# Convert field to lowercase to use in index name

**URL:** <https://discuss.elastic.co/t/convert-field-to-lowercase-to-use-in-index-name/145836>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [August 24, 2018, 5:36am UTC](https://discuss.elastic.co/t/convert-field-to-lowercase-to-use-in-index-name/145836 "2018-08-24T05:36:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![insomniac](https://avatars.discourse-cdn.com/v4/letter/i/bb73d2/32.png) [@insomniac](https://discuss.elastic.co/u/insomniac)\
**Post date:** [August 24, 2018, 5:36am UTC](https://discuss.elastic.co/t/convert-field-to-lowercase-to-use-in-index-name/145836/1 "2018-08-24T05:36:11Z")

</div>

Trying to use the value of a field in the index name for the output to Elastic Cloud caused this error

```
 {"type":"invalid_index_name_exception","reason":"Invalid index name [winlogbeat-Microsoft-Windows-TaskScheduler-6.2.4-2018.08.22], must be lowercase

```

Is there a way to convert the field name to lower case to be used?

```
index: "winlogbeat-%{[source_name]}-%{[beat.version]}-%{+yyyy.MM.dd}"
```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 24, 2018, 2:47pm UTC](https://discuss.elastic.co/t/convert-field-to-lowercase-to-use-in-index-name/145836/2 "2018-08-24T14:47:12Z")

</div>

When researching this issue I found an existing ticket open about it. [https://github.com/elastic/beats/issues/6342](https://github.com/elastic/beats/issues/6342) Feel free to comment on the existing issue.

IMO I think adding a lowercase processor would make sense.

As a workaround, I think you might be able use an Ingest Node pipeline. I think an ingest node pipeline can modify the `_index` value so you could dynamically set the value in the pipeline after [lowercasing](https://www.elastic.co/guide/en/elasticsearch/reference/master/lowercase-processor.html) the value. Once you have the pipeline setup and tested then set `output.elasticsearch.pipeline` to point Winlogbeat at the pipeline.

- [https://www.elastic.co/guide/en/elasticsearch/reference/master/accessing-data-in-pipelines.html#accessing-metadata-fields](https://www.elastic.co/guide/en/elasticsearch/reference/master/accessing-data-in-pipelines.html#accessing-metadata-fields)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2018, 2:47pm UTC](https://discuss.elastic.co/t/convert-field-to-lowercase-to-use-in-index-name/145836/3 "2018-09-21T14:47:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
