# Kv variable with multiple types

**URL:** <https://discuss.elastic.co/t/kv-variable-with-multiple-types/42102>\
**Category:** Logstash\
**Created:** [February 18, 2016, 5:42am UTC](https://discuss.elastic.co/t/kv-variable-with-multiple-types/42102 "2016-02-18T05:42:38Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![angelsmile](https://avatars.discourse-cdn.com/v4/letter/a/e19b73/32.png) [@angelsmile](https://discuss.elastic.co/u/angelsmile)\
**Post date:** [February 18, 2016, 5:42am UTC](https://discuss.elastic.co/t/kv-variable-with-multiple-types/42102/1 "2016-02-18T05:42:38Z")

</div>

Hi,

I have used kv filter in logstash configuration file. A variable "jobname" created by kv originally had the type of integer according to its value,

"jobname=40000"

but now in some documents the values of the variable are in type of string

"jobname=c148a"

Elasticsearch complains this and drops all the documents with the value of "jobname" in string. How can I solve this issue?

Thanks,

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 18, 2016, 6:24am UTC](https://discuss.elastic.co/t/kv-variable-with-multiple-types/42102/2 "2016-02-18T06:24:59Z")

</div>

You will need to convert the field to a string in LS, then it will always treated as such in ES.

---

<div class="post-metadata">

**Author:** ![angelsmile](https://avatars.discourse-cdn.com/v4/letter/a/e19b73/32.png) [@angelsmile](https://discuss.elastic.co/u/angelsmile)\
**Post date:** [February 18, 2016, 10:07am UTC](https://discuss.elastic.co/t/kv-variable-with-multiple-types/42102/3 "2016-02-18T10:07:44Z")

</div>

Thanks for your response Mark. I have converted the field to a string in LS but ES is still dropping the documents. Maybe because in ES the field is still integer? How can I change the type of the field in ES?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 18, 2016, 7:16pm UTC](https://discuss.elastic.co/t/kv-variable-with-multiple-types/42102/4 "2016-02-18T19:16:52Z")

</div>

You will need to drop the index and recreate it so that it has the correct mapping applied to the field, you cannot convert it in an existing index.

---

<div class="post-metadata">

**Author:** ![angelsmile](https://avatars.discourse-cdn.com/v4/letter/a/e19b73/32.png) [@angelsmile](https://discuss.elastic.co/u/angelsmile)\
**Post date:** [February 19, 2016, 12:51am UTC](https://discuss.elastic.co/t/kv-variable-with-multiple-types/42102/5 "2016-02-19T00:51:37Z")

</div>

Thanks for the information. I will try that. In the new index created today the type of the field has become string and the error disappeared.

---

<div class="post-metadata">

**Author:** ![angelsmile](https://avatars.discourse-cdn.com/v4/letter/a/e19b73/32.png) [@angelsmile](https://discuss.elastic.co/u/angelsmile)\
**Post date:** [February 24, 2016, 5:19am UTC](https://discuss.elastic.co/t/kv-variable-with-multiple-types/42102/6 "2016-02-24T05:19:28Z")

</div>

I've got a new problem now: same field in a log has multiple values with multiple types. Is there anyway to apply kv filter to such logs?

For example, in the following log, fields such as jobfs\_local and mem have different values with different types. elasticsearch/logstash complain if I apply kv filter to such logs:

**02/24/2016 15:54:30;0080;walltime\_for\_job: Resources:select=4:ncpus=16:mpiprocs=16:mem=34359738368:job\_tags=normal:jobfs\_local=104857600,mpiprocs=64,uuid=6eadfce3-481f-43d4-983c-74a0e4ff82be,ncpus=64,nodect=4,jobprio=8092.4810,jobfs\_local=419430400b,HT=0,wd=0,mem=137438953472b,jobfs=419430400b,walltime=00:20:00,place=free**

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 24, 2016, 6:31pm UTC](https://discuss.elastic.co/t/kv-variable-with-multiple-types/42102/7 "2016-02-24T18:31:43Z")

</div>

As I mentioned before - You will need to convert the field to a string in LS, then it will always treated as such in ES.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:09am UTC](https://discuss.elastic.co/t/kv-variable-with-multiple-types/42102/8 "2017-07-06T05:09:52Z")

</div>


