# Logstash convert string field to number

**URL:** <https://discuss.elastic.co/t/logstash-convert-string-field-to-number/112023>\
**Category:** Logstash\
**Created:** [December 15, 2017, 5:21pm UTC](https://discuss.elastic.co/t/logstash-convert-string-field-to-number/112023 "2017-12-15T17:21:49Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ravikumar\_G](https://avatars.discourse-cdn.com/v4/letter/r/71e660/32.png) [@Ravikumar\_G](https://discuss.elastic.co/u/Ravikumar_G)\
**Post date:** [December 15, 2017, 5:21pm UTC](https://discuss.elastic.co/t/logstash-convert-string-field-to-number/112023/1 "2017-12-15T17:21:49Z")

</div>

Hi I'm trying to ingest durationUs=786 into numeric value in elasticsearch but no luck tried using mutate  
but the events still shows as string so any help would be great  
if [type] == "pump" {  
grok {  
match =\> {  
"message" =\> [  
"%{NOTSPACE:timestamp} %{NOTSPACE:field\_1} %{NOTSPACE:field\_2} %  
{GREEDYDATA:raw\_data}", "%{NOTSPACE:timestamp},%{GREEDYDATA:raw\_data}"  
]  
}  
tag\_on\_failure =\> ["fail\_in\_grok"]  
}  
date {  
match =\> ["timestamp","yyyy-MM-dd'T'HH:mm:ss.SSSSSSZ"]  
}  
if [raw\_data] {  
kv {  
field\_split =\> ","  
source =\> "raw\_data"  
transform\_key =\> "lowercase"  
}  
}

```
   if "fail_in_grok" not in [tags] {
                                       mutate {
                          remove_field => ["timestamp"]
         }

    }

    mutate {
               convert => {
                           "durationus" => "integer"
             }
                     }

 }

```

Log Event : 2017-12-15T17:18:34.637368+00:00 ccdn-ats-tk-vbn-01 pump1[30512]: Level=Debug, subSystem=CONTENT, xmt: header in response trace-id=b0e44c2f-7050-45f7-8d39-afe870f14b0e;parent-id=0x15cf7c280bdb79b6;span-id=0x1137dafdbabfe9e8  
2017-12-15T17:18:34.641027+00:00 ccdn-ats-tk-vbn-01 pump1[30512]: Level=Debug, subSystem=CONTENT, Event=Span\_Success, span: trace-id=f8e41d0c-1f84-4112-b488-c0ee75530bef span-id=570631895973423548 parent-id=-7840287596547113655#012span-name=fetchRngAsync.[http://mpeg4origin.sys](http://mpeg4origin.sys)..net/t6qam10/PFOX0022824020170718/1500331485928/Superhuman\_105\_HD\_VOD8\_AUTH\_mezz\_4QAM.ts.bytes=1270771712-1272119295 app-name=./pump1 start-time=1513358314 span-duration=23471 span-http-code=206 span-success=true

 ![11 PM](https://us1.discourse-cdn.com/elastic/original/3X/e/d/ed153490805925347899645ed18b13e926e52319.png)

---

<div class="post-metadata">

**Author:** ![Kurt\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kurt_s/32/17755_2.png) [@Kurt\_S](https://discuss.elastic.co/u/Kurt_S)\
**Post date:** [December 18, 2017, 12:19am UTC](https://discuss.elastic.co/t/logstash-convert-string-field-to-number/112023/2 "2017-12-18T00:19:45Z")

</div>

I would lock the type in the [elastic search mapping](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-templates.html). In the properties section of the mapping template, I would put something like:

```
  ..."properties": {
    "durationus": {
      "type": "integer"
    },...
```

---

<div class="post-metadata">

**Author:** ![Ravikumar\_G](https://avatars.discourse-cdn.com/v4/letter/r/71e660/32.png) [@Ravikumar\_G](https://discuss.elastic.co/u/Ravikumar_G)\
**Post date:** [December 18, 2017, 1:53am UTC](https://discuss.elastic.co/t/logstash-convert-string-field-to-number/112023/3 "2017-12-18T01:53:58Z")

</div>

Thannks Very much will test tomrrow

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 18, 2017, 6:23am UTC](https://discuss.elastic.co/t/logstash-convert-string-field-to-number/112023/4 "2017-12-18T06:23:07Z")

</div>

Keep in mind that the mapping of an existing field can't be changed, so even if you've updated your Logstash configuration to produce documents with an integer `durationus` field that won't make a difference in ES if that field has already been mapped as a string.

---

<div class="post-metadata">

**Author:** ![Ravikumar\_G](https://avatars.discourse-cdn.com/v4/letter/r/71e660/32.png) [@Ravikumar\_G](https://discuss.elastic.co/u/Ravikumar_G)\
**Post date:** [December 18, 2017, 1:55pm UTC](https://discuss.elastic.co/t/logstash-convert-string-field-to-number/112023/5 "2017-12-18T13:55:35Z")

</div>

Deleting old index is only option ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 18, 2017, 1:56pm UTC](https://discuss.elastic.co/t/logstash-convert-string-field-to-number/112023/6 "2017-12-18T13:56:38Z")

</div>

You can copy the data to a new index, delete the old index, and copy the data back.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2018, 2:04pm UTC](https://discuss.elastic.co/t/logstash-convert-string-field-to-number/112023/7 "2018-01-15T14:04:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
