# Unable to mutate values to integer\_range

**URL:** <https://discuss.elastic.co/t/unable-to-mutate-values-to-integer-range/86705>\
**Category:** Logstash\
**Created:** [May 22, 2017, 4:11pm UTC](https://discuss.elastic.co/t/unable-to-mutate-values-to-integer-range/86705 "2017-05-22T16:11:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![xanadsonf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xanadsonf/32/18451_2.png) [@xanadsonf](https://discuss.elastic.co/u/xanadsonf)\
**Post date:** [May 22, 2017, 4:11pm UTC](https://discuss.elastic.co/t/unable-to-mutate-values-to-integer-range/86705/1 "2017-05-22T16:11:04Z")

</div>

Hi all,

I'm trying to "convert" two integer values to a range with mutate without success...  
Range is a recent functionality, I'm unable to find any working syntax in the documentation.

values : 2 integers in [eng][rs] and [eng][re]  
destination [eng][range]

Syntax, configuration &log below. Please can someone tell me what's wrong with my logstash syntax?  
Do not hesitate to tell me if I'm not clear ;o)

Best,  
Antony

* * *

**My template** :  
"eng": {  
"dynamic": true,  
"properties": {  
...  
"rs": {  
"type": "integer"  
},  
"re": {  
"type": "integer"  
},  
"slrange": {  
"type": "integer\_range"  
}  
...

**My logstash filter** :  
filter {  
# ENGAGEMENT CLEANING  
if [path] =~ //+(?:[+\]|%20)\*eng.k/ {  
mutate {  
...  
add\_field =\> { "[eng][range]" =\> { "gte" =\> %{[eng][rs]} "lte" =\> %{[eng][re]} } }  
# trying with the following syntax: same error  
# add\_field =\> { "[eng][slrange]" =\> { "gte" =\> 10 "lte" =\> 20 } }  
# add\_field =\> { "[eng][slrange]" =\> { "gte" =\> 10, "lte" =\> 20 } }  
...  
}  
}  
}

**Logstash log** :  
[2017-05-22T17:53:15,303][WARN][logstash.outputs.elasticsearch] Failed action. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"engagement-2017", :\_type=\>"logs", :\_routing=\>nil}, 2017-05-22T15:53:13.000Z %{host} 130.211.72.178 - - [22/May/2017:17:53:13 +0200] "GET /eng.k?s=plop1&m=9d562d41cde38d78&f=2820046521&u=plop&t=hls&q=720p&rs=150&re=240 HTTP/1.1" 404 935 "-" "curl/7.38.0" 0], :response=\>{"index"=\>{"\_index"=\>"engagement-2017", "\_type"=\>"logs", "\_id"=\>"AVww3MsMxqoY7doNaybz", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse [eng.range]", "caused\_by"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"**error parsing field [eng.slrange], expected an object but got null**"}}}}}

---

<div class="post-metadata">

**Author:** ![xanadsonf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xanadsonf/32/18451_2.png) [@xanadsonf](https://discuss.elastic.co/u/xanadsonf)\
**Post date:** [May 29, 2017, 9:12am UTC](https://discuss.elastic.co/t/unable-to-mutate-values-to-integer-range/86705/2 "2017-05-29T09:12:50Z")

</div>

No idea where I'm wrong?

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [May 31, 2017, 8:56am UTC](https://discuss.elastic.co/t/unable-to-mutate-values-to-integer-range/86705/3 "2017-05-31T08:56:43Z")

</div>

Have you tried?

```auto
add_field => { "[eng][slrange][gte] "=> "%{[eng][rs]", "[eng][slrange][lte]" => "%{[eng][re]" }

```

Not tested.

I find it is best to think of the the add\_field function as (in a Tree datatype) adding values to leaf positions as opposed to adding sub-trees. The LHS describes the path to the leaf node and the RHS is a scalar value.

---

<div class="post-metadata">

**Author:** ![xanadsonf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xanadsonf/32/18451_2.png) [@xanadsonf](https://discuss.elastic.co/u/xanadsonf)\
**Post date:** [June 2, 2017, 4:00pm UTC](https://discuss.elastic.co/t/unable-to-mutate-values-to-integer-range/86705/4 "2017-06-02T16:00:13Z")

</div>

Many thanks for your answer Guy.

I added the right syntax in my mutate filer:  
add\_field =\> {  
"[eng][slrange][gte]" =\> "%{[eng][rs]}"  
"[eng][slrange][lte]" =\> "%{[eng][re]}"  
}

Values are now inserted in my documents.

I changed my stand and do not use integer\_range fields. I wrote a ruby filter and found queries that fit my needs.  
I'm unable to check range specific queries since it need my ES template to be changed, which is not possible right now. Will check that before last index scratch ;o)

Thanks again, best.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2017, 4:00pm UTC](https://discuss.elastic.co/t/unable-to-mutate-values-to-integer-range/86705/5 "2017-06-30T16:00:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
