# Logstash grok plugin is considering number as text

**URL:** <https://discuss.elastic.co/t/logstash-grok-plugin-is-considering-number-as-text/185558>\
**Category:** Logstash\
**Created:** [June 13, 2019, 7:05am UTC](https://discuss.elastic.co/t/logstash-grok-plugin-is-considering-number-as-text/185558 "2019-06-13T07:05:26Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![prataprajasekhar](https://avatars.discourse-cdn.com/v4/letter/p/e19b73/32.png) [@prataprajasekhar](https://discuss.elastic.co/u/prataprajasekhar)\
**Post date:** [June 13, 2019, 7:05am UTC](https://discuss.elastic.co/t/logstash-grok-plugin-is-considering-number-as-text/185558/1 "2019-06-13T07:05:26Z")

</div>

Dear Team,

We are using logstash that will receive logs from filebeat for sending tomcat access logs. We have configured grok to map message's column data to respective fields in elasticsearch. We have configured response as NUMBER in grok but the field is appearing as string in index mappings.

Even we tried mutate but no luck. Can someone please help?

Here is the configuration -

input {  
beats {  
port =\> "5044"  
tags =\> ["logstash-access-log"]  
}  
}  
filter {

mutate {  
convert =\> { "response" =\> "integer" }  
}

fingerprint {  
source =\> "message"  
target =\> "[@metadata][fingerprint]"  
method =\> "MURMUR3"  
}

```
grok {
    match => { "message" => "%{IP:client} %{USER:IDENT} %{USER:AUTH} \[%{HTTPDATE:DATEANDTIME}\] \"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}\" %{NUMBER:status} %{NUMBER:bytes} %{WORD:verb} %{NUMBER:response}"}
}

```

}  
output {  
if "logstash-access-log" in [tags]{  
elasticsearch {  
hosts =\> ["MYPOCHOST:9200"]  
index =\> "index-accesslogs-%{+YYYY.MM.dd}"  
document\_id =\> "%{[@metadata][fingerprint]}"  
user =\> XXXXXX  
password =\> XXXXXXX  
}  
}  
#stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![Vikash\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_singh1/32/42119_2.png) [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Post date:** [June 13, 2019, 7:06am UTC](https://discuss.elastic.co/t/logstash-grok-plugin-is-considering-number-as-text/185558/2 "2019-06-13T07:06:40Z")

</div>

Can we get some sample of your logs to test the grok?

---

<div class="post-metadata">

**Author:** ![prataprajasekhar](https://avatars.discourse-cdn.com/v4/letter/p/e19b73/32.png) [@prataprajasekhar](https://discuss.elastic.co/u/prataprajasekhar)\
**Post date:** [June 13, 2019, 7:43am UTC](https://discuss.elastic.co/t/logstash-grok-plugin-is-considering-number-as-text/185558/3 "2019-06-13T07:43:34Z")

</div>

dear vikas, thanks for looking into this. Here is the sample lines of log file for your reference -

