# Unexpected default mapping

**URL:** <https://discuss.elastic.co/t/unexpected-default-mapping/25182>\
**Category:** Elasticsearch\
**Created:** [July 8, 2015, 8:57pm UTC](https://discuss.elastic.co/t/unexpected-default-mapping/25182 "2015-07-08T20:57:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Khoa\_Nguyen1](https://avatars.discourse-cdn.com/v4/letter/k/dec6dc/32.png) [@Khoa\_Nguyen1](https://discuss.elastic.co/u/Khoa_Nguyen1)\
**Post date:** [July 8, 2015, 8:57pm UTC](https://discuss.elastic.co/t/unexpected-default-mapping/25182/1 "2015-07-08T20:57:27Z")

</div>

Using logstash, I have parsed a CSV file and loaded them to elasticsearch. It looks like all numbers are treated as string. Is there a way to tell elasticsearch to treat them as number without defining a custom mapping? My CSV record has hundreds of fields so I try to avoid the tedious and error-prone task of writing a custom mapping.

---

<div class="post-metadata">

**Author:** ![Harlin\_ES](https://avatars.discourse-cdn.com/v4/letter/h/977dab/32.png) [@Harlin\_ES](https://discuss.elastic.co/u/Harlin_ES)\
**Post date:** [July 8, 2015, 9:09pm UTC](https://discuss.elastic.co/t/unexpected-default-mapping/25182/2 "2015-07-08T21:09:48Z")

</div>

Number should be treated as Longs in Elasticsearch by default. At least this is the behavior I have always seen. How are you passing the documents? Are you maybe adding quotes around the numbers where there shouldn't be any?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 8, 2015, 10:30pm UTC](https://discuss.elastic.co/t/unexpected-default-mapping/25182/3 "2015-07-08T22:30:20Z")

</div>

Quoted numbers will be treated as strings ☹  
It's always best to use Logstash with convert and explicitly set them as ints.

---

<div class="post-metadata">

**Author:** ![Khoa\_Nguyen1](https://avatars.discourse-cdn.com/v4/letter/k/dec6dc/32.png) [@Khoa\_Nguyen1](https://discuss.elastic.co/u/Khoa_Nguyen1)\
**Post date:** [July 8, 2015, 11:51pm UTC](https://discuss.elastic.co/t/unexpected-default-mapping/25182/4 "2015-07-08T23:51:43Z")

</div>

There are no quotes in the CSV file. Below is my logstash configuration. Fields like spkgOctets, duration, etc. are plain numbers.

```
input {
    stdin {}
}

filter {
    if [message] =~ /.+XDR_ACCT_SUMMARY.+/ {
            csv {
                    columns => [header, recordTime, UTC, sessionId, col5,
                                imsi, msisdn, xdrType, apn, operatorId,
                                roamingGroup, subsIp, sgsnIp, ggsnIp, 
                                spkgId, spkgStartTime, spkgTier, spkgCredits,
                                spkgOctets, duration, timeStamp, technology, col23,
                                carrierId, sessStartTime, sessStopTime, cycleDay,
                                bcsd, sessCredits, sessOctets, probeType,
                                homeMcc, homeMnc, currencyCode, bundleGroup,
                                bundleId, bundleVol1, bundleCurrency1,
                                bundleVol2, bundleCurrency2, 
                                bundleVol3, bundleCurrency3, 
                                bundleVol4, bundleCurrency4, 
                                isProrate, padUsage, extnData, probeData
                                ]
                    separator => "&"
                    remove_field => ["col5", "col23", "column49"]
            }
            # Use session stop time as timestamp for this event
            date {
                    match => ["sessStopTime", "yyyyMMddHHmmss"]
                    timezone => "UTC"
            }

            fingerprint {
                    method => "SHA1"
                    key => message
            }

            geoip {
                    source => "sgsnIp"
            }
    }
}

output {
    stdout { codec => dots}
    elasticsearch { 
            host => localhost 
            cluster => "rm_cluster_dev"
            document_id => "%{fingerprint}"
    }
}
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 9, 2015, 10:43am UTC](https://discuss.elastic.co/t/unexpected-default-mapping/25182/5 "2015-07-09T10:43:36Z")

</div>

The CSV file parses all fields as strings and do not perform any automatic type conversions, so you may need to convert the integer fields explicitly using the mutate filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:02am UTC](https://discuss.elastic.co/t/unexpected-default-mapping/25182/6 "2017-07-06T00:02:37Z")

</div>


