# Port number ECS field data type

**URL:** <https://discuss.elastic.co/t/port-number-ecs-field-data-type/289992>\
**Category:** Kibana\
**Tags:** ecs-elastic-common-schema\
**Created:** [November 23, 2021, 10:35pm UTC](https://discuss.elastic.co/t/port-number-ecs-field-data-type/289992 "2021-11-23T22:35:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![groth](https://avatars.discourse-cdn.com/v4/letter/g/b487fb/32.png) [@groth](https://discuss.elastic.co/u/groth)\
**Post date:** [November 23, 2021, 10:35pm UTC](https://discuss.elastic.co/t/port-number-ecs-field-data-type/289992/1 "2021-11-23T22:35:50Z")

</div>

Can someone please explain to me why port number ECS fields like source.port, destination.port, etc. are defined as numerical type long? When would port numbers from logs ever need to be used in any kind of mathematical calculation?

Here's why I ask. In Kibana, with numerical data types the value for the port number is rendered in a document as for example:  
source.port 55,134  
Obviously no one puts a comma in a port number. Could we just change the format of the number to remove the comma under advanced settings...yes...but then it removes all commas for all other numbers everywhere.

What would be the impact of defining the ECS port number fields as keyword string type in an index template to override the default long type? Would that cause problems anywhere like in Endpoint Security?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 23, 2021, 11:04pm UTC](https://discuss.elastic.co/t/port-number-ecs-field-data-type/289992/2 "2021-11-23T23:04:53Z")

</div>

Port numbers are mapped as a numeric type because Elasticsearch optimizes those types for range queries, and making a range query on a port is a pretty common use case.

Some real use cases would be search all ports between a specific range, or search all events where the destination port is higher than some specific number.

You can change the way kibana shows numeric values by editing the format of the specific field in your index pattern, this will affect only the specific field, not other numeric fields.

To remove the thousand separator from the fields with port numbers, you just need to format the field as a number and use a `0` in the number format pattern, like the example in the following image.

 ![source-port](https://us1.discourse-cdn.com/elastic/original/3X/9/2/926f7ff0e4f234c5cf2f3026d179d617cafd013b.png)

This way, any port higher than `1000` will appear without the thousand separator, for example, `9200` will show as `9200`, not `9,200` if your thousand separator locale is `,`.

---

<div class="post-metadata">

**Author:** ![groth](https://avatars.discourse-cdn.com/v4/letter/g/b487fb/32.png) [@groth](https://discuss.elastic.co/u/groth)\
**Post date:** [November 23, 2021, 11:42pm UTC](https://discuss.elastic.co/t/port-number-ecs-field-data-type/289992/3 "2021-11-23T23:42:38Z")

</div>

Ah, ok. Thank you. I was only thinking about it from a metrics perspective.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2021, 11:43pm UTC](https://discuss.elastic.co/t/port-number-ecs-field-data-type/289992/4 "2021-12-21T23:43:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
