# Changing dotted json field names to valid json form for Logstash

**URL:** <https://discuss.elastic.co/t/changing-dotted-json-field-names-to-valid-json-form-for-logstash/171026>\
**Category:** Logstash\
**Created:** [March 6, 2019, 5:52am UTC](https://discuss.elastic.co/t/changing-dotted-json-field-names-to-valid-json-form-for-logstash/171026 "2019-03-06T05:52:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sanghyeon\_Park](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sanghyeon_park/32/50349_2.png) [@Sanghyeon\_Park](https://discuss.elastic.co/u/Sanghyeon_Park)\
**Post date:** [March 6, 2019, 5:52am UTC](https://discuss.elastic.co/t/changing-dotted-json-field-names-to-valid-json-form-for-logstash/171026/1 "2019-03-06T05:52:46Z")

</div>

Hello!  
I'm new to Logstash, and I'm trying filtering and mutating input logs from Filebeat.

First of all, I have read this article, and I know that I cannot use dot separated field names.  
[Field name cannot contain dots](https://discuss.elastic.co/t/field-name-cannot-contain/33251)

My question is that how can I change json fields automatically from an input json log?

The example input is the NFCT json file this ulogd stack  
`stack=ct1:NFCT,ip2bin1:IP2BIN,jsonnfwct:JSON`

and this is what made from

```
{
"timestamp": "2019-03-06T05:21:51",
"dvc": "devicename",
"orig.ip.protocol": 17,
"orig.l4.sport": 60770,
"orig.l4.dport": 1900,
"orig.raw.pktlen": 0,
"orig.raw.pktcount": 0,
"reply.ip.protocol": 17,
"reply.l4.sport": 1900,
"reply.l4.dport": 60770,
"reply.raw.pktlen": 0,
"reply.raw.pktcount": 0,
"ct.mark": 0,
"ct.id": 3190284752,
"ct.event": 1,
"flow.start.sec": 1551849711,
"flow.start.usec": 151034,
"oob.family": 2,
"oob.protocol": 0
}

```

As you see, It emits dotted field name that is json form.  
And to recognize by Kibana, It has to be changed to another word.

Here is what I want

```
{
    "timestamp": "2019-03-06T05:21:51",
    "dvc": "devicename", 
    "orig": { 
        "ip": { 
            "protocol": "17"
        },
        "l4": {
            "sport": "60770",
            "dport": "1900"
        },
        "raw": {
            "pktlen": "0",
            "pktcount": "0"
        }
    },
    "reply": {
        "ip": {
            "protocol": "17"
        },
        "l4": {
            "sport": "1900",
            "dport": "60770"
        },
        "raw": {
            "pktlen": "0",
            "pktcount": "0"
        }
    },
    "ct": {
        "mark": "0",
        "id": "3190284752",
        "event": "1"
    },
    "flow": {
        "start": {
            "sec": "1551849711",
            "usec": "151034"
        }
    },
    "oob": {
        "family": "2",
        "protocol": "0"
    }
}

```

Actually, before I ask this, I was trying to use the gsub module to replace '.' to '\_'  
The configuration pipeline was this

```
filter {
    mutate {                           
        gsub => ["message", "\.+", "_"]
    }
}

```

But it changed every '.' to '\_', now those are just single values without the relationship.  
Can I make it?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 6, 2019, 12:59pm UTC](https://discuss.elastic.co/t/changing-dotted-json-field-names-to-valid-json-form-for-logstash/171026/2 "2019-03-06T12:59:27Z")

</div>

A dedot filter with the nested option enabled would do what you want.

---

<div class="post-metadata">

**Author:** ![Sanghyeon\_Park](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sanghyeon_park/32/50349_2.png) [@Sanghyeon\_Park](https://discuss.elastic.co/u/Sanghyeon_Park)\
**Post date:** [March 7, 2019, 12:24am UTC](https://discuss.elastic.co/t/changing-dotted-json-field-names-to-valid-json-form-for-logstash/171026/3 "2019-03-07T00:24:07Z")

</div>

Yay! That is what i want!  
Thanks for your great help!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2019, 12:24am UTC](https://discuss.elastic.co/t/changing-dotted-json-field-names-to-valid-json-form-for-logstash/171026/4 "2019-04-04T00:24:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
