# Kibana 4.0.1 displays number field as string/text - unable to aggregate

**URL:** <https://discuss.elastic.co/t/kibana-4-0-1-displays-number-field-as-string-text-unable-to-aggregate/22811>\
**Category:** Elasticsearch\
**Created:** [March 23, 2015, 5:38am UTC](https://discuss.elastic.co/t/kibana-4-0-1-displays-number-field-as-string-text-unable-to-aggregate/22811 "2015-03-23T05:38:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aaran\_Stent](https://avatars.discourse-cdn.com/v4/letter/a/2bfe46/32.png) [@Aaran\_Stent](https://discuss.elastic.co/u/Aaran_Stent)\
**Post date:** [March 23, 2015, 5:38am UTC](https://discuss.elastic.co/t/kibana-4-0-1-displays-number-field-as-string-text-unable-to-aggregate/22811/1 "2015-03-23T05:38:15Z")

</div>

I am new to the ELK stack but have spent 2 days now trying o solve this  
rather annoying issue,

Kibana 4 displays my number fields as strings/text fields and I cannot  
perform any max/aggregate calculations on the field.  
Logstash is configured to specifically type/cast/mutate the field to a  
number. Elastic Search sees the fields as numbers. Even the JSON tab in  
Kibana 4 shows it as a number.  
However the rest of Kibana thinks its a string.

I have attached the Tabel view and The JSON view. I assume I should see a  
different icon in the table view? Not the little "t"

Here is what I see on my latest event in Kibana...

[https://lh3.googleusercontent.com/-PoyS22lCz0c/VQ-j0mX9aOI/AAAAAAAAD3s/eh6D\_nh\_rQ4/s1600/JSON\_View.png](https://lh3.googleusercontent.com/-PoyS22lCz0c/VQ-j0mX9aOI/AAAAAAAAD3s/eh6D_nh_rQ4/s1600/JSON_View.png)  
[https://lh6.googleusercontent.com/-j7eNo3hQy9A/VQ-ju8VbU\_I/AAAAAAAAD3k/nIuAUdWvQfA/s1600/Tabel\_view.png](https://lh6.googleusercontent.com/-j7eNo3hQy9A/VQ-ju8VbU_I/AAAAAAAAD3k/nIuAUdWvQfA/s1600/Tabel_view.png)

Some background...

I am consuming logs from an Apache Webserver log that was customised by the  
application developer.  
I use logstash-forwarder (logstash-forwarder-0.3.1-1.x86\_64.rpm) to send  
the logs from the production server to the ELK server.

Here is the logstash-forwader config...

{  
"network": {  
"servers": ["[elkserver.mydomain.net:5000](http://elkserver.mydomain.net:5000)" ],  
"timeout": 15,  
"ssl ca": "/etc/pki/tls/certs/logstash-forwarder.crt"  
},  
"files": [  
{  
"paths": [  
"/var/log/httpd/access\_log"  
],  
"fields": { "type": "webpas-access" }  
}  
]  
}  
And on the ELK server the logstash configuration....

input {  
lumberjack {  
port =\> 5000  
type =\> "webpas-access"  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}  
filter {  
grok {  
type =\> "webpas-access"  
pattern =\> "%{APACHE\_WEBPAS}"  
}  
mutate {  
convert =\> ["delay", "integer"]  
}  
}  
output {  
elasticsearch { host =\> localhost }  
stdout { codec =\> rubydebug }  
}

I added a custom pattern to Logstash. I added type values to the bytes and  
delay fields. "Delay" is the field I am trying to measure and treat as a  
number,

APACHE\_WEBPAS %{IPORHOST:clientip} %{USERNAME:user}  
%{TIMESTAMP\_ISO8601:stamp} "(?:%{WORD:verb} %{NOTSPACE:request}(?:  
HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response}  
(?:%{NUMBER:bytes:int}|-) %{WORD}=%{NUMBER:delay:int} %{WORD}=%{QS:referrer}  
I installed Elastic HQ and checked the indexes...

[https://lh4.googleusercontent.com/-iHiCHU5Q4mc/VQ-mF4FlT3I/AAAAAAAAD34/tYwvsURw\_uQ/s1600/elastic\_index.png](https://lh4.googleusercontent.com/-iHiCHU5Q4mc/VQ-mF4FlT3I/AAAAAAAAD34/tYwvsURw_uQ/s1600/elastic_index.png)

This looks to me like a problem in Kibana but I am very much out of ideas  
on what to do next.

PS. I made changes to the grok pattern 2 days ago but could not work out  
how to reset/refresh the index so I waited overnight for a new index to be  
created. Still no joy.

Please help.

Aaran

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/870605d3-fbd1-4973-b151-e89679b4daa7%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/870605d3-fbd1-4973-b151-e89679b4daa7%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Aaran\_Stent](https://avatars.discourse-cdn.com/v4/letter/a/2bfe46/32.png) [@Aaran\_Stent](https://discuss.elastic.co/u/Aaran_Stent)\
**Post date:** [March 23, 2015, 5:44am UTC](https://discuss.elastic.co/t/kibana-4-0-1-displays-number-field-as-string-text-unable-to-aggregate/22811/2 "2015-03-23T05:44:23Z")

</div>

Ooops I am running....

logstash-1.4.2

And ES...

{  
"status" : 200,  
"name" : "Umar",  
"cluster\_name" : "elasticsearch",  
"version" : {  
"number" : "1.4.4",  
"build\_hash" : "c88f77ffc81301dfa9dfd81ca2232f09588bd512",  
"build\_timestamp" : "2015-02-19T13:05:36Z",  
"build\_snapshot" : false,  
"lucene\_version" : "4.10.3"  
},  
"tagline" : "You Know, for Search"  
}

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/4b4116f7-7cc6-4bb3-8648-6dc062f5eace%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/4b4116f7-7cc6-4bb3-8648-6dc062f5eace%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:24am UTC](https://discuss.elastic.co/t/kibana-4-0-1-displays-number-field-as-string-text-unable-to-aggregate/22811/3 "2017-07-06T00:24:59Z")

</div>


