# Is it necessary to change the field data type?

**URL:** <https://discuss.elastic.co/t/is-it-necessary-to-change-the-field-data-type/27440>\
**Category:** Elasticsearch\
**Created:** [August 15, 2015, 9:28am UTC](https://discuss.elastic.co/t/is-it-necessary-to-change-the-field-data-type/27440 "2015-08-15T09:28:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [August 15, 2015, 9:28am UTC](https://discuss.elastic.co/t/is-it-necessary-to-change-the-field-data-type/27440/1 "2015-08-15T09:28:00Z")

</div>

Hi Experts,

I have a very basic question , I am using ELK stack to show syslog data in Kibana. My plan is not to mutate or modified any field at the logstash level. Here I have a question, can i treat ES as a traditional databases like SQL where data types plays an important role or is it necessary to change the data type of the field ? I have seen if I did not modify data type in LS , ES will pick all the fields as string .

Thanks  
VG

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 15, 2015, 9:33am UTC](https://discuss.elastic.co/t/is-it-necessary-to-change-the-field-data-type/27440/2 "2015-08-15T09:33:50Z")

</div>

Depends on your use case, but I'd certainly define things.

---

<div class="post-metadata">

**Author:** ![vikas\_gopal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikas_gopal/32/47661_2.png) [@vikas\_gopal](https://discuss.elastic.co/u/vikas_gopal)\
**Post date:** [August 15, 2015, 9:38am UTC](https://discuss.elastic.co/t/is-it-necessary-to-change-the-field-data-type/27440/3 "2015-08-15T09:38:20Z")

</div>

Thanks Mark ,

My Use case would be like , maximum firewall byte in or byte out , top 10 destination IP ,Top destination Ports , Top source port etc

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 15, 2015, 9:39am UTC](https://discuss.elastic.co/t/is-it-necessary-to-change-the-field-data-type/27440/4 "2015-08-15T09:39:44Z")

</div>

Then yes, you should map those fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:55pm UTC](https://discuss.elastic.co/t/is-it-necessary-to-change-the-field-data-type/27440/5 "2017-07-05T23:55:39Z")

</div>


