# Dot in field name? Scripting issue

**URL:** <https://discuss.elastic.co/t/dot-in-field-name-scripting-issue/191534>\
**Category:** Elasticsearch\
**Created:** [July 21, 2019, 6:44pm UTC](https://discuss.elastic.co/t/dot-in-field-name-scripting-issue/191534 "2019-07-21T18:44:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fb-l](https://avatars.discourse-cdn.com/v4/letter/f/e47c2d/32.png) [@fb-l](https://discuss.elastic.co/u/fb-l)\
**Post date:** [July 21, 2019, 6:44pm UTC](https://discuss.elastic.co/t/dot-in-field-name-scripting-issue/191534/1 "2019-07-21T18:44:22Z")

</div>

Hi everybody,

I'm reading various opinions / best practices re: field names. Apparently dots are fully supported but not recommended " \* usage of point "." is discouraged but possible".  
Is that correct? Most of the beats fields include a dot (i.e. destination.ip or agent.type).

I'm trying to run some reindexing to rename my fields to match the beats convention. For example, I want to reindex and rename dst\_ip in destination.ip. However, I get a null\_pointer\_exception.

Code:

POST \_reindex  
{  
"source": {  
"index": "logstash-2018.04"  
},  
"dest": {  
"index": "logstash-reindex-2018.04"  
},  
"script": {  
"inline": "ctx.\_source.source.ip = ctx.\_source.remove('src\_ip');"  
}  
}

Error:

{  
"error": {  
"root\_cause": [  
{  
"type": "script\_exception",  
"reason": "runtime error",  
"script\_stack": [  
"ctx.\_source.source.ip = ctx.\_source.remove('src\_ip');",  
" ^---- HERE"  
],  
"script": "ctx.\_source.source.ip = ctx.\_source.remove('src\_ip');",  
"lang": "painless"  
}  
],  
"type": "script\_exception",  
"reason": "runtime error",  
"script\_stack": [  
"ctx.\_source.source.ip = ctx.\_source.remove('src\_ip');",  
" ^---- HERE"  
],  
"script": "ctx.\_source.source.ip = ctx.\_source.remove('src\_ip');",  
"lang": "painless",  
"caused\_by": {  
"type": "null\_pointer\_exception",  
"reason": null  
}  
},  
"status": 400  
}

Any help is much appreciated.

Thanks.

---

<div class="post-metadata">

**Author:** ![fb-l](https://avatars.discourse-cdn.com/v4/letter/f/e47c2d/32.png) [@fb-l](https://discuss.elastic.co/u/fb-l)\
**Post date:** [July 21, 2019, 7:18pm UTC](https://discuss.elastic.co/t/dot-in-field-name-scripting-issue/191534/2 "2019-07-21T19:18:03Z")

</div>

Additional issue I found when using dots in field names.

THIS WORKS:

output {  
elasticsearch {  
index =\> "%{logstash\_input}-%{+xxxx.ww}"  
}  
}  
... and the index name is dynamically generated from the field content.

THIS DOESN'T  
output {  
elasticsearch {  
index =\> "%{logstash.input}-%{+xxxx.ww}"  
}  
}  
... here the generated index name is: %{logstash.input}-2019.29

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2019, 7:18pm UTC](https://discuss.elastic.co/t/dot-in-field-name-scripting-issue/191534/3 "2019-08-18T19:18:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
