my fileds name in index are :category_code, userdata1,userdata2 ,userdata3 .
for events by category_code= 1 then userdata1 means name ,userdata2 means family ,userdata3 means phone
for events by category_code= 2 then userdata1 means ip ,userdata2 means domain ,userdata3 means mac_address
and many other category_codes
i have to saved discovery for category_cods , for clarity i need save some alias name for those fields.but there is nothing to do that.
i dont like do this in logstash or change data structure.