# How to get Number type by using Grok

**URL:** <https://discuss.elastic.co/t/how-to-get-number-type-by-using-grok/150084>\
**Category:** Logstash\
**Created:** [September 26, 2018, 8:21pm UTC](https://discuss.elastic.co/t/how-to-get-number-type-by-using-grok/150084 "2018-09-26T20:21:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![saad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saad/32/17214_2.png) [@saad](https://discuss.elastic.co/u/saad)\
**Post date:** [September 26, 2018, 8:21pm UTC](https://discuss.elastic.co/t/how-to-get-number-type-by-using-grok/150084/1 "2018-09-26T20:21:24Z")

</div>

Hi,

I have this field below  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/3/43dfc67d8e8151c34954c162c9646eb45c8ac7f8.png)  
and I want to use grok to get the number 427 at the end and add it to new field as type number

I did the following  
grok {  
match =\> { "name" =\> "%{GREEDYDATA}device: %{NUMBER:concurrentUsers}"}  
}

but still get the new field named concurrentUsers as string concurrentUsers  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/6/76b85dfca5f71cc49f7f0e94cdcf207d2f69606c.png)

How can I make Number type??

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 26, 2018, 9:02pm UTC](https://discuss.elastic.co/t/how-to-get-number-type-by-using-grok/150084/2 "2018-09-26T21:02:46Z")

</div>

Quoting the grok filter documentation:

> Optionally you can add a data type conversion to your grok pattern. By default all semantics are saved as strings. If you wish to convert a semantic’s data type, for example change a string to an integer then suffix it with the target data type. For example `%{NUMBER:num:int}` which converts the `num` semantic from a string to an integer. Currently the only supported conversions are `int` and `float` .

Keep in mind that the data type of a field in an index can't ever change, so you have to reindex your current data or just start over.

---

<div class="post-metadata">

**Author:** ![saad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saad/32/17214_2.png) [@saad](https://discuss.elastic.co/u/saad)\
**Post date:** [September 27, 2018, 2:27pm UTC](https://discuss.elastic.co/t/how-to-get-number-type-by-using-grok/150084/3 "2018-09-27T14:27:34Z")

</div>

I did the change in conf file with %{NUMBER:concurrentUsers:int} and still the field string cause I think the index in elasticsearch is mentioning string datatype. How can I reindex the data?

---

<div class="post-metadata">

**Author:** ![saad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saad/32/17214_2.png) [@saad](https://discuss.elastic.co/u/saad)\
**Post date:** [September 27, 2018, 3:36pm UTC](https://discuss.elastic.co/t/how-to-get-number-type-by-using-grok/150084/4 "2018-09-27T15:36:32Z")

</div>

I created new index and removed the old one and now its working successfully  
thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2018, 3:36pm UTC](https://discuss.elastic.co/t/how-to-get-number-type-by-using-grok/150084/5 "2018-10-25T15:36:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
