# Mutate convert not working

**URL:** <https://discuss.elastic.co/t/mutate-convert-not-working/42995>\
**Category:** Logstash\
**Created:** [February 29, 2016, 11:47am UTC](https://discuss.elastic.co/t/mutate-convert-not-working/42995 "2016-02-29T11:47:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rohan\_Jain](https://avatars.discourse-cdn.com/v4/letter/r/e36b37/32.png) [@Rohan\_Jain](https://discuss.elastic.co/u/Rohan_Jain)\
**Post date:** [February 29, 2016, 11:47am UTC](https://discuss.elastic.co/t/mutate-convert-not-working/42995/1 "2016-02-29T11:47:42Z")

</div>

I am trying to convert a field named " sf\_query\_time" from string to integer field using mutate convert in filters in logstash.conf. But its not getting converted

Here is the code (filter in logstash)

input {

beats {  
port =\> 5045  
type =\> "logs"  
ssl =\> false  
ssl\_certificate =\> "/etc/pki/tls/certs/connectandsell-logging.crt"  
ssl\_key =\> "/etc/pki/tls/private/connectandsell-logging.key"  
}  
}

filter {  
mutate {  
convert =\> { "sf\_query\_time" =\> "integer" }  
}  
metrics {  
meter =\> "events"  
add\_tag =\> "metric"  
}

if [input\_type] == "log"{  
grok{  
match =\> ["source", "%{GREEDYDATA}[/\]%{WORD:log\_server}-%{GREEDYDATA}" ]  
}  
}else{  
grok{  
match =\> ["path", "%{GREEDYDATA}[/\]%{WORD:log\_server}-%{DATA:type}-%{GREEDYDATA}" ]  
}  
}

if "\_grokparsefailure" in [tags] {  
mutate {  
replace =\> ["message" , "Incorrect filename format"]  
add\_tag =\> ["incorrectFilenameFormat"]  
}  
} else if [type] == "lightning" {  
grok {  
patterns\_dir =\> "/etc/logstash/conf.d/pattern"  
match =\> ["message", "(?m)%{LIGLOG}"] }  
if "\_grokparsefailure" in [tags] {  
grok {  
match =\> { "message" =\> "(?m)%{GREEDYDATA}" }  
}  
}else{  
mutate {  
replace =\> ["message" , "%{temp\_message}"]  
replace =\> ["timestamp" , "%{source\_timestamp}"]  
remove\_field =\> ["temp\_message"]  
remove\_field =\> ["source\_timestamp"]  
}  
date {  
match =\> ["timestamp" , "yyyy-MM-dd HH:mm:ss,SSS"]  
timezone =\> "US/Pacific"  
}  
}  
} else if [type] == "engineactivity" {  
grok {  
patterns\_dir =\> "/etc/logstash/conf.d/pattern"  
match =\> ["message", "(?m)%{ENGLOG}"] }  
if "\_grokparsefailure" in [tags] {  
grok {  
match =\> { "message" =\> "(?m)%{GREEDYDATA}" }  
}  
}else{  
mutate {  
# For some reason for this index type is not getting set automatically.  
# It throws following error: InvalidIndexNameException[Invalid index name [engineactivity,4-2016.01.12], must not contain the following characters [, /, \*, ?, ", \<, \>, |, , ,]]  
# Therefore, we are specifying the correct type.  
replace =\> ["type" , "engineactivity"]  
replace =\> ["message" , "%{temp\_message}"]  
replace =\> ["timestamp" , "%{source\_timestamp}"]  
remove\_field =\> ["temp\_message"]  
remove\_field =\> ["source\_timestamp"]  
}  
date {  
match =\> ["timestamp" , "yyyy-MM-dd HH:mm:ss.SSS"]  
timezone =\> "UTC"  
}  
}  
} else if [type] == "engineasterisk" {  
grok {  
patterns\_dir =\> "/etc/logstash/conf.d/pattern"  
match =\> ["message", "(?m)%{ENGAST\_LOG}"]  
}  
if "\_grokparsefailure" in [tags] {  
grok {  
match =\> { "message" =\> "(?m)%{GREEDYDATA}" }  
}  
}else{  
mutate {  
gsub =\> [ "kvpairs", ": \n", ": dummy  
" ] # please do not edit this line. For details: [https://github.com/elastic/logstash/issues/1645](https://github.com/elastic/logstash/issues/1645)  
}

```
  kv {
    field_split => "\n"
    value_split => ":"
    source => "kvpairs"
    remove_field => ["kvpairs"]
  }

  if [source_timestamp] {
    mutate {
      replace => ["timestamp" , "%{source_timestamp}"]
      remove_field => ["source_timestamp"]
    }
  }

  date {
    match => ["timestamp" , "MM.dd.yy HH:mm:ss.SSS"]
    timezone => "US/Pacific"
  }
}

```

}else if [type] == "asterisk" or [type] == "proxy" {  
grok {  
patterns\_dir =\> "/etc/logstash/conf.d/pattern"  
match =\> ["message", "(?m)%{ASTLOG}"]  
}  
if "\_grokparsefailure" in [tags] {  
grok {  
match =\> { "message" =\> "(?m)%{GREEDYDATA}" }  
}  
}else{  
mutate {  
replace =\> ["timestamp" , "%{source\_timestamp}"]  
remove\_field =\> ["source\_timestamp"]  
}  
date {  
match =\> ["timestamp" , "yyyy-MM-dd HH:mm:ss.SSS" , "yyyy-MM-dd HH:mm:ss"]  
timezone =\> "US/Pacific"  
}  
}  
}else{  
grok {  
match =\> { "message" =\> "(?m)%{GREEDYDATA}" }  
}  
mutate {  
replace =\> ["type" , "junk-data"]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![marke72](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marke72/32/10832_2.png) [@marke72](https://discuss.elastic.co/u/marke72)\
**Post date:** [February 29, 2016, 5:23pm UTC](https://discuss.elastic.co/t/mutate-convert-not-working/42995/3 "2016-02-29T17:23:09Z")

</div>

Are there any errors in your logs? Also I've had some problems with Elasticsearch dynamic mapping not working for integer fields. They still got put in as strings. My fix was to add the field in the mapping with the correct data type. This only lets new indexes from having the correct mapping though unless you reindex the old indexes with the new mapping.

---

<div class="post-metadata">

**Author:** ![Rohan\_Jain](https://avatars.discourse-cdn.com/v4/letter/r/e36b37/32.png) [@Rohan\_Jain](https://discuss.elastic.co/u/Rohan_Jain)\
**Post date:** [March 1, 2016, 6:11am UTC](https://discuss.elastic.co/t/mutate-convert-not-working/42995/4 "2016-03-01T06:11:58Z")

</div>

NO there are no error in my logs

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:09am UTC](https://discuss.elastic.co/t/mutate-convert-not-working/42995/5 "2017-07-06T05:09:12Z")

</div>


