# Logstash Netflow Module Change Index Pattern Field

**URL:** <https://discuss.elastic.co/t/logstash-netflow-module-change-index-pattern-field/113113>\
**Category:** Logstash\
**Created:** [December 25, 2017, 12:40am UTC](https://discuss.elastic.co/t/logstash-netflow-module-change-index-pattern-field/113113 "2017-12-25T00:40:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michael\_Tsikerdekis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_tsikerdekis/32/25950_2.png) [@Michael\_Tsikerdekis](https://discuss.elastic.co/u/Michael_Tsikerdekis)\
**Post date:** [December 25, 2017, 12:40am UTC](https://discuss.elastic.co/t/logstash-netflow-module-change-index-pattern-field/113113/1 "2017-12-25T00:40:02Z")

</div>

I am trying to change the default indexing pattern for logstash's netflow module. Currently fields netflow.dst\_port and netflow.src\_port are set to be string!

I have been changing the json files (netflow.json) in this directory:  
/usr/share/logstash/modules/netflow

And then erasing all data from elasticsearch and restarting everything. However, Kibana still shows that the field is a string.

Am I editing the right files?

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [December 25, 2017, 1:00pm UTC](https://discuss.elastic.co/t/logstash-netflow-module-change-index-pattern-field/113113/2 "2017-12-25T13:00:49Z")

</div>

I am curious why you want to map them as integers? While port values are numbers, they are really a kind of identifier rather than a quantity. This means that you will likely never be doing math functions on them, but you will be doing aggregations all the time using terms queries. By setting the type of these fields to a string you maximize query performance. More info here...

[https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-search-speed.html#\_map\_identifiers\_as\_literal\_keyword\_literal](https://www.elastic.co/guide/en/elasticsearch/reference/current/tune-for-search-speed.html#_map_identifiers_as_literal_keyword_literal)

This is exactly the reason those fields are keywords in the Netflow module.

---

<div class="post-metadata">

**Author:** ![Michael\_Tsikerdekis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_tsikerdekis/32/25950_2.png) [@Michael\_Tsikerdekis](https://discuss.elastic.co/u/Michael_Tsikerdekis)\
**Post date:** [December 25, 2017, 10:21pm UTC](https://discuss.elastic.co/t/logstash-netflow-module-change-index-pattern-field/113113/3 "2017-12-25T22:21:50Z")

</div>

Thank you Robert for the link. What I want to do is built a query that displays only the ports that are above 1024. I have tried using [1024 TO \*] and \>=1024 but I keep getting lower port numbers as well. Are term/string fields allowed to work for queries with range values?

---

<div class="post-metadata">

**Author:** ![Michael\_Tsikerdekis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_tsikerdekis/32/25950_2.png) [@Michael\_Tsikerdekis](https://discuss.elastic.co/u/Michael_Tsikerdekis)\
**Post date:** [December 29, 2017, 2:09am UTC](https://discuss.elastic.co/t/logstash-netflow-module-change-index-pattern-field/113113/4 "2017-12-29T02:09:04Z")

</div>

Is there another way that I can filter out any dest port numbers below 1024?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2018, 2:09am UTC](https://discuss.elastic.co/t/logstash-netflow-module-change-index-pattern-field/113113/5 "2018-01-26T02:09:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
