# Wrong Long vlaue when store long value in es

**URL:** <https://discuss.elastic.co/t/wrong-long-vlaue-when-store-long-value-in-es/53882>\
**Category:** Logstash\
**Created:** [June 24, 2016, 10:57am UTC](https://discuss.elastic.co/t/wrong-long-vlaue-when-store-long-value-in-es/53882 "2016-06-24T10:57:18Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![yzhang226](https://avatars.discourse-cdn.com/v4/letter/y/9d8465/32.png) [@yzhang226](https://discuss.elastic.co/u/yzhang226)\
**Post date:** [June 24, 2016, 10:57am UTC](https://discuss.elastic.co/t/wrong-long-vlaue-when-store-long-value-in-es/53882/1 "2016-06-24T10:57:18Z")

</div>

today i met one long value convert issue,  
for clear seeing this issue, i capture one image, as following:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/4aa9e966be69c70fe9ef2ffed1bb41c10f6a6f94.png)

**logstash: 2.1.1**  
**elasticsearch: 2.1.1**  
**completely logstash config file is shown as following,**  
input {  
stdin { }  
}  
filter {  
grok {  
match =\> {  
"message" =\> "%{TIMESTAMP\_ISO8601:logging\_time}\t%{INT:biz\_type}\t%{GREEDYDATA:data}\t%{IP:local\_ip}"  
}  
}  
if [biz\_type] {  
if ( [data] and [data] =~ /(._){(.+)}(._)/ ) {  
json {  
source =\> "data"  
remove\_field =\> ["data"]  
}  
}  
}  
}  
output {  
stdout {  
codec =\> rubydebug  
}  
elasticsearch {  
hosts =\> ["localhost:9200"]  
document\_type =\> "biz\_log\_record\_%{biz\_type}"  
index =\> "bizlog-%{+YYYY-MM-dd}"  
template\_name =\> "template\_revised"  
template =\> "/programs/server/logstash-2.1.1/template/dada-template.json"  
template\_overwrite =\> true  
manage\_template =\> true  
}  
}

**detail logstash info and es info , as following,**  
2016-06-24 15:54:33 10050 {"transporter\_id\_list": [605603], "push\_count": 1, "device\_type": 1, "request\_id": 1466754873939567710, "is\_success": true, "push\_id": null, "area\_id": 10, "time\_type": "test"} 10.10.183.101  
{  
"@version" =\> "1",  
"@timestamp" =\> "2016-06-24T10:31:43.531Z",  
"host" =\> "cookorg.local",  
"logging\_time" =\> "2016-06-24 15:54:33",  
"biz\_type" =\> "10050",  
"local\_ip" =\> "10.10.183.101",  
"transporter\_id\_list" =\> [  
[0] 605603  
],  
"push\_count" =\> 1,  
"device\_type" =\> 1,  
**"request\_id" =\> 1466754873939567710,**  
"is\_success" =\> true,  
"push\_id" =\> nil,  
"area\_id" =\> 10,  
"time\_type" =\> "test"  
}

**in the es storage, i see different request\_id value, as following:**  
{  
"\_index": "bizlog-2016-06-24",  
"\_type": "biz\_log\_record\_10050",  
"\_id": "AVWB9x3-qfZHqOoPMgIt",  
"\_version": 1,  
"\_score": 1,  
"\_source": {  
"@version": "1",  
"@timestamp": "2016-06-24T10:31:43.531Z",  
"host": "cookorg.local",  
"logging\_time": "2016-06-24 15:54:33",  
"biz\_type": "10050",  
"local\_ip": "10.10.183.101",  
"transporter\_id\_list": [  
605603  
],  
"push\_count": 1,  
"device\_type": 1,  
**"request\_id": 1466754873939567600,**  
"is\_success": true,  
"push\_id": null,  
"area\_id": 10,  
"time\_type": "test"  
}  
}

does someone met this issue?

---

<div class="post-metadata">

**Author:** ![yzhang226](https://avatars.discourse-cdn.com/v4/letter/y/9d8465/32.png) [@yzhang226](https://discuss.elastic.co/u/yzhang226)\
**Post date:** [June 25, 2016, 7:54am UTC](https://discuss.elastic.co/t/wrong-long-vlaue-when-store-long-value-in-es/53882/3 "2016-06-25T07:54:47Z")

</div>

i don't get it.  
don't you think this is an issue?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 25, 2016, 8:17am UTC](https://discuss.elastic.co/t/wrong-long-vlaue-when-store-long-value-in-es/53882/4 "2016-06-25T08:17:05Z")

</div>

I moved the discussion to logstash.

To me, it's not happening in Elasticsearch but in logstash.  
I mean that Elasticsearch stores the JSON content as is.

---

<div class="post-metadata">

**Author:** ![yzhang226](https://avatars.discourse-cdn.com/v4/letter/y/9d8465/32.png) [@yzhang226](https://discuss.elastic.co/u/yzhang226)\
**Post date:** [June 25, 2016, 1:09pm UTC](https://discuss.elastic.co/t/wrong-long-vlaue-when-store-long-value-in-es/53882/5 "2016-06-25T13:09:22Z")

</div>

in my opinion, logstash parse the line well,  
the issue happened when store into es

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 28, 2016, 7:23am UTC](https://discuss.elastic.co/t/wrong-long-vlaue-when-store-long-value-in-es/53882/6 "2016-06-28T07:23:08Z")

</div>

What's the mapping of the field? Could the problem be related to [https://github.com/elastic/elasticsearch/issues/14506](https://github.com/elastic/elasticsearch/issues/14506), i.e. that ES stores things correctly but that the JavaScript library used to extract the documents doesn't handle a sufficient number of significant digits?

---

<div class="post-metadata">

**Author:** ![yzhang226](https://avatars.discourse-cdn.com/v4/letter/y/9d8465/32.png) [@yzhang226](https://discuss.elastic.co/u/yzhang226)\
**Post date:** [February 21, 2017, 7:22am UTC](https://discuss.elastic.co/t/wrong-long-vlaue-when-store-long-value-in-es/53882/7 "2017-02-21T07:22:16Z")

</div>

maybe it just is issue when being display in kibana

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:28am UTC](https://discuss.elastic.co/t/wrong-long-vlaue-when-store-long-value-in-es/53882/8 "2017-07-06T04:28:25Z")

</div>


