# Extracting a value(Integer) from the logs and plotting it in kibana VS time

**URL:** <https://discuss.elastic.co/t/extracting-a-value-integer-from-the-logs-and-plotting-it-in-kibana-vs-time/39861>\
**Category:** Logstash\
**Created:** [January 22, 2016, 10:19am UTC](https://discuss.elastic.co/t/extracting-a-value-integer-from-the-logs-and-plotting-it-in-kibana-vs-time/39861 "2016-01-22T10:19:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shivam\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shivam_singh/32/4225_2.png) [@shivam\_singh](https://discuss.elastic.co/u/shivam_singh)\
**Post date:** [January 22, 2016, 10:19am UTC](https://discuss.elastic.co/t/extracting-a-value-integer-from-the-logs-and-plotting-it-in-kibana-vs-time/39861/1 "2016-01-22T10:19:16Z")

</div>

Hi,

I am tying to parse logs using grok filters.

if [type]=="xyz"{  
multiline {  
pattern =\> "^%{SYSLOG5424SD} "  
negate =\> true  
what =\> previous  
}  
grok{  
match =\> {  
"message" =\> ["%{SYSLOG5424SD:Timestamp} [%{LOGLEVEL:Severity}] [helium[.]grid[.]env[.]%{WORD:DataLakeLoader}[$]] [com.ca.ri.hercules.dataloader.push.PushSchedulerTimerTask] % **{NUMBER:Event\_Loaded:int}**",  
"%{SYSLOG5424SD:Timestamp} [%{LOGLEVEL:Severity}] %{GREEDYDATA:Message}"  
]  
}  
}  
}

As u can see in my grok filter i am parsing an int value using **{NUMBER:Event\_Loaded:int}** , but when i try to plot this Event\_loaded on a line graph VS time, it is not coming up under the number field on y axis.

Need help

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 22, 2016, 11:59am UTC](https://discuss.elastic.co/t/extracting-a-value-integer-from-the-logs-and-plotting-it-in-kibana-vs-time/39861/2 "2016-01-22T11:59:11Z")

</div>

That's most likely because the `Event_Loaded` field has already been mapped as a string in ES, so your change to have grok emit an integer field doesn't make a difference (an index's field mappings can't be changed after the fact). You either have to reindex or wait until tomorrow when a new index is created.

---

<div class="post-metadata">

**Author:** ![shivam\_singh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shivam_singh/32/4225_2.png) [@shivam\_singh](https://discuss.elastic.co/u/shivam_singh)\
**Post date:** [January 22, 2016, 12:06pm UTC](https://discuss.elastic.co/t/extracting-a-value-integer-from-the-logs-and-plotting-it-in-kibana-vs-time/39861/3 "2016-01-22T12:06:46Z")

</div>

Thanks for the reply!!

"You either have to reindex or wait until tomorrow when a new index is created"  
logstash is running for more than 10 days, with the same configuration.

Also, is their any difference between {NUMBER:Event\_Loaded:int} and {NUMBER:Event\_Loaded:float} with respect to kibana UI number field. What i mean is will it not show as number if I use float instead of int??

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 22, 2016, 12:12pm UTC](https://discuss.elastic.co/t/extracting-a-value-integer-from-the-logs-and-plotting-it-in-kibana-vs-time/39861/4 "2016-01-22T12:12:30Z")

</div>

> logstash is running for more than 10 days, with the same configuration.

Hmm, okay. What does the mapping look like in ES (use the get mapping API)? Can you show an example message? And have you reloaded the field list in Kibana?

> Also, is their any difference between {NUMBER:Event\_Loaded:int} and {NUMBER:Event\_Loaded:float} with respect to kibana UI number field. What i mean is will it not show as number if I use float instead of int??

I don't think it matters.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:14am UTC](https://discuss.elastic.co/t/extracting-a-value-integer-from-the-logs-and-plotting-it-in-kibana-vs-time/39861/5 "2017-07-06T05:14:44Z")

</div>


