# How do i convert my existing logstash grok to match with Elastic Common Schema ECS data type

**URL:** <https://discuss.elastic.co/t/how-do-i-convert-my-existing-logstash-grok-to-match-with-elastic-common-schema-ecs-data-type/192171>\
**Category:** Logstash\
**Tags:** ecs-elastic-common-schema\
**Created:** [July 25, 2019, 6:05am UTC](https://discuss.elastic.co/t/how-do-i-convert-my-existing-logstash-grok-to-match-with-elastic-common-schema-ecs-data-type/192171 "2019-07-25T06:05:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shiv18](https://avatars.discourse-cdn.com/v4/letter/s/958977/32.png) [@Shiv18](https://discuss.elastic.co/u/Shiv18)\
**Post date:** [July 25, 2019, 6:05am UTC](https://discuss.elastic.co/t/how-do-i-convert-my-existing-logstash-grok-to-match-with-elastic-common-schema-ecs-data-type/192171/1 "2019-07-25T06:05:19Z")

</div>

Hi Team,

Im trying to change the existing grok pattern for several log formats into standard ECS format.

For example,  
ecs url schema says for defining URL, i can use url.full and the type should be 'keyword'.

When i try grok developer tool in kibana it says Unable to find pattern [keyword] in Grok's pattern dictionary, with { property\_name="patterns" & processor\_type="grok" }

Same applies to source.port where type is 'long' and same error.

Reference,  
[https://www.elastic.co/guide/en/ecs/current/ecs-url.html](https://www.elastic.co/guide/en/ecs/current/ecs-url.html)

Can you help on this what am i missing that stops me to convert existing filter into ECS format.

Thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 25, 2019, 1:16pm UTC](https://discuss.elastic.co/t/how-do-i-convert-my-existing-logstash-grok-to-match-with-elastic-common-schema-ecs-data-type/192171/2 "2019-07-25T13:16:35Z")

</div>

I believe that when ECS says the type is keyword it is referring to the mapping in elasticsearch. It has nothing to do with grok, or anything in logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2019, 1:16pm UTC](https://discuss.elastic.co/t/how-do-i-convert-my-existing-logstash-grok-to-match-with-elastic-common-schema-ecs-data-type/192171/3 "2019-08-22T13:16:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![webmat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webmat/32/46191_2.png) [@webmat](https://discuss.elastic.co/u/webmat)\
**Post date:** [November 29, 2019, 3:47pm UTC](https://discuss.elastic.co/t/how-do-i-convert-my-existing-logstash-grok-to-match-with-elastic-common-schema-ecs-data-type/192171/4 "2019-11-29T15:47:26Z")

</div>

Yes Badger is correct, these are datatypes.

Check out this post, for a good start at parsing web logs: [Parsing URL with Logstash (using ECS fields) nested!](https://discuss.elastic.co/t/parsing-url-with-logstash-using-ecs-fields-nested/209953)
