# Detected ambiguous Field Reference warning

**URL:** <https://discuss.elastic.co/t/detected-ambiguous-field-reference-warning/328218>\
**Category:** Logstash\
**Created:** [March 22, 2023, 8:29am UTC](https://discuss.elastic.co/t/detected-ambiguous-field-reference-warning/328218 "2023-03-22T08:29:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![parosio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/parosio/32/27367_2.png) [@parosio](https://discuss.elastic.co/u/parosio)\
**Post date:** [March 22, 2023, 8:29am UTC](https://discuss.elastic.co/t/detected-ambiguous-field-reference-warning/328218/1 "2023-03-22T08:29:58Z")

</div>

Hello,  
I've got to ingest (logstash 6.7) documents which are stages of a workflow (queue\_in, start\_work, end\_work, queue\_out, etc.).  
I need to add various fields with elapsed times (looking for initial times in previous docs), depending on the stage the workflow.

So I assign the literal string name to a `@metadata` field:  
`add_field => { "[@metadata][deltaT_fieldname]" => "<literal field name>" }`  
I compute the elapsed time and put it in a generic `[delta_sec]` field using a ruby plugin, then assign its value to the field specified in `deltaT_fieldname`:

`mutate { add_field => { "%{[@metadata][deltaT_fieldname]}" => "%{[@metadata][delta_sec]}"} }`

The warn is `Detected ambiguous Field Reference `%{[@metadata][deltaT_fieldname]}`, which we expanded to the path `[%{, @metadata, deltaT_fieldname, }]`; in a future release of Logstash, ambiguous Field References will not be expanded.`

I've read through other similar issues [like this](https://discuss.elastic.co/t/detected-ambiguous-field-reference-warnings-in-logstash-6-4-0/149825), or the [grammar](https://github.com/elastic/logstash/blob/dd2aec19458f248e1238062d6bfd1c2d3086eb50/docs/static/field-reference.asciidoc) by @yaauie, but still don't understand how to fix my "sprintf" format string.

Any suggestion, to keep it working with newer logstash versions?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2023, 8:29am UTC](https://discuss.elastic.co/t/detected-ambiguous-field-reference-warning/328218/2 "2023-03-22T08:29:58Z")

</div>

logstash 6.7 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2023, 8:30am UTC](https://discuss.elastic.co/t/detected-ambiguous-field-reference-warning/328218/3 "2023-04-19T08:30:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
