# How to assign a new field a certain type and value?

**URL:** <https://discuss.elastic.co/t/how-to-assign-a-new-field-a-certain-type-and-value/34148>\
**Category:** Logstash\
**Created:** [November 9, 2015, 12:45pm UTC](https://discuss.elastic.co/t/how-to-assign-a-new-field-a-certain-type-and-value/34148 "2015-11-09T12:45:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![marv](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@marv](https://discuss.elastic.co/u/marv)\
**Post date:** [November 9, 2015, 12:45pm UTC](https://discuss.elastic.co/t/how-to-assign-a-new-field-a-certain-type-and-value/34148/1 "2015-11-09T12:45:25Z")

</div>

Hi,

I´m using the grok filter to process logs. Everything works fine but I can´t find a solution for the following problem:

I need to extract a numerical value out of my log files. There are two ways they appear in the logs. Firstly, as a numerical value from 2-x, which is pretty easy to extract. Secondly they appear as "one", which is a string right. Here is what I´d like to do. When the pattern matches, I want to add a new field with a certain type (integer) and assign this field a certain value (1). I tried the mutate statement with  
add\_field =\> { somefield =\> 1 } and serveral other possibilites e.g. the convert statement. But still when I take a look at the field in Kibana the type still is string.  
It is important for me because I want to visualize Logs via Kibana and at the moment I can only process log messages that contain values from 2-x.

Thank you guys  
Marv

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 9, 2015, 7:45pm UTC](https://discuss.elastic.co/t/how-to-assign-a-new-field-a-certain-type-and-value/34148/2 "2015-11-09T19:45:35Z")

</div>

Perhaps surprisingly, `mutate { add_field => { somefield => 1 } }` doesn't actually add an integer field:

```
$ cat test.config
input { stdin { } }
output { stdout { codec => rubydebug } }
filter {
  mutate {
    add_field => { "somefield" => 1 }
  }
}
$ echo 'foo' | /opt/logstash/bin/logstash -f test.config
Logstash startup completed
{
       "message" => "foo",
      "@version" => "1",
    "@timestamp" => "2015-11-09T19:45:06.364Z",
          "host" => "hallonet",
     "somefield" => "1"
}
Logstash shutdown completed

```

Use a second mutate filter to convert the field.

---

<div class="post-metadata">

**Author:** ![marv](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@marv](https://discuss.elastic.co/u/marv)\
**Post date:** [November 13, 2015, 7:32am UTC](https://discuss.elastic.co/t/how-to-assign-a-new-field-a-certain-type-and-value/34148/3 "2015-11-13T07:32:12Z")

</div>

Thanks Magnus,  
your proposition actually worked. It worked the following.

filter{  
mutate { add\_field =\> {"somefield" =\> 1} }  
mutate { convert =\> ["somefield","float] }  
}

Update:  
Perhaps less suprisingly  
mutate {convert =\> ["somefield","interger"]}

also works 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:18am UTC](https://discuss.elastic.co/t/how-to-assign-a-new-field-a-certain-type-and-value/34148/4 "2017-07-06T05:18:36Z")

</div>


