# How to set field type to "ip"?

**URL:** <https://discuss.elastic.co/t/how-to-set-field-type-to-ip/24659>\
**Category:** Logstash\
**Created:** [June 30, 2015, 7:23pm UTC](https://discuss.elastic.co/t/how-to-set-field-type-to-ip/24659 "2015-06-30T19:23:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![naisanza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/naisanza/32/44808_2.png) [@naisanza](https://discuss.elastic.co/u/naisanza)\
**Post date:** [June 30, 2015, 7:23pm UTC](https://discuss.elastic.co/t/how-to-set-field-type-to-ip/24659/1 "2015-06-30T19:23:33Z")

</div>

I've used the date filter to set a target field as a date type. I don't see a filter to set a target field type to "ip".

I'm looking to do this so I can use the IPv4 Range Aggregation, but  
haven't been able to find the documentation on how I can map a field to  
type: ip, without needing a custom template.

And also, I've been trying to find out how you will deal with a log that contains multiple ip fields.

Logstash isn't able to deal with multiple geoip fields without a  
custom template. I'm hoping this isn't the same case with ip fields.

An example event would be:

`63.88.73.59,104.197.28.247,104.197.28.0,-,,-,Google Inc.,Mountain View,CA,US,Google Inc.,Mountain View,CA,US`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 30, 2015, 8:38pm UTC](https://discuss.elastic.co/t/how-to-set-field-type-to-ip/24659/2 "2015-06-30T20:38:53Z")

</div>

I think you need a custom index template for this. But really, you'll want to have that sooner or later anyway.

---

<div class="post-metadata">

**Author:** ![naisanza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/naisanza/32/44808_2.png) [@naisanza](https://discuss.elastic.co/u/naisanza)\
**Post date:** [June 30, 2015, 9:07pm UTC](https://discuss.elastic.co/t/how-to-set-field-type-to-ip/24659/3 "2015-06-30T21:07:44Z")

</div>

You're right. It's not part of the default dynamic mapping, and will need to be done manually.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:35am UTC](https://discuss.elastic.co/t/how-to-set-field-type-to-ip/24659/4 "2017-07-06T05:35:56Z")

</div>


