# KV-Pairs and type conversion

**URL:** https://discuss.elastic.co/t/kv-pairs-and-type-conversion/100046
**Category:** Logstash
**Created:** [September 11, 2017, 12:17pm UTC](https://discuss.elastic.co/t/kv-pairs-and-type-conversion/100046 "2017-09-11T12:17:45Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![desete](https://avatars.discourse-cdn.com/v4/letter/d/5daacb/32.png) [@desete](https://discuss.elastic.co/u/desete)
#### Post date: [September 11, 2017, 12:17pm UTC](https://discuss.elastic.co/t/kv-pairs-and-type-conversion/100046/1 "2017-09-11T12:17:45Z")

</div>

Hello,

I have an input like this

`<14>1 2017-09-11T14:00:27.582+02:00 SECRETHOSTNAME RT_FLOW - RT_FLOW_SESSION_CREATE [junos@2636.1.1.1.2.40 source-address="1.1.1.1" source-port="53780" destination-address="2.2.2.2" destination-port="389" service-name="junos-ldap" nat-source-address="3.3.3.3" nat-source-port="53780" nat-destination-address="4.4.4.4" nat-destination-port="389" src-nat-rule-type="N/A" src-nat-rule-name="N/A" dst-nat-rule-type="N/A" dst-nat-rule-name="N/A" protocol-id="6" policy-name="newNetAccess" source-zone-name="BLUB" destination-zone-name="BLAA" session-id-32="28173" username="N/A" roles="N/A" packet-incoming-interface="reth0.999" application="UNKNOWN" nested-application="UNKNOWN" encrypted="UNKNOWN"]`

I managed to extract all fields I need with kv-pairs filter.  
But... everything seems to be a string, so I cannot draw and things like that as ip-addresses are not ip-addresses.  
I searched a lot now, but I can't find a solution.

this is what I am doing now and my question is how can I determine for each pair what type of data it is?

```
if "RT_FLOW" in [message] {
        grok {
        match => ["message","%{GREEDYDATA:kvpairs}"]
  }

kv {
   source => "kvpairs"
}

```

thank you very much in advance

//desete

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 11, 2017, 6:28pm UTC](https://discuss.elastic.co/t/kv-pairs-and-type-conversion/100046/2 "2017-09-11T18:28:17Z")

</div>

> But... everything seems to be a string, so I cannot draw and things like that as ip-addresses are not ip-addresses.

Whether a field is mapped as an IP address depends on the mappings of the ES index. You can use index templates to explicitly map fields as e.g. IP addresses.

You can use a mutate filter and its `convert` option to convert string fields in Logstash to numbers but even though you have fields containing numbers (like ports) they're not numbers that you'd typically process numerically (like compute sums or averages) so it's not terribly important.

---

<div class="post-metadata">

### Author: ![desete](https://avatars.discourse-cdn.com/v4/letter/d/5daacb/32.png) [@desete](https://discuss.elastic.co/u/desete)
#### Post date: [September 12, 2017, 7:31pm UTC](https://discuss.elastic.co/t/kv-pairs-and-type-conversion/100046/3 "2017-09-12T19:31:48Z")

</div>

thanks Magnus.

> You can use index templates to explicitly map fields as e.g. IP addresses.

any recommended reading?

thx and br  
//seb

---

<div class="post-metadata">

### Author: ![kmsasidhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmsasidhar/32/21838_2.png) [@kmsasidhar](https://discuss.elastic.co/u/kmsasidhar)
#### Post date: [September 13, 2017, 3:54am UTC](https://discuss.elastic.co/t/kv-pairs-and-type-conversion/100046/4 "2017-09-13T03:54:55Z")

</div>

[https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html)

[https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html)

[https://www.elastic.co/guide/en/elasticsearch/reference/current/ip.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/ip.html)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 11, 2017, 3:55am UTC](https://discuss.elastic.co/t/kv-pairs-and-type-conversion/100046/5 "2017-10-11T03:55:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
