# Change field name during index

**URL:** <https://discuss.elastic.co/t/change-field-name-during-index/224193>\
**Category:** Elasticsearch\
**Created:** [March 18, 2020, 9:54pm UTC](https://discuss.elastic.co/t/change-field-name-during-index/224193 "2020-03-18T21:54:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sukramolas](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@Sukramolas](https://discuss.elastic.co/u/Sukramolas)\
**Post date:** [March 18, 2020, 9:54pm UTC](https://discuss.elastic.co/t/change-field-name-during-index/224193/1 "2020-03-18T21:54:31Z")

</div>

It is possible to create a character map analyzer for fields that are indexed but is it possible to do the same for field names?

Example field name would be "A|B" and the need would be to change the pipe to some other character, e.g. underscore "A\_B".

---

<div class="post-metadata">

**Author:** ![scottdfedorov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scottdfedorov/32/64699_2.png) [@scottdfedorov](https://discuss.elastic.co/u/scottdfedorov)\
**Post date:** [March 18, 2020, 10:23pm UTC](https://discuss.elastic.co/t/change-field-name-during-index/224193/2 "2020-03-18T22:23:08Z")

</div>

> [@Sukramolas](#):
>
> Example field name would be "A|B" and the need would be to change the pipe to some other character, e.g. underscore "A\_B".

That's exactly what the [Gsub processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/gsub-processor.html) does.

Edit: the [mutate/Gsub filter documentation from Logstash](https://www.elastic.co/guide/en/logstash/7.6/plugins-filters-mutate.html#plugins-filters-mutate-gsub) is more helpful I think, same basic thing.

---

<div class="post-metadata">

**Author:** ![Sukramolas](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@Sukramolas](https://discuss.elastic.co/u/Sukramolas)\
**Post date:** [March 19, 2020, 12:01am UTC](https://discuss.elastic.co/t/change-field-name-during-index/224193/3 "2020-03-19T00:01:26Z")

</div>

This seems to do whats needed, however it would need to apply to any field and it's not possible for me to list all field names.

---

<div class="post-metadata">

**Author:** ![scottdfedorov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scottdfedorov/32/64699_2.png) [@scottdfedorov](https://discuss.elastic.co/u/scottdfedorov)\
**Post date:** [March 19, 2020, 1:21am UTC](https://discuss.elastic.co/t/change-field-name-during-index/224193/4 "2020-03-19T01:21:09Z")

</div>

Do you want to replace all instances of the pipe character with an underscore, or only if they're in the field name?

You can still run a custom normalizer/char filter, just apply it to the `_source` field and it'll replace all the pipes regardless of location.

If you need to run it on all field names, then you can try using a Foreach processor on the `_source` and it'll run the Gsub against all the top-level fields. If you need to to apply it to subfields as well, then you get into recursion and it can get complicated fast, depending on number of levels and uniformity.  
You can always create a custom pipeline. With the script processors you can do a whole lot of things, but when you start to get into this level of complexity, it might be worth taking a step back and re-examining the problem starting with where the content is being indexed from and how...

Spend some time reading the helpdocs, and think outside the box. You can do almost anything. Some things scale and some don't.

Also, generally speaking, try to give more specifics on your use case when asking for help. Include examples.

Hope that helps.

---

<div class="post-metadata">

**Author:** ![Sukramolas](https://avatars.discourse-cdn.com/v4/letter/s/d2c977/32.png) [@Sukramolas](https://discuss.elastic.co/u/Sukramolas)\
**Post date:** [March 19, 2020, 2:41pm UTC](https://discuss.elastic.co/t/change-field-name-during-index/224193/5 "2020-03-19T14:41:58Z")

</div>

Hi Scott, thank you for the reply!

i need to replace values only in field names and top level fields. I will give Gsub a try.

[Edit]:

solved the issue with ingest pipeline.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 16, 2020, 2:41pm UTC](https://discuss.elastic.co/t/change-field-name-during-index/224193/6 "2020-04-16T14:41:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
