Netflow and IP fields

I’m using the Netwflow UDP input and I just noticed that any field that could simply be an ‘ip’ elasticsearch type is actually just a string type.
My understanding was that elasticsearch should automatically map the correct field type but it seems to prefer string over ip. Is there anyway to force this or do I need to create another field using a pipeline?

what graylog and elasticsearch version are we talking about?

AFAIK the only way to tell elasrticsearch the field is of given type is using custom index mapping

1 Like

Graylog 3.3
Elasticsearch 6.8.9

I’ll look into custom mapping like maniel suggested.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.