# Supported field types?

**URL:** <https://discuss.elastic.co/t/supported-field-types/62839>\
**Category:** Logstash\
**Created:** [October 12, 2016, 4:56pm UTC](https://discuss.elastic.co/t/supported-field-types/62839 "2016-10-12T16:56:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 12, 2016, 4:56pm UTC](https://discuss.elastic.co/t/supported-field-types/62839/1 "2016-10-12T16:56:09Z")

</div>

Topic says it...specifically looking at mutate -\> convert:

```
Convert a field’s value to a different type, like turning a string to an integer.

```

I'm suspecting that my config with converting to type "ip" is no longer supported? But I can't seem to find a list of what types of fields I can use. Thank you.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [October 12, 2016, 5:19pm UTC](https://discuss.elastic.co/t/supported-field-types/62839/2 "2016-10-12T17:19:51Z")

</div>

If your target is Elasticsearch, you'll have to use a mapping. Logstash is really only able to understand `int` (or `integer`), `float`, and `string`. These changes are used internally in Logstash to allow for mathematical operations on numbers, when they were originally seen as strings.

Additionally, `integer` and `float` field types can send properly typed values via JSON, since that is what Elasticsearch requires. Otherwise, Elasticsearch mappings would be needed to convert "10" to `10`. Elasticsearch also uses mappings (and mapping templates), to convert "192.168.0.10" to an IP-type field. These mappings are also highly recommended as there are more numeric types besides `integer` and `float`. Choosing the correct java primitive type can save a lot of storage space (`short` vs. `long`, for example).

So, long story short, see the [default mapping template](https://github.com/logstash-plugins/logstash-output-elasticsearch/blob/v5.2.0/lib/logstash/outputs/elasticsearch/elasticsearch-template-es2x.json#L86) provided by Logstash for insight into mapping an IP type.

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 12, 2016, 5:38pm UTC](https://discuss.elastic.co/t/supported-field-types/62839/3 "2016-10-12T17:38:20Z")

</div>

Thank you as always Aaron. Looks like my mutate -\> convert to type "ip" is no longer valid for logstash.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [October 12, 2016, 5:52pm UTC](https://discuss.elastic.co/t/supported-field-types/62839/4 "2016-10-12T17:52:59Z")

</div>

Mutating a field to type _ip_ has never been valid. I'm not sure where you found that. [Mutate filter plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-convert)

Note the phrase:

> Valid conversion targets are: integer, float, string, and boolean.

---

<div class="post-metadata">

**Author:** ![DigiAngel](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@DigiAngel](https://discuss.elastic.co/u/DigiAngel)\
**Post date:** [October 12, 2016, 5:54pm UTC](https://discuss.elastic.co/t/supported-field-types/62839/5 "2016-10-12T17:54:59Z")

</div>

You're of course right...I think as this is my test setup I added that in...VERY good to know thanks again Aaron 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:34am UTC](https://discuss.elastic.co/t/supported-field-types/62839/6 "2017-07-06T04:34:30Z")

</div>


