# GROK NUMBER field type creating field as string and not number

**URL:** <https://discuss.elastic.co/t/grok-number-field-type-creating-field-as-string-and-not-number/98906>\
**Category:** Logstash\
**Created:** [August 30, 2017, 6:49pm UTC](https://discuss.elastic.co/t/grok-number-field-type-creating-field-as-string-and-not-number/98906 "2017-08-30T18:49:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![cchooks2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cchooks2/32/21987_2.png) [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Post date:** [August 30, 2017, 6:49pm UTC](https://discuss.elastic.co/t/grok-number-field-type-creating-field-as-string-and-not-number/98906/1 "2017-08-30T18:49:47Z")

</div>

I have a created a GROK pattern to parse out a "number" field on an access log, but when i look at the data in the kibana management console it is showing these fields as a string.

Any thoughts on this?

GROK pattern:

%{IP:client\_ip}%{SPACE}%{DATA:client\_port}%{SPACE}%{DATA:ident}%{SPACE}[%{EVENT\_TS:event\_ts}]%{SPACE}"%{WORD:method}%{SPACE}%{URIPATHPARAM:uri\_path}%{SPACE}%{GREEDYDATA:version}"%{SPACE}%{NUMBER:status}%{SPACE}%{DATA:bytes}%{SPACE}%{NUMBER:request\_time\_in\_secs}%{SPACE}%{NUMBER:keep\_alives}%{SPACE}"%{GREEDYDATA:referer}"%{SPACE}"%{GREEDYDATA:user\_agent}"%{SPACE}"%{GREEDYDATA:contenttype}"%{SPACE}%{GREEDYDATA:jsession\_id}%{SPACE}%{IP:x\_clientip}%{SPACE} **%{NUMBER:response\_time\_in\_secs}**

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 30, 2017, 7:51pm UTC](https://discuss.elastic.co/t/grok-number-field-type-creating-field-as-string-and-not-number/98906/2 "2017-08-30T19:51:14Z")

</div>

This is expected. To get a number field, see this paragraph in the grok filter docs:

> Optionally you can add a data type conversion to your grok pattern. By default all semantics are saved as strings. If you wish to convert a semantic’s data type, for example change a string to an integer then suffix it with the target data type. For example %{NUMBER:num:int} which converts the num semantic from a string to an integer. Currently the only supported conversions are int and float.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2017, 7:51pm UTC](https://discuss.elastic.co/t/grok-number-field-type-creating-field-as-string-and-not-number/98906/3 "2017-09-27T19:51:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
