# Create elastic field alias

**URL:** <https://discuss.elastic.co/t/create-elastic-field-alias/313966>\
**Category:** Logstash\
**Created:** [September 8, 2022, 8:45am UTC](https://discuss.elastic.co/t/create-elastic-field-alias/313966 "2022-09-08T08:45:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sirReeall](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sirreeall/32/94713_2.png) [@sirReeall](https://discuss.elastic.co/u/sirReeall)\
**Post date:** [September 8, 2022, 8:45am UTC](https://discuss.elastic.co/t/create-elastic-field-alias/313966/1 "2022-09-08T08:45:58Z")

</div>

Hello,

Is it possible for logstash to alias fields as described in the elastic docs below?

> **[Alias field type | Elasticsearch Guide \[8.4\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/field-alias.html)**

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 8, 2022, 5:53pm UTC](https://discuss.elastic.co/t/create-elastic-field-alias/313966/2 "2022-09-08T17:53:07Z")

</div>

> [@sirReeall](#):
>
> Is it possible for logstash to alias fields as described in the elastic docs below?

Not sure what you think logstash could do related to aliases. An alias allows a different name to be used when sending a search request to elasticsearch. If logstash sends a query to elasticsearch (either an input or a filter) then I would certainly expect it to be able to use an alias. Other than that, what would you want logstash to do?

---

<div class="post-metadata">

**Author:** ![sirReeall](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sirreeall/32/94713_2.png) [@sirReeall](https://discuss.elastic.co/u/sirReeall)\
**Post date:** [September 9, 2022, 9:13am UTC](https://discuss.elastic.co/t/create-elastic-field-alias/313966/3 "2022-09-09T09:13:59Z")

</div>

I have some existing fields that are parsed from events, I wanted to add an alias to these fields.

For example:

```auto
grok {
    match => {
      "message" => "%{GREEDYDATA:foo}"
    }
  }

```

I now want to add an alias `bar` that I can use for search.

I looked at `mutate.add_field` but this will add a field to the document that will not be coupled to the originally parsed field.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 9, 2022, 3:57pm UTC](https://discuss.elastic.co/t/create-elastic-field-alias/313966/4 "2022-09-09T15:57:45Z")

</div>

> [@sirReeall](#):
>
> I have some existing fields that are parsed from events, I wanted to add an alias to these fields.

So set the mapping of the index in elasticsearch such that bar is an alias for foo.

---

<div class="post-metadata">

**Author:** ![sirReeall](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sirreeall/32/94713_2.png) [@sirReeall](https://discuss.elastic.co/u/sirReeall)\
**Post date:** [September 16, 2022, 9:25am UTC](https://discuss.elastic.co/t/create-elastic-field-alias/313966/5 "2022-09-16T09:25:34Z")

</div>

The ELK stack is disposable and indexes, and their settings are not persisted. Plus, I'm using datastreams to create the index rather then manually setting them up.

I was wondering if I can define alias at parse time using logstash, I'm guessing not.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2022, 9:26am UTC](https://discuss.elastic.co/t/create-elastic-field-alias/313966/6 "2022-10-14T09:26:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
