# Winlogbeat - event\_data data types

**URL:** <https://discuss.elastic.co/t/winlogbeat-event-data-data-types/182503>\
**Category:** Logstash\
**Created:** [May 23, 2019, 6:23pm UTC](https://discuss.elastic.co/t/winlogbeat-event-data-data-types/182503 "2019-05-23T18:23:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![raged](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raged/32/45722_2.png) [@raged](https://discuss.elastic.co/u/raged)\
**Post date:** [May 23, 2019, 6:23pm UTC](https://discuss.elastic.co/t/winlogbeat-event-data-data-types/182503/1 "2019-05-23T18:23:18Z")

</div>

I am trying to get properties that are sent to logstash via our Winlogbeat data shipper to show up as an integer type if the value is indeed an integer.

Here is an example of a snippet of JSON that was posted to ES:

```
"event_data": {
  "ShutdownPreShutdownNotificationsTime": "10191",
  "ShutdownUserPolicyTime": "98",
  "ShutdownKernelTime": "2353",
  "ShutdownRootCauseGradualDegradationBits": "0",
  "ShutdownTimeChange": "0",
  "ShutdownTime": "46062",
  "ShutdownRootCauseStepDegradationBits": "0",
  "ShutdownEndTime": "2019-05-22T19:37:02.119561900Z",
  "ShutdownStartTime": "2019-05-22T19:36:16.057145700Z",
  "ShutdownUserProfilesTime": "118",
  "ShutdownTsVersion": "1",
  "ShutdownRootCauseStepImprovementBits": "0",
  "ShutdownServicesTime": "3861",
  "ShutdownSystemSessionsTime": "14266",
  "ShutdownRootCauseGradualImprovementBits": "0",
  "ShutdownIsDegradation": "false",
  "ShutdownUserSessionTime": "29442"
},

```

It seems that Kibana has determined that this field should be a string:

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/e/2ef2c6f82f0c8e8add4cc006237c11e539ad12f2.png)

I know I could essentially do something like this in my logstash config:

```
  if [event_data][ShutdownTime] {
    mutate {
     convert => {"[event_data][ShutdownTime]" => "integer"}
    }
  }    

```

But I don't want to have to re-index if I find another field that was stuffed into ES was stuffed as a string and not a integer.

What would be the easiest way to get the data types setup correctly without having to go through each desirable field and adding a mutate to get it to be indexed as a number rather than a string?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 23, 2019, 9:20pm UTC](https://discuss.elastic.co/t/winlogbeat-event-data-data-types/182503/2 "2019-05-23T21:20:10Z")

</div>

How about

```
ruby {
    code => '
        event.get("event_data").each { |k, v|
            if v.to_i.to_s == v
                event.set("[event_data][#{k}]", v.to_i)
            end
        }
    '
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2019, 9:29pm UTC](https://discuss.elastic.co/t/winlogbeat-event-data-data-types/182503/3 "2019-06-20T21:29:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
