

---

<div class="post-metadata">

**Author:** ![BruceLeroy](https://avatars.discourse-cdn.com/v4/letter/b/8edcca/32.png) [@BruceLeroy](https://discuss.elastic.co/u/BruceLeroy)\
**Post date:** [February 12, 2018, 10:23pm UTC](https://discuss.elastic.co/t/elasticsearch-json-date-payload-being-converted-to-type-long-cannot-use-for-range-queries/119552/3 "2018-02-12T22:23:07Z")

</div>

Thanks for helping! I'll try to follow formatting.

So I create an index with the following mapping like this:

```
`PUT /test3
{
  "test3" : {
    "mappings" : {
      "doc" : {
        "properties" : {
          "alerttype" : {
            "type" : "text"
          },
          "devicename" : {
            "type" : "text"
          },
          "eventtime" : {
            "type" : "date"
          },
          "text" : {
            "type" : "text"
          },
          "timestamp" : {
            "type" : "date",
            "format" : "epoch_second"
          }
        }
      }
    }
  }
}`

```

Then my application does the following:

> ```
> POST /test3/doc/
> {
> "alertinfo": {
> "alerttype": "Showoff-Soft-Trigger",
> "deviceRef": {
> "refName": "Lab-7070",
> "refObjectType": "device_vs_camera_ip",
> "refUid": "161272cc-62e7-4fc4-8b13-ab3daf0b9645",
> "refVsomUid": "1d0ac9ec-e357-47e5-b9c8-978705b9f0dc"
> },
> "devicename": "Lab-7070",
> "eventtime": "Feb 12 at 2018 3:23:36 PM ",
> "text": "Holy crap Batman!!!<br>On Feb 12 at 2018 3:23:36 PM , we received an alert from location: Main Office, with severity: INFO, triggered by device name: Lab-7070.<br>Alert data: Showoff-Soft-Trigger<br>",
> "timestamp": 1518470616
> }
> }
> 
> ```

After that POST - the return from Elasticsearch is:

> {  
> "\_index": "test3",  
> "\_type": "doc",  
> "\_id": "s2nmi2EBkXZxUv2r1RM8",  
> "\_version": 1,  
> "result": "created",  
> "\_shards": {  
> "total": 2,  
> "successful": 1,  
> "failed": 0  
> },  
> "\_seq\_no": 0,  
> "\_primary\_term": 1  
> }

When I pull the mapping after the first document is posted my mapping looks like this:

> ```
> {
> "test3": {
> "mappings": {
> "doc": {
> "properties": {
> "alertinfo": {
> "properties": {
> "alerttype": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> }
> }
> },
> "deviceRef": {
> "properties": {
> "refName": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> }
> }
> },
> "refObjectType": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> }
> }
> },
> "refUid": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> }
> }
> },
> "refVsomUid": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> }
> }
> }
> }
> },
> "devicename": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> }
> }
> },
> "eventtime": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> }
> }
> },
> "text": {
> "type": "text",
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> }
> }
> },
> "timestamp": {
> "type": "long"
> }
> }
> },
> "alerttype": {
> "type": "text"
> },
> "devicename": {
> "type": "text"
> },
> "eventtime": {
> "type": "date"
> },
> "text": {
> "type": "text"
> },
> "timestamp": {
> "type": "date",
> "format": "epoch_second"
> }
> }
> }
> }
> }
> }`
> 
> ```

---

<div class="post-metadata">

**Author:** ![BruceLeroy](https://avatars.discourse-cdn.com/v4/letter/b/8edcca/32.png) [@BruceLeroy](https://discuss.elastic.co/u/BruceLeroy)\
**Post date:** [February 12, 2018, 10:23pm UTC](https://discuss.elastic.co/t/elasticsearch-json-date-payload-being-converted-to-type-long-cannot-use-for-range-queries/119552/4 "2018-02-12T22:23:47Z")

</div>

omg. Apparently I cannot figure out your formatting tools here or my browser hates this site ☹

