# Dynamically match and rename json fields

**URL:** <https://discuss.elastic.co/t/dynamically-match-and-rename-json-fields/77220>\
**Category:** Logstash\
**Created:** [March 2, 2017, 8:49pm UTC](https://discuss.elastic.co/t/dynamically-match-and-rename-json-fields/77220 "2017-03-02T20:49:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lask001](https://avatars.discourse-cdn.com/v4/letter/l/4da419/32.png) [@lask001](https://discuss.elastic.co/u/lask001)\
**Post date:** [March 2, 2017, 8:49pm UTC](https://discuss.elastic.co/t/dynamically-match-and-rename-json-fields/77220/1 "2017-03-02T20:49:45Z")

</div>

Hoping I can get some ideas on how to go about fixing this issue I'm running into.

I'm on elastic 2.3.5, and it doesn't allow for fields to contain a `.`. I'm using the JSON filter in log stash to parse this data:

```
"network_throughput":{  
   "localhost://10.10.10.1:5000":{  
      "read":{  
         "message_count":"33",
         "inflight_time":"3",
         "read_throughput":"630900",
         "write_throughput":"2244"
      },
      "existing_connectors":1
   },
   "localhost://10.10.10.2:5000":{  
      "read":{  
         "message_count":"33",
         "inflight_time":"3",
         "read_throughput":"630900",
         "write_throughput":"2244"
      },
      "existing_connectors":1
   },

```

Is there a way that I can search through my JSON and if I see the `network_throughput` field to mutate the localhost fields? I was trying to get it to do something like:

```
"localhost":{  
      "ip": "10.10.10.1:5000"
      "read":{  
         "message_count":"33",
         "inflight_time":"3",
         "read_throughput":"630900",
         "write_throughput":"2244"
      },
      "existing_connectors":1

```

I've spent the afternoon looking for ideas, but I haven't found anything that has got me even remotely close to what I'm looking for. Even rewriting the `.` as a `_` would work at this point - Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 6, 2017, 9:31am UTC](https://discuss.elastic.co/t/dynamically-match-and-rename-json-fields/77220/2 "2017-03-06T09:31:36Z")

</div>

Have you look at the de\_dot filter? Otherwise you'll have to write a small Ruby snippet and put in a ruby filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2017, 9:31am UTC](https://discuss.elastic.co/t/dynamically-match-and-rename-json-fields/77220/3 "2017-04-03T09:31:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
