# Query Logstash error type

**URL:** <https://discuss.elastic.co/t/query-logstash-error-type/216934>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [January 29, 2020, 2:00am UTC](https://discuss.elastic.co/t/query-logstash-error-type/216934 "2020-01-29T02:00:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bruno\_aleixo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bruno_aleixo/32/68834_2.png) [@bruno\_aleixo](https://discuss.elastic.co/u/bruno_aleixo)\
**Post date:** [January 29, 2020, 2:00am UTC](https://discuss.elastic.co/t/query-logstash-error-type/216934/1 "2020-01-29T02:00:35Z")

</div>

Hi,

First, sorry my english not be good,  
I made a jdbc connection in the logstash, collecting information from an oracle bank, the query consists of searching the size of the bank and the name of the instance in a single query (using join), when I start the data goes up to the kibana, but the values the types of the fields come out wrong, the size of the bank needed it to come with the type number and it comes in string, so I can't create graphics with this field, I tried to change this existing index with the api mapping, I tried to create an idexe via api, but when I will recognize it in the indexes pathers it just doesn't appear, I tried to run two jdbc entries with the separate queries and even so it doesn't change the field that I need to be in number

Config JDBC

input {  
jdbc {  
jdbc\_driver\_library =\> "/opt/elk/applications/logstash/config/ojdbc6.jar"  
jdbc\_driver\_class =\> "Java::oracle.jdbc.driver.OracleDriver"  
jdbc\_connection\_string =\> "jdbc:oracle:thin:@IP:1521/RUNDECK"  
jdbc\_user =\> "xxxxxxx"  
jdbc\_password =\> "zzzzzzzzz"  
statement =\> "select cold\_used\_mb FROM V$ASM\_DISKGROUP WHERE name LIKE ('%DATA%')"

}  
}  
filter {

}  
output {  
elasticsearch {  
hosts =\> ["elk1:9200", "elk2:9200"]  
index =\> "size\_db-%{+YYYY.MM.dd}"  
}  
}

Version Logstash 6.5

---

<div class="post-metadata">

**Author:** ![ropc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ropc/32/47022_2.png) [@ropc](https://discuss.elastic.co/u/ropc)\
**Post date:** [January 29, 2020, 7:52am UTC](https://discuss.elastic.co/t/query-logstash-error-type/216934/2 "2020-01-29T07:52:56Z")

</div>

@bruno_aleixo A couple of points for your consideration:

- Ensure that the [mappings definitions](https://www.elastic.co/guide/en/elasticsearch/reference/current/mapping.html) are correct for the related index.
- In your Logstash event processing pipeline, you could use the [mutate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-convert) to convert a field’s value to a different type.

I hope that helps.

---

<div class="post-metadata">

**Author:** ![bruno\_aleixo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bruno_aleixo/32/68834_2.png) [@bruno\_aleixo](https://discuss.elastic.co/u/bruno_aleixo)\
**Post date:** [January 29, 2020, 2:51pm UTC](https://discuss.elastic.co/t/query-logstash-error-type/216934/3 "2020-01-29T14:51:49Z")

</div>

The second mutation option was a solution, thank you very much  
filter {  
mutate {  
convert =\> {  
"used\_mb" =\> "float"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2020, 2:51pm UTC](https://discuss.elastic.co/t/query-logstash-error-type/216934/4 "2020-02-26T14:51:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