---

<div class="post-metadata">

**Author:** ![BruceLeroy](https://avatars.discourse-cdn.com/v4/letter/b/8edcca/32.png) [@BruceLeroy](https://discuss.elastic.co/u/BruceLeroy)\
**Post date:** [February 13, 2018, 12:30am UTC](https://discuss.elastic.co/t/elasticsearch-json-date-payload-being-converted-to-type-long-cannot-use-for-range-queries/119552/5 "2018-02-13T00:30:07Z")

</div>

Just in case - I pulled a pcap from the machine posting my json payload to the elasticsearch instance. I was thinking maybe the key was malformatted. Or maybe a spelling mistake I'm not seeing.

Here is the copy/paste:

```
`{"alertinfo": {"devicename": "Lab-7070", "eventtime": "Feb 12 at 2018 6:26:04 PM ", "alerttype": "Showoff-Soft-Trigger", "text": "Holy crap Batman!!!<br>On Feb 12 at 2018 6:26:04 PM , we received an alert from location: Main Office, with severity: INFO, triggered by device name: Lab-7070.<br>Alert data: Showoff-Soft-Trigger<br>", "time": 1518481565, "deviceRef": {"refUid": "161272cc-62e7-4fc4-8b13-ab3daf0b9645", "refVsomUid": "1d0ac9ec-e357-47e5-b9c8-978705b9f0dc", "refObjectType": "device_vs_camera_ip", "refName": "Lab-7070"}}}`
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [February 13, 2018, 10:39am UTC](https://discuss.elastic.co/t/elasticsearch-json-date-payload-being-converted-to-type-long-cannot-use-for-range-queries/119552/6 "2018-02-13T10:39:09Z")

</div>

Don't use the citation icon but only the code icon.

In your example you defined a mapping for a field named `timestamp` but then you provided a document with a field named `alertinfo.timestamp` which is not known by elasticsearch and then is created as a number.

---

<div class="post-metadata">

**Author:** ![BruceLeroy](https://avatars.discourse-cdn.com/v4/letter/b/8edcca/32.png) [@BruceLeroy](https://discuss.elastic.co/u/BruceLeroy)\
**Post date:** [February 13, 2018, 11:33am UTC](https://discuss.elastic.co/t/elasticsearch-json-date-payload-being-converted-to-type-long-cannot-use-for-range-queries/119552/7 "2018-02-13T11:33:28Z")

</div>

> [@BruceLeroy](#):
>
> {  
> "test3": {  
> "mappings": {  
> "doc": {  
> "properties": {  
> "alertinfo": {  
> "properties": {  
> "alerttype": {  
> "type": "text",  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "deviceRef": {  
> "properties": {  
> "refName": {  
> "type": "text",  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "refObjectType": {  
> "type": "text",  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "refUid": {  
> "type": "text",  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "refVsomUid": {  
> "type": "text",  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> }  
> }  
> },  
> "devicename": {  
> "type": "text",  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "eventtime": {  
> "type": "text",  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "text": {  
> "type": "text",  
> "fields": {  
> "keyword": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> },  
> "timestamp": {  
> "type": "long"  
> }  
> }  
> },  
> "alerttype": {  
> "type": "text"  
> },  
> "devicename": {  
> "type": "text"  
> },  
> "eventtime": {  
> "type": "date"  
> },  
> "text": {  
> "type": "text"  
> },  
> "timestamp": {  
> "type": "date",  
> "format": "epoch\_second"  
> }  
> }  
> }  
> }  
> }  
> }

AH! So mappings need to be nested in cases of nested objects. So I can use the mapping that was dynamically generated as a formatting guide.

Assuming that's correct, thank you!!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 13, 2018, 11:33am UTC](https://discuss.elastic.co/t/elasticsearch-json-date-payload-being-converted-to-type-long-cannot-use-for-range-queries/119552/8 "2018-03-13T11:33:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
