How to map to ES type "ip" properly?

(jahlives) #1


use logstash+elasticsearch+kibana all in version 6.4 on a Centos7 with latest updates

I have an issue with a mapping for ip-type in elasticsearch. I read that this cannot be done via convert in logstash and has to be applied by a logstash template to elasticsearch.
So I set a mapping in the respective template file like


and restarted logstash.
After checking the index today I saw that clientip is still considered text by elasticsearch


So how can it be achieved that this field is considered of type ip?
Or is this any issue because that field formerly was of type string before I wanted to change it to ip?

Thanks for any help


(system) #2

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.