# \[Resolved\]Interger field defined in index template is treated as string, it looks like the interger mapping doesn't take effect

**URL:** <https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990>\
**Category:** Elasticsearch\
**Created:** [July 17, 2019, 12:50pm UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990 "2019-07-17T12:50:31Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![cheriemilk](https://avatars.discourse-cdn.com/v4/letter/c/c37758/32.png) [@cheriemilk](https://discuss.elastic.co/u/cheriemilk)\
**Post date:** [July 17, 2019, 12:50pm UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/1 "2019-07-17T12:50:31Z")

</div>

Hi Team,

I defined 4 integer fields in index template(if1,if2,if3 and if4), and ship serveral events to Elasticsearch by logstash. I found that these 4 interger fields are displayed as 'string' type in Kibana, which is unexpected.  
Please help take a look and advice how to correct this issue.

1. Index template

> ```
> {
> "template": "kvaudit",
> "index_patterns": ["kvaudit*"],
> "settings": {
> "index": {
> "number_of_shards": "1",
> "codec": "best_compression",
> "number_of_replicas": "0"
> }
> },
> "mappings": {
> "doc": {
> "properties": {
> "@version": {
> "type": "keyword" }
> }
> }
> },
> 
> "beat": { 
> "properties": {
> "version": {
> "type": "keyword"
> }
> }
> },
> 
> "fields": {
> "properties": { "at": {"type": "keyword"},
> "ktf1": {"type": "keyword"},
> "kf1": {"type": "keyword"},
> "kf2": {"type": "keyword"},
> "kf3": {"type": "keyword"},
> "if1": { "type": "integer"},
> "if2": { "type": "integer"},
> "if3": { "type": "integer"},
> "if4": { "type": "integer"}}}
> }
> 
> ```

1. logstash.conf

> ```
> input { file{ path => "C:/elkstack/elasticsearch-7.0.1-windows-x86_64/data/integertest.csv"		
> start_position => "beginning"
> mode => "tail"
> sincedb_path => "C:/elkstack/elasticsearch-7.0.1-windows-x86_64/sincedb/sincedb.txt" }
> }
> 
> filter { 
> csv { columns => [ "at",
> "ktf1",
> "kf1",
> "kf2",
> "kf3",
> "if1",
> "if2",
> "if3",
> "if4"]
> separator => ","
> skip_header => "true"
> } 
> 
> ruby {
> code => "
> hash = event.to_hash
> hash.each do |k, v|
> if(v != nil && v.kind_of?(String) && v.length > 2 && v[0,1] == '[' && v[v.length-1,1] == ']')
> event.set(k, v[1, v.length-2].split(','))
> end
> end
> "
> }
> }
> 
> output {
> elasticsearch {
> action => "index"
> hosts => "localhost:9200"
> index => "kvaudit"
> manage_template => true
> template => "C:/elkstack/elasticsearch-7.0.1-windows-x86_64/mapping/kvaudit2.json"
> template_name=> "kvaudit2.json"
> template_overwrite => true }
> 
> stdout { codec => rubydebug {metadata => true}}
> }
> 
> ```

1. the data shipped to ES

> ```
> at,ktf1,kf1,kf2,kf3,if1,if2,if3,if4
> SAVE,performance,perf,,perf_guideline,1,2,3,4
> SAVE,"[performance,liveprofile,talentflag]","[obj,comp,sysoverallperformance,sysoverallpotential]","[obj,comp]","[sysoverallperformance,sysoverallpotential]",2,3,4,5
> SAVE,"[performance,liveproifle]","[obj,sysoverallperformance,sysoverallpotential]",obj,"[obj,sysoverallperformance,sysoverallpotential]",1,2,3,4
> 
> ```

1. But in kibana, the data type for 4 fields if1, if2, if3 and if4 are string, which is not consittent with what I defined in index template.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f7b5848103296856a22a792ade47281f79b7c430.png)

Anyone can take a look?

---

<div class="post-metadata">

**Author:** ![Ignacio\_Vera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ignacio_vera/32/36674_2.png) [@Ignacio\_Vera](https://discuss.elastic.co/u/Ignacio_Vera)\
**Post date:** [July 18, 2019, 12:30pm UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/2 "2019-07-18T12:30:32Z")

</div>

Hi,

Could you share the version you are using? This is an importation information in order to help. In addition, could you please revise the index template you have posted here, something looks off in that template. If would we better if you can share exactly the same command you are executing.

---

<div class="post-metadata">

**Author:** ![cheriemilk](https://avatars.discourse-cdn.com/v4/letter/c/c37758/32.png) [@cheriemilk](https://discuss.elastic.co/u/cheriemilk)\
**Post date:** [July 19, 2019, 6:26am UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/3 "2019-07-19T06:26:16Z")

</div>

Hi Ignacio\_Vera,  
I am using elasticsearch-7.0.1-windows-x86\_64, logstash-7.0.1 and kibana-7.0.1-windows-x86\_64.

