# Logstash Transposing Field Data

**URL:** <https://discuss.elastic.co/t/logstash-transposing-field-data/41547>\
**Category:** Logstash\
**Created:** [February 11, 2016, 7:06pm UTC](https://discuss.elastic.co/t/logstash-transposing-field-data/41547 "2016-02-11T19:06:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nomoneynoproblems](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nomoneynoproblems/32/44524_2.png) [@nomoneynoproblems](https://discuss.elastic.co/u/nomoneynoproblems)\
**Post date:** [February 11, 2016, 7:06pm UTC](https://discuss.elastic.co/t/logstash-transposing-field-data/41547/1 "2016-02-11T19:06:36Z")

</div>

Hi. We're using Logstash to transport SQL data into ElasticSearch via the JDBC plugin.

Two of the fields we're copying include:

Name  
ZipCode

For some reason the first few characters of zipcode are being inserted into the Name column for a small percentage of records. For example:

"Mcdonald, Mike" who lives in 90210 is being inserted as "Mcdonald, 902 Mike" in the Name column in ES.

Out of 16m inserts into ES around 10% end up with this odd data in the Name column. Zip is fine. It's always 5 numbers.

Settings below:

input {  
jdbc {  
jdbc\_connection\_string =\> "blah"  
jdbc\_user =\> "blah"  
jdbc\_driver\_library =\> "sqljdbc4.jar"  
jdbc\_driver\_class =\> "com.microsoft.sqlserver.jdbc.SQLServerDriver"  
statement\_filepath =\> "query.sql"  
last\_run\_metadata\_path =\> "last\_run\_metadata"  
sql\_log\_level =\> "debug"  
jdbc\_paging\_enabled =\> true  
jdbc\_page\_size =\> 100000  
jdbc\_pool\_timeout =\> 5000

```
}

```

}

output {  
elasticsearch {  
hosts =\> ["blah"]  
index =\> "blah"  
document\_type =\> "document"  
action =\> "update"  
document\_id =\> "%{id}"  
doc\_as\_upsert =\> true  
}  
}

SQL Query:

SELECT Name, City, State, Zip, occupation, [GiveDate],  
Amount, recip, Type, actID, actID as id, halftime, bicycle,  
CASE when display is null then 'x' else display END as display, actID as DeleteID  
from ourTable where actID is not null  
and bicycle \< '1985'

Ideas? It's driving us nuts.

---

<div class="post-metadata">

**Author:** ![nomoneynoproblems](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nomoneynoproblems/32/44524_2.png) [@nomoneynoproblems](https://discuss.elastic.co/u/nomoneynoproblems)\
**Post date:** [February 17, 2016, 4:10pm UTC](https://discuss.elastic.co/t/logstash-transposing-field-data/41547/2 "2016-02-17T16:10:26Z")

</div>

Any ideas at all? Does Elastic not monitor these message boards?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:11am UTC](https://discuss.elastic.co/t/logstash-transposing-field-data/41547/3 "2017-07-06T05:11:00Z")

</div>


