# How to make something like an IP address be stored in an array of integers instead of a string

**URL:** https://discuss.elastic.co/t/how-to-make-something-like-an-ip-address-be-stored-in-an-array-of-integers-instead-of-a-string/76444
**Category:** Logstash
**Created:** [February 24, 2017, 8:06pm UTC](https://discuss.elastic.co/t/how-to-make-something-like-an-ip-address-be-stored-in-an-array-of-integers-instead-of-a-string/76444 "2017-02-24T20:06:44Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Ben\_Hoffman](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Ben\_Hoffman](https://discuss.elastic.co/u/Ben_Hoffman)
#### Post date: [February 24, 2017, 8:06pm UTC](https://discuss.elastic.co/t/how-to-make-something-like-an-ip-address-be-stored-in-an-array-of-integers-instead-of-a-string/76444/1 "2017-02-24T20:06:44Z")

</div>

So I want to basically do a string split at the " . " in one of my outputs from a log file (It is an IP address). Is there any way to do this with a Logstash filter? It would make the requests from my application to my server generate much less garbage when I call the server.

---

<div class="post-metadata">

### Author: ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)
#### Post date: [February 27, 2017, 8:37pm UTC](https://discuss.elastic.co/t/how-to-make-something-like-an-ip-address-be-stored-in-an-array-of-integers-instead-of-a-string/76444/2 "2017-02-27T20:37:17Z")

</div>

This configuration:

```auto
input { stdin {} }

filter {
  mutate { split => { "message" => "." } }
  mutate { convert => { "message" => "integer" } }
}

output { stdout { codec => rubydebug } }

```

Will result in this output, if fed `172.19.73.1` as STDIN:

```auto
172.19.73.1
{
    "@timestamp" => 2017-02-27T20:35:00.726Z,
      "@version" => "1",
          "host" => "REDACTED.local",
       "message" => [
        [0] 172,
        [1] 19,
        [2] 73,
        [3] 1
    ]
}

```

---

<div class="post-metadata">

### Author: ![Ben\_Hoffman](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Ben\_Hoffman](https://discuss.elastic.co/u/Ben_Hoffman)
#### Post date: [February 28, 2017, 3:32pm UTC](https://discuss.elastic.co/t/how-to-make-something-like-an-ip-address-be-stored-in-an-array-of-integers-instead-of-a-string/76444/3 "2017-02-28T15:32:51Z")

</div>

That worked perfectly, thanks a lot!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 28, 2017, 3:32pm UTC](https://discuss.elastic.co/t/how-to-make-something-like-an-ip-address-be-stored-in-an-array-of-integers-instead-of-a-string/76444/4 "2017-03-28T15:32:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