100.120.77.247 - - [13/Jun/2019:06:25:09 +0000] "GET /specialcase/v2/experiment/balance?lid=989 HTTP/1.1" 200 246 GET 32  
100.120.77.177 - - [13/Jun/2019:06:25:09 +0000] "PUT /specialcase/v2/experiment/preflight?uatype=Android&uaversion=4.12.3 HTTP/1.1" 200 46 PUT 4  
100.120.77.241 - - [13/Jun/2019:06:25:09 +0000] "GET /specialcase/v2/sudogroup/l7R0i2toK62qS5t6Mmglzv HTTP/1.1" 200 1095 GET 22  
100.120.77.141 - - [13/Jun/2019:06:25:09 +0000] "PUT /specialcase/v2/experiment/lockAmount/1pk1srora8u9nuvz9d999cv7wk7ic49h HTTP/1.1" 202 - PUT 0  
100.120.77.161 - - [13/Jun/2019:06:25:10 +0000] "GET /specialcase/v2/analytics/sudogroup/[http://admin.specialcase.com:3000/admin/sudogroups/uwaUt0EUifkEy3y4Iy0RaT/threshold](http://admin.specialcase.com:3000/admin/sudogroups/uwaUt0EUifkEy3y4Iy0RaT/threshold) HTTP/1.1" 500 1866 GET 2  
100.120.77.221 - - [13/Jun/2019:06:25:10 +0000] "GET /specialcase/v2/sudogroup/l7R0i2toK62qS5t6Mmglzv/trays?details=true HTTP/1.1" 200 16154 GET 105  
100.120.77.189 - - [13/Jun/2019:06:25:11 +0000] "GET /specialcase/v2/sudogroup/SACIG7dh7idzUPFVFC3yiZ/trays?details=true HTTP/1.1" 200 15385 GET 107  
100.120.77.188 - - [13/Jun/2019:06:25:12 +0000] "GET /specialcase/v2/sudogroup/V8LUCL9QNSkPSHSgTv9UHW/trays?details=true HTTP/1.1" 200 8239 GET 61  
100.120.77.156 - - [13/Jun/2019:06:25:12 +0000] "GET /specialcase/v2/experiment/balance?lid=2&showdeactivated=true HTTP/1.1" 200 262 GET 6  
100.120.77.192 - - [13/Jun/2019:06:25:12 +0000] "GET /specialcase/v3/experiment/offers?locationId=1313&type=activation\_offer HTTP/1.1" 200 189 GET 4  
100.120.77.245 - - [13/Jun/2019:06:25:12 +0000] "GET /specialcase/v2/app/forceupgrade?appname=Android&appversion=4120300 HTTP/1.1" 200 33 GET 1  
100.120.77.140 - - [13/Jun/2019:06:25:12 +0000] "GET /specialcase/v2/sudogroup/n8jbBXblv16H2SJ881qONX/trays?details=true HTTP/1.1" 200 15303 GET 110

---

<div class="post-metadata">

**Author:** ![Vikash\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_singh1/32/42119_2.png) [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Post date:** [June 13, 2019, 11:13am UTC](https://discuss.elastic.co/t/logstash-grok-plugin-is-considering-number-as-text/185558/4 "2019-06-13T11:13:22Z")

</div>

> [@prataprajasekhar](#):
>
> 100.120.77.247 - - [13/Jun/2019:06:25:09 +0000] "GET /specialcase/v2/experiment/balance?lid=989 HTTP/1.1" 200 246 GET 32

You grok is working absolutely fine..  
100.120.77.247 - - [13/Jun/2019:06:25:09 +0000] "GET /specialcase/v2/experiment/balance?lid=989 HTTP/1.1" 200 246 GET 32

%{IP:client\_ip} %{USER:ident} %{USER:auth} [%{HTTPDATE:apache\_timestamp}] "%{WORD:method} /%{NOTSPACE:request\_page} HTTP/%{NUMBER:http\_version}" %{NUMBER:server\_response}

Output:  
{  
"request\_page": "specialcase/v2/experiment/balance?lid=989",  
"method": "GET",  
"auth": "-",  
"ident": "-",  
"http\_version": "1.1",  
"client\_ip": "100.120.77.247",  
"server\_response": "200",  
"apache\_timestamp": "13/Jun/2019:06:25:09 +0000"  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 13, 2019, 11:48am UTC](https://discuss.elastic.co/t/logstash-grok-plugin-is-considering-number-as-text/185558/5 "2019-06-13T11:48:40Z")

</div>

Your mutate+convert is before your grok, so at that point the response field does not exist, so the mutate+convert does not do anything.

---

<div class="post-metadata">

**Author:** ![prataprajasekhar](https://avatars.discourse-cdn.com/v4/letter/p/e19b73/32.png) [@prataprajasekhar](https://discuss.elastic.co/u/prataprajasekhar)\
**Post date:** [June 13, 2019, 5:05pm UTC](https://discuss.elastic.co/t/logstash-grok-plugin-is-considering-number-as-text/185558/6 "2019-06-13T17:05:21Z")

</div>

fantastic Mr. Badger. Moved the mutate next to grok and issue fixed.

Many thanks for your support.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2019, 5:05pm UTC](https://discuss.elastic.co/t/logstash-grok-plugin-is-considering-number-as-text/185558/7 "2019-07-11T17:05:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
