# Field type doesn't change in logstash

**URL:** <https://discuss.elastic.co/t/field-type-doesnt-change-in-logstash/193038>\
**Category:** Logstash\
**Created:** [July 31, 2019, 5:30am UTC](https://discuss.elastic.co/t/field-type-doesnt-change-in-logstash/193038 "2019-07-31T05:30:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohammad\_hossein\_Taj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammad_hossein_taj/32/44550_2.png) [@Mohammad\_hossein\_Taj](https://discuss.elastic.co/u/Mohammad_hossein_Taj)\
**Post date:** [July 31, 2019, 5:30am UTC](https://discuss.elastic.co/t/field-type-doesnt-change-in-logstash/193038/1 "2019-07-31T05:30:19Z")

</div>

Hi. I want to extract hour from timestamp and I do it but its type is String and I'm trying to change the type of `hour` to integer but it doesn't effect. here is my logstash config:

```auto
input {
  beats {
    client_inactivity_timeout => 1200
    port => 5044
  }
}

filter {
  grok {
    match => {"message" => ["%{NOTSPACE:queueType}, (?<nothing>.{4})(?<part1>.{15})(?<nothing2>.{6}) %{NUMBER:part2}, %{INT:returnedCode}", "%{NOTSPACE:queueType}, (?<nothing>.{4})(?<part1>.{15})(?<nothing2>.{6}) %{NUMBER:part2}, %{INT:returnedCode}", "%{TIMESTAMP_ISO8601:timestamp}%{SPACE}%{LOGLEVEL:loglevel} %{NOTSPACE:webService} @ %{NOTSPACE:function}, System:(?<systemName>.), User:%{NOTSPACE:userId}, StudentIDs:\[%{NUMBER:studentId}\], GroupID:%{GREEDYDATA:groupId}, DocType:%{NOTSPACE:docType}, returned %{INT:returnedCode}", "%{TIMESTAMP_ISO8601:timestamp}%{SPACE}%{LOGLEVEL:loglevel} %{NOTSPACE:webService} @ batchAddOrUpdateStdMetadata, returned %{INT:returnedCode}", "%{TIMESTAMP_ISO8601:timestamp}%{SPACE}%{LOGLEVEL:loglevel} %{NOTSPACE:webService} @ getInternalID, System:(?<systemName>.), resultCode:%{INT:resultCode}, returned %{INT:returnedCode}"]}
  }
  if "_grokparsefailure" in [tags] {
    drop { }
  }
  if [queueType]{
    mutate {
      add_tag => ["taskTerminated"]
      add_field => { 
        "timestamp" => "%{part1} %{part2}"
      }
      remove_field => ["part1", "part2", "nothing", "nothing2"]
    }
  }
  else{
    mutate{
      gsub => ["timestamp", "\,\d{3}$", ""]
      add_tag => ["taskStarted"]
    }
  }
  date {
    match => ["timestamp", "MMM dd HH:mm:ss YYYY", "MMM d HH:mm:ss YYYY", "YYYY-MM-dd HH:mm:ss"]
    timezone => "Asia/Tehran"
    target => "@timestamp"
  }
  mutate {
      add_field => {"[hour]" => "%{+HH}"}
  }
  mutate {
    convert => {
      "hour" => "integer"
    }
  }
  elapsed {
    start_tag => "taskStarted"
    end_tag => "taskTerminated"
    unique_id_field => "returnedCode"
    timeout => 10000
    new_event_on_match => false
  }
}

output {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
    #user => "elastic"
    #password => "changeme"
  }
}

```

thanks for your help.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [July 31, 2019, 9:13am UTC](https://discuss.elastic.co/t/field-type-doesnt-change-in-logstash/193038/2 "2019-07-31T09:13:14Z")

</div>

What does your output event/doc look like?

Use the stdout output with the rubydebug codec  
`stdout { codec => rubydebug }`

---

<div class="post-metadata">

**Author:** ![Mohammad\_hossein\_Taj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammad_hossein_taj/32/44550_2.png) [@Mohammad\_hossein\_Taj](https://discuss.elastic.co/u/Mohammad_hossein_Taj)\
**Post date:** [July 31, 2019, 9:55am UTC](https://discuss.elastic.co/t/field-type-doesnt-change-in-logstash/193038/3 "2019-07-31T09:55:24Z")

</div>

here is one log line output:

```auto
{
            "tags" => [
        [0] "beats_input_codec_plain_applied",
        [1] "taskStarted"
    ],
       "timestamp" => "2019-07-24 23:10:00",
            "hour" => 18,
         "message" => "2019-07-24 23:10:00,395 INFO ir.ac.ut.sdrwebservice.SDRWebService @ getInternalID, System:G, resultCode:1563993063971772, returned -1",
      "@timestamp" => 2019-07-24T18:40:00.000Z,
            "host" => {
        "name" => "localhost.localdomain"
    },
      "webService" => "ir.ac.ut.sdrwebservice.SDRWebService",
             "ecs" => {
        "version" => "1.0.0"
    },
           "agent" => {
            "hostname" => "localhost.localdomain",
                  "id" => "9c56df38-1f41-4972-8cad-e6b84a23b29e",
             "version" => "7.2.0",
                "type" => "filebeat",
        "ephemeral_id" => "2737fa09-4610-4e9d-b838-73c853b3613c"
    },
             "log" => {
          "file" => {
            "path" => "/home/mam23n/Desktop/elk/logs/sdrwebservice.log-2019-07-24"
        },
        "offset" => 1854777
    },
      "resultCode" => "1563993063971772",
        "@version" => "1",
        "loglevel" => "INFO",
    "returnedCode" => "-1",
           "input" => {
        "type" => "log"
    },
      "systemName" => "G"
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 31, 2019, 12:24pm UTC](https://discuss.elastic.co/t/field-type-doesnt-change-in-logstash/193038/4 "2019-07-31T12:24:42Z")

</div>

> [@Mohammad\_hossein\_Taj](#):
>
> "hour" =\> 18,

There are no quotes around the value, so it is an integer in logstash, not a string. If it is a string in elasticsearch you need to modify the [mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-mapping.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2019, 12:24pm UTC](https://discuss.elastic.co/t/field-type-doesnt-change-in-logstash/193038/5 "2019-08-28T12:24:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
