# Fortinet module \`sentdelta\` and \`rcvddelta\` field type is not number

**URL:** <https://discuss.elastic.co/t/fortinet-module-sentdelta-and-rcvddelta-field-type-is-not-number/382240>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [September 26, 2025, 6:10am UTC](https://discuss.elastic.co/t/fortinet-module-sentdelta-and-rcvddelta-field-type-is-not-number/382240 "2025-09-26T06:10:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![hylowaker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hylowaker/32/145169_2.png) [@hylowaker](https://discuss.elastic.co/u/hylowaker)\
**Post date:** [September 26, 2025, 6:10am UTC](https://discuss.elastic.co/t/fortinet-module-sentdelta-and-rcvddelta-field-type-is-not-number/382240/1 "2025-09-26T06:10:27Z")

</div>

In the Filebeat `fortinet` module, the fields `fortinet.firewall.sentdelta` and `fortinet.firewall.rcvddelta` are set as _Keyword_ type.

I am not sure if it is intended or not, but I think these fields should be _Long_ type to support aggregation.

> <https://github.com/elastic/beats/blob/ff13c7f43f89ba83832d5acc38e74514f776976f/x-pack/filebeat/module/fortinet/firewall/_meta/fields.yml#L1598-L1601>

> <https://github.com/elastic/beats/blob/ff13c7f43f89ba83832d5acc38e74514f776976f/x-pack/filebeat/module/fortinet/firewall/_meta/fields.yml#L1483-L1486>

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 26, 2025, 1:31pm UTC](https://discuss.elastic.co/t/fortinet-module-sentdelta-and-rcvddelta-field-type-is-not-number/382240/2 "2025-09-26T13:31:56Z")

</div>

Hello and welcome,

You will need to open an Issue on the Beats repository in Github, [this one](https://github.com/elastic/beats).

This was already fixed on the Elastic Agent integration, but the fix was not replicated to the Filebeat module for some reason.

On the Integration this was fixed on April, with this PR: [[fortinet\_fortigate] Add deltabytes field, ensure rcvddelta and sentdelta fields are integers by taylor-swanson · Pull Request #13668 · elastic/integrations · GitHub](https://github.com/elastic/integrations/pull/13668)
