# Changing field in Index pattern

**URL:** <https://discuss.elastic.co/t/changing-field-in-index-pattern/206619>\
**Category:** Kibana\
**Created:** [November 5, 2019, 1:24pm UTC](https://discuss.elastic.co/t/changing-field-in-index-pattern/206619 "2019-11-05T13:24:56Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aileen](https://avatars.discourse-cdn.com/v4/letter/a/b5a626/32.png) [@Aileen](https://discuss.elastic.co/u/Aileen)\
**Post date:** [November 5, 2019, 1:24pm UTC](https://discuss.elastic.co/t/changing-field-in-index-pattern/206619/1 "2019-11-05T13:24:56Z")

</div>

Hi  
We have recently changed our field names to include a suffix of the type.  
I have run a refresh on my index pattern and can now see the new fields and the old, but my visualizations now need updating to handle both (as I don't want to lose the old data).

Is it possible to create scripted fields to return either or both?  
When I try, and run the preview window then it comes back with 0 values.

Thank you in advance

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [November 5, 2019, 4:14pm UTC](https://discuss.elastic.co/t/changing-field-in-index-pattern/206619/2 "2019-11-05T16:14:55Z")

</div>

Hi @Aileen,

how does the script you tried look like?

Something like this should you the trick:

```auto
if (doc['newfield'].empty) {
    return doc['oldfield'];
} else {
    return doc['newfield'];
}

```

That begin said, depending on how much data you have it might make sense to re-ingest the data and change the fieldnames in the actual indexed documents because performance might not be great using scripted fields.

---

<div class="post-metadata">

**Author:** ![Aileen](https://avatars.discourse-cdn.com/v4/letter/a/b5a626/32.png) [@Aileen](https://discuss.elastic.co/u/Aileen)\
**Post date:** [November 5, 2019, 5:05pm UTC](https://discuss.elastic.co/t/changing-field-in-index-pattern/206619/3 "2019-11-05T17:05:00Z")

</div>

Hi @flash1293

Thanks for your help. That is pretty much what I tried.  
I have just tried again, and now when I go to the Discover page, I only see my scripted field in "Available fields", and it claims that no data matches my search criteria.  
Is it because the data has already been received, without that field?

Thanks

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [November 5, 2019, 5:49pm UTC](https://discuss.elastic.co/t/changing-field-in-index-pattern/206619/4 "2019-11-05T17:49:05Z")

</div>

Hi, could you post your mapping definition and your script? It's hard to tell without knowing specifics.

---

<div class="post-metadata">

**Author:** ![Aileen](https://avatars.discourse-cdn.com/v4/letter/a/b5a626/32.png) [@Aileen](https://discuss.elastic.co/u/Aileen)\
**Post date:** [November 6, 2019, 7:39am UTC](https://discuss.elastic.co/t/changing-field-in-index-pattern/206619/5 "2019-11-06T07:39:45Z")

</div>

Hi  
Here are the hostname fields:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/4/f44c31228aa56e546b0bd4eb2d996f57c2f8e4e8.png)  
And my scripted field:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a02fe4c1843c63d4bf5250875ff687f7d374868b.png)

Here is my discover page:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/8/8898169340b0a328ed6ade7f5583db8ca1ed4cf2.png)

Usually there is a whole list of Available fields on the left, and as you can see we have over 3 million entries, all of which have either HostName or HostName\_String. And yet apparently none match the search, even though I don't see that I have any search criteria.

Thanks

---

<div class="post-metadata">

**Author:** ![Aileen](https://avatars.discourse-cdn.com/v4/letter/a/b5a626/32.png) [@Aileen](https://discuss.elastic.co/u/Aileen)\
**Post date:** [November 6, 2019, 7:49am UTC](https://discuss.elastic.co/t/changing-field-in-index-pattern/206619/7 "2019-11-06T07:49:40Z")

</div>

Perhaps it will help to show you what has happened with the records.

Here is how it looked 2 days ago:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/7/57b4e5f1d130d81e1a3cc50d6e85707bed866c37.png)

Here is how it looks now, as you can see, we have suffixed some of the fields with the type.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/5/459dcc4ed879733f73600955ead717d52daf3a46.png)

Our visualizations filter on things like HostName, MetricName, and then display other fields, such as for example SqlStringLength

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2019, 7:49am UTC](https://discuss.elastic.co/t/changing-field-in-index-pattern/206619/8 "2019-12-04T07:49:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
