# FileBeat file type is not correctly set system-wide

**URL:** <https://discuss.elastic.co/t/filebeat-file-type-is-not-correctly-set-system-wide/275794>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 14, 2021, 6:41am UTC](https://discuss.elastic.co/t/filebeat-file-type-is-not-correctly-set-system-wide/275794 "2021-06-14T06:41:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kwoxer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kwoxer/32/74809_2.png) [@kwoxer](https://discuss.elastic.co/u/kwoxer)\
**Post date:** [June 14, 2021, 6:41am UTC](https://discuss.elastic.co/t/filebeat-file-type-is-not-correctly-set-system-wide/275794/1 "2021-06-14T06:41:44Z")

</div>

I have trouble to set the file type of field via filebeat.

Somehow the file type is `keyword` in the` Index Pattern` overview  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/d/edcd46ee72a20308442838063db215e7200fda2c.png)

But in `mappings` tab of the `Index management` it says  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bb642fd40818b095cc4787de1eb025fd0784b27d.png)

What is the type of the field now?

This is how I set the long type in `filebeat`:

```auto
  - dissect:
      tokenizer: '"%{licence}","%{system}","%{part}","%{uses|integer}","%{users|integer}"'
      field: "message"
      target_prefix: "data"

```

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [June 14, 2021, 8:25am UTC](https://discuss.elastic.co/t/filebeat-file-type-is-not-correctly-set-system-wide/275794/2 "2021-06-14T08:25:55Z")

</div>

Hi @kwoxer!

I'm not sure if what you see is correct. Since you set the type to `integer` why it is `long` in the mapping? Maybe something goes wrong?

If we verify that Filebeat sets the mapping properly then we can ask for help in Kibana's forum to check what goes wrong with the index-template. But for now let's verify that what is set by Filebeat is correct.

---

<div class="post-metadata">

**Author:** ![kwoxer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kwoxer/32/74809_2.png) [@kwoxer](https://discuss.elastic.co/u/kwoxer)\
**Post date:** [June 14, 2021, 10:16am UTC](https://discuss.elastic.co/t/filebeat-file-type-is-not-correctly-set-system-wide/275794/3 "2021-06-14T10:16:54Z")

</div>

It seemed to be a caching issue.

Now it says

![image](https://us1.discourse-cdn.com/elastic/original/3X/9/0/90215744e6732b2a1e88f218a1f64af55e58b543.png)

So solution is to wait an hour.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2021, 12:17pm UTC](https://discuss.elastic.co/t/filebeat-file-type-is-not-correctly-set-system-wide/275794/4 "2021-07-12T12:17:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
