# Convert fields to ECS

**URL:** https://discuss.elastic.co/t/convert-fields-to-ecs/224888
**Category:** Logstash
**Created:** [March 24, 2020, 4:47pm UTC](https://discuss.elastic.co/t/convert-fields-to-ecs/224888 "2020-03-24T16:47:53Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![david-vazquez](https://avatars.discourse-cdn.com/v4/letter/d/ac8455/32.png) [@david-vazquez](https://discuss.elastic.co/u/david-vazquez)
#### Post date: [March 24, 2020, 4:47pm UTC](https://discuss.elastic.co/t/convert-fields-to-ecs/224888/1 "2020-03-24T16:47:54Z")

</div>

Hello,

I´m trying to ingest log file using ECS (Elastic Common Schema). For doing it, I have to rename source fields following the ECS convention. I made a filter which is not working:

```
filter {
json {
source => "message"
}

mutate {
rename => { "EventType" => "dns.type" }
rename => { "Timestamp" => "@timestamp" }
rename => { "ResponseCode" => "dns.repose_code" }
rename => { "InternalIp" => "source.ip" }
rename => { "Action" => "event.action" }
rename => { "Identities" => "event.module" }
rename => { "Domain" => "dns.question.name" }
rename => { "Categories" => "dns.answers.type" }
rename => { "QueryType" => "dns.op_code" }
rename => { "sourceFile" => "file.name" }
remove_field => ["ExternalIp","MostGranularIdentity"]
}
date {
match => ["@timestamp", "yyyy-MM-dd HH:mm:ss"]
}
}

```

I don´t know why it´s not working. I´m using rubydebug output and no data is showed in console.  
While I was using that filter without mutate part (only json used), it was properly working, but obviusly ingested fields were not properly named following ECS.

The source log file is a json like this one:  
`{"sourceFile":"dns.csv.gz","EventType":"DNSLog","Timestamp":"2020-03-03 20:41:31","MostGranularIdentity":"TRYINGDNS","Identities":"TRYINGDNS","InternalIp":"10.10.10.10","ExternalIp":"10.10.10.10","Action":"Allowed","QueryType":"1 (C)","ResponseCode":"NOERROR","Domain":"www.google.com","Categories":"Software/Technology,Business Services"}`

Am I doing it properly? Why it´s not working?  
I also tryed without using the "remove\_field". Also does not work.

Thanks.

Greetings.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [March 24, 2020, 5:02pm UTC](https://discuss.elastic.co/t/convert-fields-to-ecs/224888/2 "2020-03-24T17:02:28Z")

</div>

> [@david-vazquez](#):
>
> rename =\> { "Domain" =\> "dns.question.name" }

ECS objects are objects, so in logstash you would refer to dns.question.name as [dns][question][name].

We have no way of telling why your input might not be generating events if you do not show us the input.

---

<div class="post-metadata">

### Author: ![david-vazquez](https://avatars.discourse-cdn.com/v4/letter/d/ac8455/32.png) [@david-vazquez](https://discuss.elastic.co/u/david-vazquez)
#### Post date: [March 24, 2020, 5:07pm UTC](https://discuss.elastic.co/t/convert-fields-to-ecs/224888/3 "2020-03-24T17:07:16Z")

</div>

This is my Input:

```
input {
file {
path => "/home/user/Downloads/file.log"
start_position => "beginning"
}
}

```

So you mean I have to rename fields in that way?:  
rename =\> { "Domain" =\> [dns][question][name] }

I was following the guide:  
[https://www.elastic.co/guide/en/ecs/current/ecs-dns.html](https://www.elastic.co/guide/en/ecs/current/ecs-dns.html)

And I just decided which fields can correspond with ECS fields... I thought that renaming fields was the way to get ECS convention, I mean, mapping the fields to ECS fields so follow ECS convention.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [March 24, 2020, 5:42pm UTC](https://discuss.elastic.co/t/convert-fields-to-ecs/224888/4 "2020-03-24T17:42:34Z")

</div>

I mean that you should use

```
rename => {
    "EventType" => "[dns][type]"
    "ResponseCode" => "[dns][response_code]"
    "InternalIp" => "[source][ip]"
    ...
}

```

If you have a "dns" object that contains a type field then in elasticsearch that would be called dns.type. In logstash it is referred to as [dns][type]

---

<div class="post-metadata">

### Author: ![david-vazquez](https://avatars.discourse-cdn.com/v4/letter/d/ac8455/32.png) [@david-vazquez](https://discuss.elastic.co/u/david-vazquez)
#### Post date: [March 24, 2020, 6:09pm UTC](https://discuss.elastic.co/t/convert-fields-to-ecs/224888/5 "2020-03-24T18:09:42Z")

</div>

I just changed it following your example:  
mutate {  
rename =\> { "EventType" =\> "[dns][type]" }  
rename =\> { "ResponseCode" =\> "[dns][repose\_code]" }  
rename =\> { "InternalIp" =\> "[source][ip]" }  
rename =\> { "Action" =\> "[event][action]" }  
rename =\> { "Identities" =\> "[event][module]" }  
rename =\> { "Domain" =\> "[dns][question][name]" }  
rename =\> { "Categories" =\> "[dns][answers][type]" }  
rename =\> { "QueryType" =\> "[dns][op\_code]" }  
rename =\> { "sourceFile" =\> "[file][name]" }  
#remove\_field =\> ["ExternalIp","MostGranularIdentity"]  
}  
}

It´s not working... no data showed in console. The source log with input values are in first message I sent in this thread.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [March 24, 2020, 6:29pm UTC](https://discuss.elastic.co/t/convert-fields-to-ecs/224888/6 "2020-03-24T18:29:27Z")

</div>

Are you appending lines to the file? If logstash has already read it then it will not re-read it.

---

<div class="post-metadata">

### Author: ![david-vazquez](https://avatars.discourse-cdn.com/v4/letter/d/ac8455/32.png) [@david-vazquez](https://discuss.elastic.co/u/david-vazquez)
#### Post date: [March 24, 2020, 7:06pm UTC](https://discuss.elastic.co/t/convert-fields-to-ecs/224888/7 "2020-03-24T19:06:06Z")

</div>

Oh! you are right. I tryed adding lines and it worked.  
How can I do to rename the field Timestamp to ECS? what should be the ECS field name? Is Timestamp valid?

Thanks

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [March 24, 2020, 7:57pm UTC](https://discuss.elastic.co/t/convert-fields-to-ecs/224888/8 "2020-03-24T19:57:01Z")

</div>

> [@david-vazquez](#):
>
> what should be the ECS field name?

I know very little about ECS, so I cannot answer that.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 21, 2020, 7:57pm UTC](https://discuss.elastic.co/t/convert-fields-to-ecs/224888/9 "2020-04-21T19:57:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
