# What type is the "port" field in Heartbeat output?

**URL:** <https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586>\
**Category:** Beats\
**Created:** [November 21, 2017, 4:06pm UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586 "2017-11-21T16:06:00Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [November 21, 2017, 4:06pm UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/1 "2017-11-21T16:06:00Z")

</div>

I think what I'm seeing is that

(1) for a type HTTP monitor with the port specified in the "urls" the "port" field in the Elasticsearch document is a string

(2) for a type TCP monitor with the port specified in the "ports" the "port" field in the Elasticsearch document is numeric

Am i imagining this?

---

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [November 21, 2017, 4:11pm UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/2 "2017-11-21T16:11:52Z")

</div>

... or did I get those the wrong way round? ... seriously confused here ...

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 22, 2017, 4:18am UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/3 "2017-11-22T04:18:26Z")

</div>

`http.url` is a text field, `tcp.port` is an integer. Is that what you are referring to? The `url` contains more then just the port. Perhaps you can share some more background on the issue you are having?

---

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [November 22, 2017, 9:06am UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/4 "2017-11-22T09:06:53Z")

</div>

With this configuration (boring bits snipped):

```
    - type: http
      urls: ['http://www.example.com:1234']

    - type: tcp
      hosts: ["appserver.example.com"]
      ports: [1410]  

```

then in Elasticseach, according to the Kibana "Discover" screen, I get, respectively

```
    "port": 1234,
    "port": "1410",

```

which confused my code somewhat until I spotted it. (Leaving aside further confusion as to how the same field can sometimes be numeric and sometimes a string in Elasticsearch anyway, surely the mapping must be one or the other?)

---

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [November 22, 2017, 9:15am UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/5 "2017-11-22T09:15:52Z")

</div>

Re the mapping point, I have now discovered [Strings in integer fields?](https://discuss.elastic.co/t/strings-in-integer-fields/58301)

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 22, 2017, 8:51pm UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/6 "2017-11-22T20:51:09Z")

</div>

Which heartbeat version are you using? This is a bug. Ports should always be numeric values.

---

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [November 23, 2017, 9:09am UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/7 "2017-11-23T09:09:28Z")

</div>

5.5.1

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 23, 2017, 9:57am UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/8 "2017-11-23T09:57:03Z")

</div>

In 6.0 we redid the event format for heartbeat. [https://github.com/elastic/beats/pull/4091](https://github.com/elastic/beats/pull/4091)

I just noticed it's using string for all port types. But the Elasticsearch template mapping configures the port number to be an integer. 😱

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [November 23, 2017, 10:01am UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/9 "2017-11-23T10:01:51Z")

</div>

New github issue: [https://github.com/elastic/beats/issues/5696](https://github.com/elastic/beats/issues/5696)

---

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [November 23, 2017, 10:13am UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/10 "2017-11-23T10:13:20Z")

</div>

What a pain. I'd written some generic code to handle boolean (true/false) statuses so I'll have to write some new code to handle "up"/"down". (I suppose an alternative would be to run it through Logstash and change it back to the old format ...)

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 26, 2017, 9:13pm UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/11 "2017-11-26T21:13:08Z")

</div>

@TimWard Thanks for bringing this up.

If the template on the elasticsearch side states `int`, ES should either reject it or store is a integer I think. So even if I agree that this is a bug, it should end up in the right format in Elasticsearch (assuming the template was applied before sending data)?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 28, 2017, 3:12am UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/12 "2017-11-28T03:12:31Z")

</div>

@TimWard Just tried to reproduce this with master / 6.x It seems we have fixed it there more by accident probably. Could you try out 6.0 and check if you still have the issue?

---

<div class="post-metadata">

**Author:** ![TimWard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timward/32/19574_2.png) [@TimWard](https://discuss.elastic.co/u/TimWard)\
**Post date:** [November 29, 2017, 9:27am UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/13 "2017-11-29T09:27:34Z")

</div>

Thanks for the investigations and comments. I'm sure I will try it with 6.0 one day, but installing and configuring a 6.0 set-up is unlikely to reach the top of my priority list in the immediate future.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 30, 2017, 3:09am UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/14 "2017-11-30T03:09:21Z")

</div>

Thanks Tim for the answer. Appreciate your effort you put into this and I'm glad you found a temporary solution.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2017, 4:06pm UTC](https://discuss.elastic.co/t/what-type-is-the-port-field-in-heartbeat-output/108586/15 "2017-12-12T16:06:03Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
