# Logstash ip data type

**URL:** <https://discuss.elastic.co/t/logstash-ip-data-type/227879>\
**Category:** Logstash\
**Created:** [April 14, 2020, 9:40am UTC](https://discuss.elastic.co/t/logstash-ip-data-type/227879 "2020-04-14T09:40:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohammad\_Mousavi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammad_mousavi/32/56508_2.png) [@Mohammad\_Mousavi](https://discuss.elastic.co/u/Mohammad_Mousavi)\
**Post date:** [April 14, 2020, 9:40am UTC](https://discuss.elastic.co/t/logstash-ip-data-type/227879/1 "2020-04-14T09:40:47Z")

</div>

Hi, I have this in grok : %{IP:clientip}, but in Kibana in index mapping I see:

> ```
> "clientip": {
> "type": "text",
> "norms": false,
> "fields": {
> "keyword": {
> "type": "keyword",
> "ignore_above": 256
> 
> ```

I can't use kibana filter based on IP range, I guess this is the reason.  
Should I reindex my indexes? How ?  
and what's wrong with logstash ? should I use some mutate to convert ?  
Thanx a lot.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 14, 2020, 10:59am UTC](https://discuss.elastic.co/t/logstash-ip-data-type/227879/2 "2020-04-14T10:59:16Z")

</div>

Mutating fields in Logstash does not control how they are mapped in Elasticsearch, just how they are formatted in the JSON document being indexed. This is why it is only possible to convert to integers and floats. For data that are sent as a string, e.g. IP addresses, you need to provide the correct mapping through an index template. What you see is the default mapping that is created dynamically for strings if you do not specify any mapping. As you can not change mappings for existing fields you will need to reindex your data with the corrected mappings.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2020, 10:59am UTC](https://discuss.elastic.co/t/logstash-ip-data-type/227879/3 "2020-05-12T10:59:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
