# Interger field showing as string

**URL:** <https://discuss.elastic.co/t/interger-field-showing-as-string/120988>\
**Category:** Logstash\
**Created:** [February 22, 2018, 6:14am UTC](https://discuss.elastic.co/t/interger-field-showing-as-string/120988 "2018-02-22T06:14:30Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![sreejiths](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@sreejiths](https://discuss.elastic.co/u/sreejiths)\
**Post date:** [February 22, 2018, 6:14am UTC](https://discuss.elastic.co/t/interger-field-showing-as-string/120988/1 "2018-02-22T06:14:30Z")

</div>

## GROK

grok {

```
     match => [
        # IOS
        "message", "%{IP:host_nagios}: Nagios-Log device_id=%{WORD:hostname} rtt=%{NUMBER:RTT} avgSD=%{NUMBER:SDLATENCY} avgDS=%

```

{NUMBER:DSLATENCY} syslog\_sev\_level=%{INT:syslog\_sev\_level} syslog\_severity=%{WORD:syslog\_severity} hostgroup=%{WORD:hostgroup} %{GR  
EEDYDATA:log\_message}"  
]  
add\_tag =\> ["Nagios"]  
}  
}

if "Nagios" in [tags]  
{

mutate { convert =\> { "syslog\_sev\_level" =\> "integer" } }  
mutate { convert =\> { "RTT" =\> "float" } }  
mutate { convert =\> { "SDLATENCY" =\> "float" } }  
mutate { convert =\> { "DSLATENCY" =\> "float" } }

```
   }

```

ISSUE:  
The field RTT/SDLATENCY/ DSLATENCY is showing as string in KIBANA .Due to this i am not able to use this parameter to created visulization .. I refeshed/recreated index in Kibana , restarted logstash mutiple times ..Any advice on how to fix ???

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 22, 2018, 6:54am UTC](https://discuss.elastic.co/t/interger-field-showing-as-string/120988/2 "2018-02-22T06:54:41Z")

</div>

What does the JSON document look like, are the fields actually numbers there?

---

<div class="post-metadata">

**Author:** ![sreejiths](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@sreejiths](https://discuss.elastic.co/u/sreejiths)\
**Post date:** [February 22, 2018, 6:58am UTC](https://discuss.elastic.co/t/interger-field-showing-as-string/120988/3 "2018-02-22T06:58:50Z")

</div>

Yes

{  
"\_index": "logstash-2018.02.22",  
"\_type": "nagios",  
"\_id": "AWG8R23JE3k31ptJ2riI",  
"\_score": null,  
"\_source": {  
"syslog\_sev\_level": 6,  
"host\_nagios": "XXXXX",  
**"SDLATENCY": 32.23,**  
"message": "XXXXX: Nagios-Log device\_id=XXXXX rtt=61.92 avgSD=32.23 avgDS=29.69 syslog\_sev\_level=6 syslog\_severity=information hostgroup=WAN service\_description=IPSLA-Latency\_To\_XXXX\_Business time="Thu Feb 22 14:50:53 SGT 2018" msg="OK: RTT=61.92ms avgSD=32.23ms avgDS=29.69ms IP SLA 86001041 # To\_XXXX1\_Business Jitter probe to 202.163.53.182 "",  
"type": "nagios",  
"syslog\_severity": "information",  
"tags": [  
"Nagios"  
],  
"hostname": "XXXXXX",  
"@timestamp": "2018-02-22T06:52:59.651Z",  
**"RTT": 61.92,**  
"port": 43587,  
"@version": "1",  
"host": "10.67.21.164",  
"hostgroup": "WAN",  
"log\_message": " service\_description=IPSLA-Latency\_To\_XXXXX\_Business time="Thu Feb 22 14:50:53 SGT 2018" msg="OK: RTT=61.92ms avgSD=32.23ms avgDS=29.69ms IP SLA 86001041 # To\_XXXXX\_Business Jitter probe toXXXXX "",  
**"DSLATENCY": 29.69**  
},  
"fields": {  
"@timestamp": [  
1519282379651  
]  
},  
"sort": [  
1519282379651  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 22, 2018, 7:09am UTC](https://discuss.elastic.co/t/interger-field-showing-as-string/120988/4 "2018-02-22T07:09:37Z")

</div>

> I refeshed/recreated index in Kibana

Do you mean you deleted the index in ES or just recreated the index pattern in Kibana?

---

<div class="post-metadata">

**Author:** ![sreejiths](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@sreejiths](https://discuss.elastic.co/u/sreejiths)\
**Post date:** [February 22, 2018, 7:10am UTC](https://discuss.elastic.co/t/interger-field-showing-as-string/120988/5 "2018-02-22T07:10:25Z")

</div>

> [@magnusbaeck](#):
>
> recreated the index pattern in Kibana

I meant recreated the index pattern in Kibana..

---

<div class="post-metadata">

**Author:** ![sreejiths](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@sreejiths](https://discuss.elastic.co/u/sreejiths)\
**Post date:** [February 22, 2018, 7:14am UTC](https://discuss.elastic.co/t/interger-field-showing-as-string/120988/6 "2018-02-22T07:14:54Z")

</div>

Running of ELK V5.2

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 22, 2018, 7:28am UTC](https://discuss.elastic.co/t/interger-field-showing-as-string/120988/7 "2018-02-22T07:28:35Z")

</div>

> I meant recreated the index pattern in Kibana..

That doesn't change anything. To change the mapping of an existing field you have to recreate the index itself.

---

<div class="post-metadata">

**Author:** ![sreejiths](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@sreejiths](https://discuss.elastic.co/u/sreejiths)\
**Post date:** [February 22, 2018, 7:36am UTC](https://discuss.elastic.co/t/interger-field-showing-as-string/120988/8 "2018-02-22T07:36:33Z")

</div>

You are right ..Thanks for help ..Fixed the issue ..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2018, 7:36am UTC](https://discuss.elastic.co/t/interger-field-showing-as-string/120988/9 "2018-03-22T07:36:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
