I started using grok patterns recently to parse numeric fields in log messages. Everything was perfect until the index rotation happened in Graylog and suddenly Elasticsearch started complaining that there is a conflict of field type for the older and the new index. In the older index the extracted field is still numeric but in the new index it is showing it as string.
Before this, I have used numerical converters in extractors to extract a numeric field from log messages and those fields are still numeric in the new index.
I am using the following versions:
Graylog : 2.4.3