# Issue with CAST

**URL:** <https://discuss.elastic.co/t/issue-with-cast/229104>\
**Category:** Logstash\
**Created:** [April 21, 2020, 5:16pm UTC](https://discuss.elastic.co/t/issue-with-cast/229104 "2020-04-21T17:16:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![JeremyP](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Post date:** [April 21, 2020, 5:16pm UTC](https://discuss.elastic.co/t/issue-with-cast/229104/1 "2020-04-21T17:16:43Z")

</div>

Hello,

I have an IP address in my database which I'm trying to extract and ingest into Elastic. I originally did a CAST on this statement (required as logstash did not like the source format).

```
input {
    jdbc {
        jdbc_connection_string => "jdbc:postgresql://192.168.65.240:5432/db"
        jdbc_user => "nexpose"
        jdbc_password => "mysecretpassword"
        jdbc_driver_class => "org.postgresql.Driver"
        jdbc_default_timezone => "America/Toronto"
        statement => "SELECT
        A.asset_id,
        A.host_name,
        CAST(ip_address AS text),

```

And my IP addresses are appended with a /32 which is not what I want. I do not want the CIDR as these are always host IP addresses and not ever networks.

From playing around with CAST directly on the SQL server, I need to do a CAST(ip\_address AS inet), however, this does not appear to be supported on logstash.... error below....

> [WARN] 2020-04-21 13:12:22.417 [[main]\<jdbc] jdbc - Exception when executing JDBC query {:exception=\>#\<Sequel::DatabaseError: Java::OrgLogstash::MissingConverterException: Missing Converter handling for full class name=org.postgresql.util.PGobject, simple name=PGobject\>

Any suggestions on how I can parse this without the CIDR?

Thanks!

---

<div class="post-metadata">

**Author:** ![JeremyP](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@JeremyP](https://discuss.elastic.co/u/JeremyP)\
**Post date:** [April 21, 2020, 5:47pm UTC](https://discuss.elastic.co/t/issue-with-cast/229104/2 "2020-04-21T17:47:48Z")

</div>

I left it as text and added a gsub filter to remove the /32 which works. Just wondering if this is the best option?

```
  mutate {
    gsub => [
      "ip_address", "/32", ""
    ]
  }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2020, 5:48pm UTC](https://discuss.elastic.co/t/issue-with-cast/229104/3 "2020-05-19T17:48:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
