# Field turns into text in elasticsearch after being mapped as INT in grok and being mutated into integer

**URL:** <https://discuss.elastic.co/t/field-turns-into-text-in-elasticsearch-after-being-mapped-as-int-in-grok-and-being-mutated-into-integer/112381>\
**Category:** Logstash\
**Created:** [December 19, 2017, 8:55am UTC](https://discuss.elastic.co/t/field-turns-into-text-in-elasticsearch-after-being-mapped-as-int-in-grok-and-being-mutated-into-integer/112381 "2017-12-19T08:55:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![yishain11](https://avatars.discourse-cdn.com/v4/letter/y/df705f/32.png) [@yishain11](https://discuss.elastic.co/u/yishain11)\
**Post date:** [December 19, 2017, 8:55am UTC](https://discuss.elastic.co/t/field-turns-into-text-in-elasticsearch-after-being-mapped-as-int-in-grok-and-being-mutated-into-integer/112381/1 "2017-12-19T08:55:11Z")

</div>

Hi everyone!  
I have logstash filter (grok) and I matched certain phrases as INT. When I open the mapping in kibana, I see that elasticsearch classified the INT as text. Why is that?  
How do I change it? I want to make number based aggregations (like average), so I have to save these values as a number.

Log example:  
`13/11/2017 10:31:15:664 - [logReaderThread] WARN LogReader - Parser has a lag of [1984] seconds above a pre-defined threshold.`

Grok filter:

```
%{DATE:date} %{TIME:time} - \[%{DATA:stream_name}\] %{LOGLEVEL:log_level}%{GREEDYDATA:msg}(?<=lag\sof\s\[)%{INT:lag_sec}

```

And the mapping:

```
"lag_sec": {
            "type": "text",
            "fields": {
              "keyword": {
                "type": "keyword",
                "ignore_above": 256
              }
            }
          }

```

And it's the same for every INT in the grok filter.  
Any ideas?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [December 19, 2017, 9:20am UTC](https://discuss.elastic.co/t/field-turns-into-text-in-elasticsearch-after-being-mapped-as-int-in-grok-and-being-mutated-into-integer/112381/2 "2017-12-19T09:20:44Z")

</div>

Question moved to #logstash.

You are just telling GROK that the field you are expecting is looking like a `INT`. But Grok extracts Strings by default.

You can use a [mutate filter](https://www.elastic.co/guide/en/logstash/6.1/plugins-filters-mutate.html) to change your field to an integer:

```auto
filter {
  mutate {
    convert => { "lag_sec" => "integer" }
  }
}

```

---

<div class="post-metadata">

**Author:** ![yishain11](https://avatars.discourse-cdn.com/v4/letter/y/df705f/32.png) [@yishain11](https://discuss.elastic.co/u/yishain11)\
**Post date:** [December 19, 2017, 10:41am UTC](https://discuss.elastic.co/t/field-turns-into-text-in-elasticsearch-after-being-mapped-as-int-in-grok-and-being-mutated-into-integer/112381/3 "2017-12-19T10:41:10Z")

</div>

Hi, Thanks for the answer!  
I did what you suggested (used mutate on the fields I want to convert from text to int), I tested the new logstash config (because I use mutate on many fields, not only "lag\_sec") and the test was OK, I started kibana and refreshed the index, but when I check the mapping:

```
      "insertsNum": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "lag_sec": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "documents_loaded__time_ms": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      },
      "fetchTime_ms": {
        "type": "text",
        "fields": {
          "keyword": {
            "type": "keyword",
            "ignore_above": 256
          }
        }
      }

```

etc...

The mutate filter:

```
mutate {
        convert =>{
                    "lag_sec" => "integer"
                    "parsedNum" => "integer"
                    "total_parsed_time_ms" => "integer"
                      .
                      .
                      .
         }
}

```

Plus, I need to add that I use the 6.1 elastic stack.  
Plus 2: Weirdly enough, there is one field that does get saved in elasticsearch as long.

So what am I doing wrong?

---

<div class="post-metadata">

**Author:** ![yishain11](https://avatars.discourse-cdn.com/v4/letter/y/df705f/32.png) [@yishain11](https://discuss.elastic.co/u/yishain11)\
**Post date:** [December 21, 2017, 7:28am UTC](https://discuss.elastic.co/t/field-turns-into-text-in-elasticsearch-after-being-mapped-as-int-in-grok-and-being-mutated-into-integer/112381/4 "2017-12-21T07:28:12Z")

</div>

anyone?

---

<div class="post-metadata">

**Author:** ![yishain11](https://avatars.discourse-cdn.com/v4/letter/y/df705f/32.png) [@yishain11](https://discuss.elastic.co/u/yishain11)\
**Post date:** [December 21, 2017, 8:12am UTC](https://discuss.elastic.co/t/field-turns-into-text-in-elasticsearch-after-being-mapped-as-int-in-grok-and-being-mutated-into-integer/112381/5 "2017-12-21T08:12:38Z")

</div>

I solved it, and this is what I did for anyone who encounter the same thing:  
The mutate filter didn't work, but we can make grok save a field not as string (as it does by default) just by adding :FORMAT after the semantic.  
For example:

```
grok{
    match => {"message" => "%{INT:someNum}"} ===> is a string
}

grok{
    match => {"message" => "%{INT:someNum:int}"} ===> is a int
}

```

That did the trick for me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2018, 8:13am UTC](https://discuss.elastic.co/t/field-turns-into-text-in-elasticsearch-after-being-mapped-as-int-in-grok-and-being-mutated-into-integer/112381/6 "2018-01-18T08:13:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