---

<div class="post-metadata">

**Author:** ![Ignacio\_Vera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ignacio_vera/32/36674_2.png) [@Ignacio\_Vera](https://discuss.elastic.co/u/Ignacio_Vera)\
**Post date:** [July 19, 2019, 10:58am UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/4 "2019-07-19T10:58:24Z")

</div>

Hi,

I think the template you shared with us is wrong. I built a lighter version:

```auto
{
  "template": "kvaudit",
  "index_patterns": [
    "kvaudit*"
  ],
  "settings": {
    "index": {
      "number_of_shards": "1",
      "codec": "best_compression",
      "number_of_replicas": "0"
    }
  },
  "mappings": {
    "properties": {
      "at": {
        "type": "keyword"
      },
      "ktf1": {
        "type": "keyword"
      },
      "kf1": {
        "type": "keyword"
      },
      "kf2": {
        "type": "keyword"
      },
      "kf3": {
        "type": "keyword"
      },
      "if1": {
        "type": "integer"
      },
      "if2": {
        "type": "integer"
      },
      "if3": {
        "type": "integer"
      },
      "if4": {
        "type": "integer"
      }
    }
  }
}

```

And in addition I might need to set to false this option in your Logstash configuration: [https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm\_enabled](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm_enabled)

---

<div class="post-metadata">

**Author:** ![cheriemilk](https://avatars.discourse-cdn.com/v4/letter/c/c37758/32.png) [@cheriemilk](https://discuss.elastic.co/u/cheriemilk)\
**Post date:** [July 23, 2019, 5:52am UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/5 "2019-07-23T05:52:36Z")

</div>

Hi Ignacio\_Vera,  
I applied your template and add this 'ilm\_enabled =\> false' in logstash output plug-in, but the 4 integer fields are still displayed as string .

Please let me know if there're other information you need to know.

Thanks,  
Cherie

---

<div class="post-metadata">

**Author:** ![Ignacio\_Vera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ignacio_vera/32/36674_2.png) [@Ignacio\_Vera](https://discuss.elastic.co/u/Ignacio_Vera)\
**Post date:** [July 23, 2019, 6:03am UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/6 "2019-07-23T06:03:41Z")

</div>

Can you share the output from the following API end-point:

```auto
GET _template/kvaudit

```

That should tell us if the template was created.

---

<div class="post-metadata">

**Author:** ![cheriemilk](https://avatars.discourse-cdn.com/v4/letter/c/c37758/32.png) [@cheriemilk](https://discuss.elastic.co/u/cheriemilk)\
**Post date:** [July 23, 2019, 6:30am UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/7 "2019-07-23T06:30:50Z")

</div>

Hi Ignacio\_Vera,

1. returned nothing when sending request **GET \_template/kvaudit**

2. I tried **GET \_template/kvaudit** \*, and it returned below template to me, the template looks like inserted as expected. Does the issue happens on mapping? as when I created the index named kvaudit\*, it shows me that if1, if2, if3, if4 are all string. Please refer to below screenshot.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/a/5a900baf64330977c5a358a2843be761ba32c73a.png)

---

<div class="post-metadata">

**Author:** ![Ignacio\_Vera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ignacio_vera/32/36674_2.png) [@Ignacio\_Vera](https://discuss.elastic.co/u/Ignacio_Vera)\
**Post date:** [July 23, 2019, 6:40am UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/8 "2019-07-23T06:40:03Z")

</div>

Have you deleted the index before ingesting the data gain? Once the mapping is created it cannot be changed so you need to delete it so it gets recreated again. I would recommend to delete the templates as well so you start from a clean cluster.

---

<div class="post-metadata">

**Author:** ![cheriemilk](https://avatars.discourse-cdn.com/v4/letter/c/c37758/32.png) [@cheriemilk](https://discuss.elastic.co/u/cheriemilk)\
**Post date:** [July 23, 2019, 6:40am UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/9 "2019-07-23T06:40:27Z")

</div>

Yes. I deleted both the index template and index and send this request **DELETE /\_template/kvaudit** \* to make sure the template are deleted.

---

<div class="post-metadata">

**Author:** ![cheriemilk](https://avatars.discourse-cdn.com/v4/letter/c/c37758/32.png) [@cheriemilk](https://discuss.elastic.co/u/cheriemilk)\
**Post date:** [July 23, 2019, 6:53am UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/10 "2019-07-23T06:53:37Z")

</div>

Thanks. I do it again with , and now is correct.

---

<div class="post-metadata">

**Author:** ![cheriemilk](https://avatars.discourse-cdn.com/v4/letter/c/c37758/32.png) [@cheriemilk](https://discuss.elastic.co/u/cheriemilk)\
**Post date:** [July 23, 2019, 6:57am UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/11 "2019-07-23T06:57:05Z")

</div>

Hi Ignacio\_Vera,

One question. what's the difference by deleting the index in index management and index pattern?

Thanks,  
Cherie

---

<div class="post-metadata">

**Author:** ![Ignacio\_Vera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ignacio_vera/32/36674_2.png) [@Ignacio\_Vera](https://discuss.elastic.co/u/Ignacio_Vera)\
**Post date:** [July 23, 2019, 7:12am UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/12 "2019-07-23T07:12:07Z")

</div>

Not an expert in that area but I think index pattern is something specific to Kibana that allows you to group indices so they can be query together. Deleting an index pattern I believe it has no effect on the index in elasticsearch.

With index management you are actually deleting the indices in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 20, 2019, 7:12am UTC](https://discuss.elastic.co/t/resolved-interger-field-defined-in-index-template-is-treated-as-string-it-looks-like-the-interger-mapping-doesnt-take-effect/190990/13 "2019-08-20T07:12:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
