# How to map memory size

**URL:** <https://discuss.elastic.co/t/how-to-map-memory-size/364296>\
**Category:** Elasticsearch\
**Created:** [August 2, 2024, 10:44pm UTC](https://discuss.elastic.co/t/how-to-map-memory-size/364296 "2024-08-02T22:44:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mg77345](https://avatars.discourse-cdn.com/v4/letter/m/df788c/32.png) [@mg77345](https://discuss.elastic.co/u/mg77345)\
**Post date:** [August 2, 2024, 10:44pm UTC](https://discuss.elastic.co/t/how-to-map-memory-size/364296/1 "2024-08-02T22:44:52Z")

</div>

I have fields that are currently being ingested as

`resources_used.vmem: 1028974kb`  
`resources_requested.vmem: 2000000kb`

They are mapped as keyword, but i would like to have the "kb" (or file size denom.) stripped and to store them as a Numeric so i can query. What would be the best way to do this?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [August 3, 2024, 9:59am UTC](https://discuss.elastic.co/t/how-to-map-memory-size/364296/2 "2024-08-03T09:59:50Z")

</div>

Use an ingest pipeline with this processor: [Bytes processor | Elasticsearch Guide [8.14] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/bytes-processor.html)

---

<div class="post-metadata">

**Author:** ![mg77345](https://avatars.discourse-cdn.com/v4/letter/m/df788c/32.png) [@mg77345](https://discuss.elastic.co/u/mg77345)\
**Post date:** [March 7, 2025, 9:24pm UTC](https://discuss.elastic.co/t/how-to-map-memory-size/364296/3 "2025-03-07T21:24:05Z")

</div>

Reviving this topic - i may be misunderstanding how the Bytes processor works. It says:

> Converts a human readable byte value (e.g. 1kb) to its value in bytes (e.g. 1024). If the field is an array of strings, all members of the array will be converted.  
> Supported human readable units are "b", "kb", "mb", "gb", "tb", "pb" case insensitive. An error will occur if the field is not a supported format or resultant value exceeds 2^63.

When running the bytes processor on my field, it seems to have no affect. This is the input on test document:

```auto
...,
"resources_used.mem": "3528kb",
...

```

This is the processor:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4f3f756a9b41df4e526b7bde95d5a6650bbf8c43.png)  
This is the output

```auto
"resources_used.mem": "3528kb",

```

The input type is a string. I can't find any other info on the processor, what the input type needs to be, or what it outputs as.

For reference this is Elastic 8.16.1

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 8, 2025, 2:30pm UTC](https://discuss.elastic.co/t/how-to-map-memory-size/364296/4 "2025-03-08T14:30:53Z")

</div>

> [@mg77345](#):
>
> `"resources_used.mem": "3528kb",`

Go to Dev Tools to Debug

```auto
POST _ingest/pipeline/_simulate
{
  "pipeline": {
    "processors": [
      {
        "bytes": {
          "field": "resources_used.mem",
          "ignore_failure": true
        }
      }
    ]
  },
  "docs": [
    {
      "_source": {
        "resources_used.mem": "3528kb"
        
      }
    },
    {
      "_source": {
        "resources_used": {
          "mem": "3528kb"
        }
      }
    }
  ]
}

```

Note the first fails and the second works... what does the actual source document look like ... Ingest pipeline does not work on `dotted` fields

---

<div class="post-metadata">

**Author:** ![mg77345](https://avatars.discourse-cdn.com/v4/letter/m/df788c/32.png) [@mg77345](https://discuss.elastic.co/u/mg77345)\
**Post date:** [March 10, 2025, 8:46pm UTC](https://discuss.elastic.co/t/how-to-map-memory-size/364296/5 "2025-03-10T20:46:00Z")

</div>

That makes sense. I do some scripting in the ingest pipeline that makes the resources\_used.mem end up that way. That field in the source is "message". I parse through that field in the context using the script below, splitting the string on " " and then "=", appending values to the context (In this case the source would be "resources\_used.mem=3528kb").

I presume the formatting error stems from this... but my painless skill is quite weak.:

```auto
if (ctx['message'].empty){
  String donothing = "";
}else{
  String[] messSplit = ctx['message'].splitOnToken(' ');
  int i = 0;
  for (item in messSplit){
    i = i+1;
    if (item.contains("Resource_List.select")){
      String[] splitItem = /=/.split(item,2);
      String label = splitItem[0];
      String data = splitItem[1];
      ctx[label] = data;
    } else {
      String[] splitItem = item.splitOnToken("=");
      int length = splitItem.length;
      if (length <= 1){
        continue;
      }
      String label = splitItem[0];
      String data = splitItem[1];
      ctx[label] = data;
    }
  }
}

```

`ctx[label]=data` is what outputs `"resources_used.mem":"3528kb"` to the field of the same name, mapped as `text`.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 11, 2025, 4:01am UTC](https://discuss.elastic.co/t/how-to-map-memory-size/364296/6 "2025-03-11T04:01:04Z")

</div>

Now works for both... 🙂

```auto
POST _ingest/pipeline/_simulate
{
  "pipeline": {
    "processors": [
      {
        "dot_expander": {
          "field": "resources_used.mem"
        }
      },
      {
        "bytes": {
          "field": "resources_used.mem",
          "ignore_failure": true
        }
      }
    ]
  },
  "docs": [
    {
      "_source": {
        "resources_used.mem": "3528kb"
      }
    },
    {
      "_source": {
        "resources_used": {
          "mem": "3528kb"
        }
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![mg77345](https://avatars.discourse-cdn.com/v4/letter/m/df788c/32.png) [@mg77345](https://discuss.elastic.co/u/mg77345)\
**Post date:** [March 11, 2025, 6:01pm UTC](https://discuss.elastic.co/t/how-to-map-memory-size/364296/7 "2025-03-11T18:01:17Z")

</div>

That worked. Thanks! Nice to have a processor made for this exact purpose 😁.
