# Ambiguous field reference for object field

**URL:** <https://discuss.elastic.co/t/ambiguous-field-reference-for-object-field/206166>\
**Category:** Logstash\
**Created:** [November 1, 2019, 1:01pm UTC](https://discuss.elastic.co/t/ambiguous-field-reference-for-object-field/206166 "2019-11-01T13:01:14Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bruce289](https://avatars.discourse-cdn.com/v4/letter/b/7bcc69/32.png) [@bruce289](https://discuss.elastic.co/u/bruce289)\
**Post date:** [November 1, 2019, 1:01pm UTC](https://discuss.elastic.co/t/ambiguous-field-reference-for-object-field/206166/1 "2019-11-01T13:01:14Z")

</div>

Hi,

I'm attempting to split a field which looks like:

```auto
{
  "VERSION" : "version-uk-v2.1.0-global-v2.2.0" 
}

```

into the following:

```auto
{
  "host" : {
    "version" : {
      "uk" : "v2.1.0",
      "global" : "v2.2.0"
    }
  }
}

```

I need to be able to reference the field value when setting the new field name since "uk" is variable. Here is the filter I'm using:

```auto
  if [VERSION] {
    mutate {
      split => ["VERSION", "-"]
      add_field => { "[host][version][%{[VERSION][1]}]" => "%{[VERSION][2]}" }
      add_field => { "[host][version][%{[VERSION][3]}]" => "%{[VERSION][4]}" }
      remove_field => ["VERSION"]
    }
  }

```

It seems to work, but it results in the warnings:

[2019-11-01T12:42:31,790][WARN][org.logstash.FieldReference] Detected ambiguous Field Reference `[host][version][%{[VERSION][1]}]`, which we expanded to the path `[host, version, %{, VERSION, 1, }]`; in a future release of Logstash, ambiguous Field References will not be expanded.  
[2019-11-01T12:42:31,791][WARN][org.logstash.FieldReference] Detected ambiguous Field Reference `[host][version][%{[VERSION][3]}]`, which we expanded to the path `[host, version, %{, VERSION, 3, }]`; in a future release of Logstash, ambiguous Field References will not be expanded.

I've tried referencing those array elements a number of different ways but the warning still remains. What is the correct way to do this?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2019, 1:01pm UTC](https://discuss.elastic.co/t/ambiguous-field-reference-for-object-field/206166/2 "2019-11-29T13:01:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
