# How do i convert my existing logstash grok to match with Elastic Common Schema ECS data type

**URL:** <https://discuss.elastic.co/t/how-do-i-convert-my-existing-logstash-grok-to-match-with-elastic-common-schema-ecs-data-type/192171>\
**Category:** Logstash\
**Tags:** ecs-elastic-common-schema\
**Created:** [July 25, 2019, 6:05am UTC](https://discuss.elastic.co/t/how-do-i-convert-my-existing-logstash-grok-to-match-with-elastic-common-schema-ecs-data-type/192171 "2019-07-25T06:05:19Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![webmat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webmat/32/46191_2.png) [@webmat](https://discuss.elastic.co/u/webmat)\
**Post date:** [November 29, 2019, 3:47pm UTC](https://discuss.elastic.co/t/how-do-i-convert-my-existing-logstash-grok-to-match-with-elastic-common-schema-ecs-data-type/192171/4 "2019-11-29T15:47:26Z")

</div>

Yes Badger is correct, these are datatypes.

Check out this post, for a good start at parsing web logs: [Parsing URL with Logstash (using ECS fields) nested!](https://discuss.elastic.co/t/parsing-url-with-logstash-using-ecs-fields-nested/209953)

---

_[View the full topic](https://discuss.elastic.co/t/how-do-i-convert-my-existing-logstash-grok-to-match-with-elastic-common-schema-ecs-data-type/192171)._
