# Elasticsearch Module - Slowlog field mapping

**URL:** <https://discuss.elastic.co/t/elasticsearch-module-slowlog-field-mapping/211522>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 11, 2019, 9:16pm UTC](https://discuss.elastic.co/t/elasticsearch-module-slowlog-field-mapping/211522 "2019-12-11T21:16:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndrewMcQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewmcq/32/23131_2.png) [@AndrewMcQ](https://discuss.elastic.co/u/AndrewMcQ)\
**Post date:** [December 11, 2019, 9:16pm UTC](https://discuss.elastic.co/t/elasticsearch-module-slowlog-field-mapping/211522/1 "2019-12-11T21:16:11Z")

</div>

Hi -

While working on enabling the Elasticsearch module, specifically the slowlog fileset, I ran into a challenge when I went to use the data in the index to build visualizations. Some of the fields that get pulled out of the slowlog are being set as "keyword" type, when they would obviously benefit from being set to "long" or some other numerical data type.

The field definitions are here: [https://github.com/elastic/beats/blob/master/filebeat/module/elasticsearch/slowlog/\_meta/fields.yml](https://github.com/elastic/beats/blob/master/filebeat/module/elasticsearch/slowlog/_meta/fields.yml)

And, a few of the fields that would seem to be better as an actual number are:

elasticsearch.slowlog.took\_millis (renamed to event.duration in 7.x)  
elasticsearch.slowlog.total\_hits  
elasticsearch.slowlog.total\_shards

And semi-related, the slowlog emits the "took" value in what appears to be a human-readable format (with "s" for seconds, "m" for minutes, etc).

Is there any reason why these fields are set as "keyword"? What is the process to request that these be switched over? .. or, is there something I can do to override this on our end?

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [December 12, 2019, 10:35am UTC](https://discuss.elastic.co/t/elasticsearch-module-slowlog-field-mapping/211522/2 "2019-12-12T10:35:15Z")

</div>

Hi @AndrewMcQ!

you can propose this change in a Github issue.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2020, 10:46am UTC](https://discuss.elastic.co/t/elasticsearch-module-slowlog-field-mapping/211522/3 "2020-01-09T10:46:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
