# Field type in logstash not applied to the elastic index

**URL:** <https://discuss.elastic.co/t/field-type-in-logstash-not-applied-to-the-elastic-index/180761>\
**Category:** Logstash\
**Created:** [May 13, 2019, 9:00am UTC](https://discuss.elastic.co/t/field-type-in-logstash-not-applied-to-the-elastic-index/180761 "2019-05-13T09:00:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shawcs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shawcs/32/45490_2.png) [@Shawcs](https://discuss.elastic.co/u/Shawcs)\
**Post date:** [May 13, 2019, 9:00am UTC](https://discuss.elastic.co/t/field-type-in-logstash-not-applied-to-the-elastic-index/180761/1 "2019-05-13T09:00:06Z")

</div>

Hi,

I have an issue with some of my field type.

In logstash I convert some fields to be in integer:

```
			mutate {
				add_field => {
					"api_transaction_duration" => "%{[json][transactionElement][duration]}"
					"api_transaction_bytesSent" => "%{[json][transactionElement][protocolInfo][http][bytesSent]}"
					"api_transaction_bytesReceived" => "%{[json][transactionElement][protocolInfo][http][bytesReceived]}"
					"api_transaction_remote_hostname" => "%{[json][transactionElement][protocolInfo][http][remoteName]}"
					"api_transaction_remote_address" => "%{[json][transactionElement][protocolInfo][http][remoteAddr]}"
					"api_transaction_remote_port" => "%{[json][transactionElement][protocolInfo][http][remotePort]}"
					"api_transaction_local_instance_address" => "%{[json][transactionElement][protocolInfo][http][localAddr]}"
					"api_transaction_local_port" => "%{[json][transactionElement][protocolInfo][http][localPort]}"
					tags => "transactionElement"
				}
				convert => {
					"api_transaction_duration" => "integer"
					"api_transaction_bytesSent" => "integer"
					"api_transaction_bytesReceived" => "integer"
				}
			}

```

In my index in kibana I have the following value:

 ![byte%20index](https://us1.discourse-cdn.com/elastic/original/3X/d/d/dd1a0f307e5f049d3b3c8df828324ef78dc85997.png)

and as you can see field type are not editable

 ![not%20changeable%20index%20type](https://us1.discourse-cdn.com/elastic/original/3X/8/4/84092f11c0e68e8158a4b7b1c051d58f8d775c11.png)

Any ideas ?

Thanks !

Alex

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 13, 2019, 2:07pm UTC](https://discuss.elastic.co/t/field-type-in-logstash-not-applied-to-the-elastic-index/180761/2 "2019-05-13T14:07:59Z")

</div>

"Decoration" (the application of common options like add\_field) occurs after all the mutate functions are applied. That means the fields do not exist when convert executes. Split this into two mutate filters.

---

<div class="post-metadata">

**Author:** ![Shawcs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shawcs/32/45490_2.png) [@Shawcs](https://discuss.elastic.co/u/Shawcs)\
**Post date:** [May 13, 2019, 2:49pm UTC](https://discuss.elastic.co/t/field-type-in-logstash-not-applied-to-the-elastic-index/180761/3 "2019-05-13T14:49:25Z")

</div>

Ok clear and quick. thanks !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2019, 2:49pm UTC](https://discuss.elastic.co/t/field-type-in-logstash-not-applied-to-the-elastic-index/180761/4 "2019-06-10T14:49:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
