# Duplicate fields with different names

**URL:** <https://discuss.elastic.co/t/duplicate-fields-with-different-names/366504>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 13, 2024, 12:38am UTC](https://discuss.elastic.co/t/duplicate-fields-with-different-names/366504 "2024-09-13T00:38:13Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![FF\_E4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ff_e4/32/137563_2.png) [@FF\_E4](https://discuss.elastic.co/u/FF_E4)\
**Post date:** [September 13, 2024, 12:38am UTC](https://discuss.elastic.co/t/duplicate-fields-with-different-names/366504/1 "2024-09-13T00:38:14Z")

</div>

I was working on my filebeat indexes in a local install of Elastic stack 7.17. While trying to sovle a problem, I added some aliases to these indexes, and then regretted it, so deleted the aliases.

At some point the data fields changed, and duplicated with \*.keyword. So url.path became url.path.keyword. But not for all of my data. Some filebeat indexes remained unchanged. The issue is that now my historic data shows up as either url.path or url.path.keyword, but not both.

Is there a way to reclaim the original field (url.path, source.ip, agent.hostname), instead of having fractured data ur.path.keyword, url.path, agent.hostname, agent.hostname.keyword, source.ip, source.ip.keyword?

---

<div class="post-metadata">

**Author:** ![Artem\_Shelkovnikov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/artem_shelkovnikov/32/134322_2.png) [@Artem\_Shelkovnikov](https://discuss.elastic.co/u/Artem_Shelkovnikov)\
**Post date:** [September 13, 2024, 8:33am UTC](https://discuss.elastic.co/t/duplicate-fields-with-different-names/366504/2 "2024-09-13T08:33:15Z")

</div>

From #Elastic Search to #Elasticsearch

---

<div class="post-metadata">

**Author:** ![Kathleen\_DeRusso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kathleen_derusso/32/132039_2.png) [@Kathleen\_DeRusso](https://discuss.elastic.co/u/Kathleen_DeRusso)\
**Post date:** [September 13, 2024, 12:21pm UTC](https://discuss.elastic.co/t/duplicate-fields-with-different-names/366504/3 "2024-09-13T12:21:37Z")

</div>

It sounds like you want to create a new index with the mappings you want, and then reindex into it.

In the near term, it's a pain, but you could probably do a boolean query to pull the contents of both fields.

---

<div class="post-metadata">

**Author:** ![FF\_E4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ff_e4/32/137563_2.png) [@FF\_E4](https://discuss.elastic.co/u/FF_E4)\
**Post date:** [September 13, 2024, 5:34pm UTC](https://discuss.elastic.co/t/duplicate-fields-with-different-names/366504/4 "2024-09-13T17:34:00Z")

</div>

Thanks Kathleen. I think you're right. What would be the best strategy here?

The index template (coming from filebeat) would need to be adjusted, as it's defining the indices, right? I suppose I have two options:

1. delete the index template and regenerate the template with filebeat setup -e
2. a better way? Can I modify the mappings of an index template without deleting it? How do new indices it creates pick up the changes? do I need to run a special command after updating it?

---

<div class="post-metadata">

**Author:** ![Kathleen\_DeRusso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kathleen_derusso/32/132039_2.png) [@Kathleen\_DeRusso](https://discuss.elastic.co/u/Kathleen_DeRusso)\
**Post date:** [September 13, 2024, 5:56pm UTC](https://discuss.elastic.co/t/duplicate-fields-with-different-names/366504/5 "2024-09-13T17:56:42Z")

</div>

From #Elasticsearch to #Beats

---

<div class="post-metadata">

**Author:** ![Kathleen\_DeRusso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kathleen_derusso/32/132039_2.png) [@Kathleen\_DeRusso](https://discuss.elastic.co/u/Kathleen_DeRusso)\
**Post date:** [September 13, 2024, 5:56pm UTC](https://discuss.elastic.co/t/duplicate-fields-with-different-names/366504/6 "2024-09-13T17:56:42Z")

</div>

Added #filebeat

---

<div class="post-metadata">

**Author:** ![Kathleen\_DeRusso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kathleen_derusso/32/132039_2.png) [@Kathleen\_DeRusso](https://discuss.elastic.co/u/Kathleen_DeRusso)\
**Post date:** [September 13, 2024, 5:58pm UTC](https://discuss.elastic.co/t/duplicate-fields-with-different-names/366504/7 "2024-09-13T17:58:12Z")

</div>

Hi there @FF_E4 - You can modify an index template but it will only be good for new indices - indices created using the template before it was modified will not pick up the changes.

I'm re-classifying this issue to the Filebeats area, hopefully we can get someone from that team to weigh in if there are better built-in options. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2024, 5:58pm UTC](https://discuss.elastic.co/t/duplicate-fields-with-different-names/366504/8 "2024-10-11T17:58:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
