# Set data type to float (vs long) on filesystem.fs.used\_p

**URL:** <https://discuss.elastic.co/t/set-data-type-to-float-vs-long-on-filesystem-fs-used-p/74287>\
**Category:** Logstash\
**Created:** [February 7, 2017, 8:54pm UTC](https://discuss.elastic.co/t/set-data-type-to-float-vs-long-on-filesystem-fs-used-p/74287 "2017-02-07T20:54:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![itsecureadmin](https://avatars.discourse-cdn.com/v4/letter/i/ebca7d/32.png) [@itsecureadmin](https://discuss.elastic.co/u/itsecureadmin)\
**Post date:** [February 7, 2017, 8:54pm UTC](https://discuss.elastic.co/t/set-data-type-to-float-vs-long-on-filesystem-fs-used-p/74287/1 "2017-02-07T20:54:14Z")

</div>

I am using logstash 2.2 and Elastic Search 1.5 on AWS and am not able to force the filesystem.fs.used\_p value to be stored as a float so that I can check the filesystem used percentage properly.

I'm looking for help that would allow me to store this value as a float so that I can run ElastAlert against Elastic Search and alert on this field.

Amazon Linux  
logstash-2.2.4-1.noarch  
packetbeat-1.3.1-1.x86\_64  
topbeat-1.3.1-1.x86\_64  
filebeat-1.3.1-1.x86\_64  
Elastic Search: 1.5 - managed by AWS

- I have also tried Elastic Search 5\*

I've searched through the forums here and have not been able to find a solution.

I've tried:

1. setting up a mutate section in the logstash config to force the conversion:

As part of the mutate addition, I would stop logstash, delete the index, start logstash, and check to validate. It did not work, the field continued to be a long.

1. I've used the mapping API to set the field to float:

That did not work either, or worked until logstash started logging to a new index for the following day.

```
curl -X GET https://${ES_ENDPOINT}/${ES_INDEX}/filesystem/_mapping?pretty
...
    "mappings" : {
      "filesystem" : {
...
          "fs" : {
            "properties" : {
...
              "used_p" : {
                "type" : "long"
              }
...

```

I would appreciate any help with this issue.

Thanks,  
Josh

---

<div class="post-metadata">

**Author:** ![itsecureadmin](https://avatars.discourse-cdn.com/v4/letter/i/ebca7d/32.png) [@itsecureadmin](https://discuss.elastic.co/u/itsecureadmin)\
**Post date:** [February 15, 2017, 7:08pm UTC](https://discuss.elastic.co/t/set-data-type-to-float-vs-long-on-filesystem-fs-used-p/74287/2 "2017-02-15T19:08:24Z")

</div>

I discovered my mistake on this issue. Nested fields must be addressed using brackets within mutate, ie:

```
        mutate {
                convert => ["[fs][used_p]" , "float" ]
        }

```

Thanks,  
Josh

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2017, 7:08pm UTC](https://discuss.elastic.co/t/set-data-type-to-float-vs-long-on-filesystem-fs-used-p/74287/3 "2017-03-15T19:08:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
